Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

CRITICAL 9.8
PyPI

CVE-2022-37454

Buffer overflow in sponge queue functions

CRITICAL 9.1
PyPI

CVE-2024-46488

Heap-based Buffer Overflow in sqlite-vec

CRITICAL 9.8
PyPI

CVE-2025-65896

asyncmy is vulnerable to SQL injection via crafted dict keys

CRITICAL 9.4
PyPI

CVE-2026-52830

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

CRITICAL 9.8
PyPI

CVE-2026-50027

mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete

CRITICAL 9.1
PyPI

CVE-2016-8638

Session Fixation in ipsilon

CRITICAL 9.8
PyPI

CVE-2024-47533

cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes

CRITICAL 9.1
PyPI

CVE-2026-28370

OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection

CRITICAL 9.6
PyPI

CVE-2024-38824

Salt vulnerable to directory traversal attack in file receiving method

CRITICAL 9.8
PyPI

CVE-2023-32321

Ckan remote code execution and private information access via crafted resource ids

CRITICAL 9.9
PyPI

CVE-2024-21669

Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC

CRITICAL 9.1
PyPI

CVE-2026-47731

NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)

CRITICAL 9.8
PyPI

CVE-2025-49652

BackendAI Missing Authentication for Critical Function

CRITICAL 9.9
PyPI

CVE-2026-29090

Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API

CRITICAL 9.9
PyPI

CVE-2026-29080

Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API

CRITICAL 9.8
PyPI

CVE-2025-2000

Qiskit allows arbitrary code execution decoding QPY format versions < 13

CRITICAL 9.8
PyPI

CVE-2026-44484

Compromise of PyTorch Lightning PyPi Package Versions

CRITICAL 9.1
PyPI

CVE-2015-8914

OpenStack Neutron allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism

CRITICAL 9.3
PyPI

CVE-2025-68664

LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs

CRITICAL 9.8
PyPI

CVE-2017-7214

OpenStack Nova logs sensitive context from notification exceptions

CRITICAL 9.1
PyPI

CVE-2019-15753

OpenStack os-vif Ageing time of 0 disables linuxbridge MAC learning

CRITICAL 9.1
PyPI

CVE-2019-17134

OpenStack Octavia Amphora-Agent not requiring Client-Certificate

CRITICAL 9.6
PyPI

CVE-2026-40088

PraisonAI Vulnerable to OS Command Injection

CRITICAL 9.8
PyPI

CVE-2026-25879

Langroid has Prompt to SQL Injection, Leading to RCE

CRITICAL 9.8
PyPI

CVE-2025-46724

Langroid has a Code Injection vulnerability in TableChatAgent

CRITICAL 9.8
PyPI

CVE-2022-34558

CVE-2022-34558

CRITICAL 9.6
PyPI

CVE-2026-44336

PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection

CRITICAL 9.9
PyPI

CVE-2026-55166

Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise

CRITICAL 9.8
PyPI

CVE-2023-40889

Heap-based buffer overflow in ZBar

CRITICAL 9.9
PyPI

CVE-2026-43948

wger: cross-tenant password reset and plaintext disclosure via gym=None bypass

CRITICAL 9.8
PyPI

CVE-2022-2650

wger vulnerable to brute force attempts

CRITICAL 9.8
PyPI

CVE-2018-25082

weixin-python XML External Entity vulnerability

CRITICAL 9.1
PyPI

CVE-2025-68398

Weblate is vulnerable to RCE through Git config file overwrite

CRITICAL 9.8
PyPI

CVE-2016-3953

web2py remote code execution via hardcoded encryption key in session.connect function

CRITICAL 9.8
PyPI

CVE-2016-10321

web2py is vulnerable to password brute-force attack

CRITICAL 9.8
PyPI

CVE-2024-9052

vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object

CRITICAL 9.8
PyPI

CVE-2025-47277

vLLM Allows Remote Code Execution via PyNcclPipe Communication Service

CRITICAL 9.8
PyPI

CVE-2024-11041

vLLM Deserialization of Untrusted Data vulnerability

CRITICAL 9.8
PyPI

CVE-2026-22778

vLLM has RCE In Video Processing

CRITICAL 9.8
PyPI

CVE-2024-5826

vanna vulnerable to remote code execution caused by prompt injection

CRITICAL 10.0
PyPI

CVE-2026-45369

utcp-cli Vulnerable to Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol

CRITICAL 9.8
PyPI

CVE-2026-30625

Upsonic: remote code execution vulnerability in its MCP server/task creation functionality

CRITICAL 9.8
PyPI

CVE-2025-64712

Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write

CRITICAL 9.8
PyPI

CVE-2026-22584

Salesforce Uni2TS has a Code Injection vulnerability

CRITICAL 9.8
PyPI

CVE-2019-25101

Header injection in TurboGears

CRITICAL 9.1
PyPI

CVE-2023-33175

toui allows user-specific variables to be shared between users

CRITICAL 9.8
PyPI

CVE-2024-35198

TorchServe vulnerable to bypass of allowed_urls configuration

CRITICAL 9.8
PyPI

CVE-2023-43654

TorchServe Server-Side Request Forgery vulnerability

CRITICAL 9.8
PyPI

CVE-2025-55037

TkEasyGUI Vulnerable to OS Command Injection

CRITICAL 10.0
PyPI

CVE-2025-61492

terminal-controller-mcp vulnerable to Command Injection

CRITICAL 9.8
PyPI

CVE-2023-25668

TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation

CRITICAL 9.8
PyPI

CVE-2024-0937

Deserialization of untrusted data in synthcity

CRITICAL 9.8
PyPI

CVE-2026-31220

PySyft server-side arbitrary Python execution after code approval

CRITICAL 9.8
PyPI

CVE-2012-4406

OpenStack Object Storage (swift) Code Injection vulnerability

CRITICAL 10.0
PyPI

CVE-2025-14931

Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE

CRITICAL 9.9
PyPI

CVE-2025-5120

smolagents has Sandbox Escape Vulnerability in the local_python_executor.py Module

CRITICAL 9.3
PyPI

CVE-2022-31558

Tooxie Shiva 0.10.0 allows absolute path traversal because Flask send_file function used unsafely

Ready to move

Start Securing

Free, no credit card | First findings in minutes