Launch Week Day 1: Announcing Security Design Review
100 Total advisories
100 Vulnerabilities
0 Malware

Vulnerabilities

UNKNOWN
PyPI

CVE-2014-1932

CVE-2014-1932

UNKNOWN
PyPI

CVE-2022-45198

CVE-2022-45198

UNKNOWN
PyPI

CVE-2022-45199

CVE-2022-45199

UNKNOWN
PyPI

CVE-2023-44271

CVE-2023-44271

UNKNOWN
PyPI

CVE-2014-3589

CVE-2014-3589

UNKNOWN
PyPI

CVE-2016-3076

CVE-2016-3076

UNKNOWN
PyPI

CVE-2014-9601

CVE-2014-9601

UNKNOWN
PyPI

CVE-2014-3598

CVE-2014-3598

UNKNOWN
PyPI

CVE-2014-3007

CVE-2014-3007

MEDIUM 5.5
PyPI

CVE-2026-42308

Pillow has an integer overflow when processing fonts

MEDIUM 5.5
PyPI

CVE-2026-42308

CVE-2026-42308

MEDIUM 5.5
PyPI

CVE-2026-42310

Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

UNKNOWN
PyPI

CVE-2026-42311

Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)

MEDIUM 5.5
PyPI

CVE-2026-42309

Pillow has a heap buffer overflow with nested list coordinates

HIGH 7.5
PyPI

CVE-2026-40192

FITS GZIP decompression bomb in Pillow

UNKNOWN
PyPI

CVE-2026-25990

Pillow affected by out-of-bounds write when loading PSD images

MEDIUM 6.5
PyPI

CVE-2016-2533

Pillow buffer overflow in ImagingPcdDecode

UNKNOWN
PyPI

CVE-2016-2533

CVE-2016-2533

HIGH 7.1
PyPI

CVE-2025-48379

Pillow vulnerability can cause write buffer overflow on BCn encoding

HIGH 8.8
crates.io KEV

CVE-2023-4863

libwebp: OOB write in BuildHuffmanTable

UNKNOWN
PyPI

PYSEC-2023-175

PYSEC-2023-175

HIGH 8.1
PyPI

CVE-2023-50447

Arbitrary Code Execution in Pillow

MEDIUM 6.7
PyPI

CVE-2024-28219

Pillow buffer overflow vulnerability

HIGH 7.5
PyPI

CVE-2021-27921

Pillow Denial of Service by Uncontrolled Resource Consumption

HIGH 7.5
PyPI

CVE-2021-27923

Pillow Denial of Service by Uncontrolled Resource Consumption

HIGH 7.5
PyPI

CVE-2021-27922

Pillow Uncontrolled Resource Consumption

UNKNOWN
PyPI

CVE-2025-48379

CVE-2025-48379

UNKNOWN
PyPI

CVE-2020-10379

CVE-2020-10379

HIGH 7.8
PyPI

CVE-2020-10379

Buffer overflow in Pillow

UNKNOWN
PyPI

CVE-2020-10378

CVE-2020-10378

MEDIUM 5.5
PyPI

CVE-2020-10378

Out-of-bounds read in Pillow

UNKNOWN
PyPI

GHSA-56pw-mpj4-fxww

Duplicate Advisory: Bundled libwebp in Pillow vulnerable

MEDIUM 4.0
PyPI

CVE-2014-1933

Pillow Temporary file name leakage

UNKNOWN
PyPI

GHSA-4fx9-vc88-q2xc

Infinite loop in Pillow

HIGH 7.5
PyPI

GHSA-jgpv-4h4c-xhw3

Uncontrolled Resource Consumption in pillow

HIGH 7.5
PyPI

CVE-2014-3598

Pillow is vulnerable to Denial of Service (DOS) in the Jpeg2KImagePlugin

HIGH 7.5
PyPI

CVE-2022-30595

Buffer over-flow in Pillow

CRITICAL 9.8
PyPI

CVE-2022-30595

CVE-2022-30595

HIGH 7.5
PyPI

CVE-2021-28677

Uncontrolled Resource Consumption in Pillow

MEDIUM 5.5
PyPI

CVE-2021-28678

Insufficient Verification of Data Authenticity in Pillow

HIGH 7.5
PyPI

CVE-2023-44271

Pillow Denial of Service vulnerability

HIGH 7.5
PyPI

CVE-2022-45199

Pillow subject to DoS via SAMPLESPERPIXEL tag

CRITICAL 9.1
PyPI

CVE-2022-24303

Path traversal in Pillow

HIGH 8.8
PyPI

CVE-2020-35654

Pillow Out-of-bounds Write

HIGH 7.5
PyPI

CVE-2022-45198

Pillow vulnerable to Data Amplification attack.

MEDIUM 6.5
PyPI

CVE-2022-22816

Out-of-bounds Read in Pillow

MEDIUM 6.5
PyPI

CVE-2022-22815

Improper Initialization in Pillow

CRITICAL 9.8
PyPI

CVE-2022-22817

Arbitrary expression injection in Pillow

HIGH 7.5
PyPI

CVE-2021-28676

Potential infinite loop in Pillow

MEDIUM 5.5
PyPI

CVE-2020-10177

Out-of-bounds reads in Pillow

CRITICAL 9.1
PyPI

CVE-2021-25288

Pillow Out-of-bounds Read vulnerability

HIGH 7.5
PyPI

CVE-2021-25291

Out of bounds read in Pillow

MEDIUM 5.5
PyPI

CVE-2016-3076

Pillow Buffer overflow in Jpeg2KEncode.c

CRITICAL 9.1
PyPI

CVE-2021-25287

Out-of-bounds Read in Pillow

MEDIUM 6.5
PyPI

CVE-2021-25292

Regular Expression Denial of Service (ReDoS) in Pillow

HIGH 7.5
PyPI

CVE-2019-16865

DOS attack in Pillow when processing specially crafted image files

CRITICAL 9.8
PyPI

CVE-2014-3007

Pillow command injection

CRITICAL 9.8
PyPI

CVE-2021-34552

Buffer Overflow in Pillow

HIGH 7.5
PyPI

CVE-2021-23437

Uncontrolled Resource Consumption in pillow

HIGH 7.5
PyPI

CVE-2014-9601

Pillow denial of service via PNG bomb

MEDIUM 6.5
PyPI

CVE-2016-0775

Pillow Buffer overflow in ImagingFliDecode

HIGH 7.5
PyPI

CVE-2021-25293

Out of bounds read in Pillow

HIGH 7.7
PyPI

CVE-2014-1932

PIL and Pillow Vulnerable to Symlink Attack on Tmpfiles

MEDIUM 5.5
PyPI

CVE-2021-28675

Pillow denial of service

HIGH 8.1
PyPI

CVE-2020-11538

Out-of-bounds read in Pillow

MEDIUM 5.5
PyPI

CVE-2020-10994

Out-of-bounds reads in Pillow

MEDIUM 6.5
PyPI

CVE-2016-0740

Pillow Buffer overflow in ImagingLibTiffDecode

CRITICAL 9.8
PyPI

CVE-2020-5312

PCX P mode buffer overflow in Pillow

HIGH 7.5
PyPI

CVE-2021-25290

Out-of-bounds Write in Pillow

HIGH 7.5
PyPI

CVE-2014-3589

Pillow denial of service via Crafted Block Size

MEDIUM 5.4
PyPI

CVE-2020-35655

Pillow Out-of-bounds Read

CRITICAL 9.8
PyPI

CVE-2020-5311

Buffer Copy without Checking Size of Input in Pillow

HIGH 7.5
PyPI

CVE-2019-19911

Uncontrolled Resource Consumption in Pillow

HIGH 8.8
PyPI

CVE-2020-5310

Integer overflow in Pillow

MEDIUM 5.5
PyPI

CVE-2016-9189

Pillow Integer overflow in Map.c

CRITICAL 9.8
PyPI

CVE-2021-25289

Out of bounds write in Pillow

HIGH 7.1
PyPI

CVE-2020-35653

Pillow Out-of-bounds Read

CRITICAL 9.8
PyPI

CVE-2016-4009

Pillow Integer overflow in ImagingResampleHorizontal

HIGH 7.1
PyPI

CVE-2020-5313

Out-of-bounds Read in Pillow

HIGH 7.8
PyPI

CVE-2016-9190

Arbitrary code using "crafted image file" approach affecting Pillow

UNKNOWN
PyPI

CVE-2022-24303

CVE-2022-24303

UNKNOWN
PyPI

CVE-2022-22817

CVE-2022-22817

UNKNOWN
PyPI

CVE-2022-22816

CVE-2022-22816

UNKNOWN
PyPI

CVE-2022-22815

CVE-2022-22815

UNKNOWN
PyPI

CVE-2021-34552

CVE-2021-34552

UNKNOWN
PyPI

CVE-2021-28678

CVE-2021-28678

UNKNOWN
PyPI

CVE-2021-28677

CVE-2021-28677

UNKNOWN
PyPI

CVE-2021-28676

CVE-2021-28676

UNKNOWN
PyPI

CVE-2021-28675

CVE-2021-28675

UNKNOWN
PyPI

CVE-2021-27923

CVE-2021-27923

UNKNOWN
PyPI

CVE-2021-27922

CVE-2021-27922

UNKNOWN
PyPI

CVE-2021-27921

CVE-2021-27921

UNKNOWN
PyPI

CVE-2021-25293

CVE-2021-25293

UNKNOWN
PyPI

CVE-2021-25292

CVE-2021-25292

UNKNOWN
PyPI

CVE-2021-25291

CVE-2021-25291

UNKNOWN
PyPI

CVE-2021-25290

CVE-2021-25290

UNKNOWN
PyPI

CVE-2021-25289

CVE-2021-25289

UNKNOWN
PyPI

CVE-2021-25288

CVE-2021-25288

UNKNOWN
PyPI

CVE-2021-25287

CVE-2021-25287

UNKNOWN
PyPI

CVE-2021-23437

CVE-2021-23437

Ready to move

Start Securing

Free, no credit card | First findings in minutes