Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

LOW 2.3
PyPI

CVE-2026-62364

wlc may disclose API tokens to project-configured URLs

LOW 3.7
PyPI

CVE-2026-12372

CVE-2026-12372

LOW 3.3
PyPI

CVE-2026-54548

kas Persistently Disables SSH Host Key Checking

LOW 3.7
PyPI

CVE-2026-81723

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

LOW 2.5
PyPI

CVE-2026-71514

NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure

LOW 3.7
PyPI

CVE-2026-55403

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

LOW 3.1
PyPI

CVE-2026-48588

Django: cache middleware may expose private responses when unrelated request cookies are present

LOW 3.1
PyPI

CVE-2026-7666

Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake

LOW 3.7
PyPI

CVE-2026-53538

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

LOW 3.3
PyPI

CVE-2026-48156

pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams

LOW 3.4
PyPI

CVE-2026-44405

Paramiko rsakey.py allows the SHA-1 algorithm

LOW 3.3
PyPI

CVE-2026-4539

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

LOW 3.7
PyPI

GHSA-hqv3-xm29-p9hq

Duplicate Advisory: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

LOW 3.7
PyPI

CVE-2026-53540

python-multipart: Negative Content-Length in parse_form buffers the entire body in memory

LOW 3.7
PyPI

CVE-2026-53537

python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters

LOW 2.2
PyPI

CVE-2026-50266

OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks

LOW 3.7
PyPI

CVE-2026-54282

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

LOW 3.1
PyPI

CVE-2026-6873

Django: signed cookies are vulnerable to salt namespace collisions

LOW 3.7
PyPI

CVE-2026-48524

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

LOW 3.7
PyPI

CVE-2026-49854

Tornado has out-of-bounds memory access via C extension

LOW 3.1
PyPI

CVE-2026-48587

Django: has_vary_header may expose cached responses when Vary values contain whitespace

LOW 3.1
PyPI

CVE-2026-8404

Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

LOW 3.3
PyPI

CVE-2026-8088

OSGeo GDAL vulnerable to out-of-bounds read

LOW 2.7
PyPI

CVE-2026-4292

Django vulnerable to privilege abuse in ModelAdmin.list_editable

LOW 3.7
PyPI

CVE-2026-25674

Django has a Race Condition vulnerability

LOW 3.7
PyPI

CVE-2026-26013

LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

LOW 3.1
PyPI

CVE-2025-59682

Django vulnerable to partial directory traversal via archives

LOW 3.5
PyPI

CVE-2025-3777

Transformers's Improper Input Validation vulnerability can be exploited through username injection

LOW 3.3
PyPI

CVE-2025-3730

PyTorch Improper Resource Shutdown or Release vulnerability

LOW 3.3
PyPI

CVE-2025-2953

PyTorch susceptible to local Denial of Service

LOW 2.2
PyPI

CVE-2024-53861

PyJWT Issuer field partial matches allowed

LOW 3.6
PyPI

CVE-2024-45314

Flask-AppBuilder's login form allows browser to cache sensitive fields

LOW 3.5
PyPI

CVE-2024-8863

Aim Stored XSS through TEXT EXPLORER

LOW 3.7
PyPI

CVE-2023-23611

LTI 1.3 Grade Pass Back Implementation has Missing Authorization Vulnerability

LOW 3.8
PyPI

CVE-2024-41124

[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`

LOW 2.7
PyPI

CVE-2024-32882

Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`

LOW 3.9
PyPI

CVE-2024-34062

tqdm CLI arguments injection attack

LOW 2.7
PyPI

CVE-2024-32969

vantage6 collaboration admins can extend their influence by expanding the collaboration

LOW 2.3
PyPI

CVE-2024-34715

Fides Webserver Logs Hosted Database Password Partial Exposure Vulnerability

LOW 3.7
PyPI

CVE-2024-29199

Unauthenticated views may expose information to anonymous users

LOW 3.7
PyPI

CVE-2024-24559

Vyper sha3 codegen bug

LOW 3.3
PyPI

CVE-2023-49297

PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution

LOW 2.6
PyPI

CVE-2023-23934

Incorrect parsing of nameless cookies leads to __Host- cookies bypass

LOW 3.6
PyPI

CVE-2025-27145

copyparty renders unsanitized filenames as HTML when user uploads empty files

LOW 3.7
PyPI

CVE-2024-24560

Vyper's external calls can overflow return data to return input buffer

LOW 2.2
PyPI

CVE-2024-22194

cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code

LOW 3.5
PyPI

CVE-2024-22193

vantage6 may create unencrypted tasks in encrypted collaboration

LOW 3.9
PyPI

CVE-2023-46126

Fides JavaScript Injection Vulnerability in Privacy Center URL

LOW 3.3
PyPI

CVE-2023-41057

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-it

LOW 3.7
PyPI

CVE-2023-42458

Zope vulnerable to Stored Cross Site Scripting with SVG images

LOW 3.7
PyPI

CVE-2023-41335

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

LOW 3.5
PyPI

CVE-2023-2970

MindSpore vulnerable to memory corruption

LOW 3.7
PyPI

CVE-2024-23329

changedetection.io API endpoint is not secured with API token

LOW 3.7
PyPI

CVE-2023-50263

Unauthenticated db-file-storage views

LOW 3.1
PyPI

CVE-2023-44389

Zope management interface vulnerable to stored cross site scripting via the title property

LOW 3.1
PyPI

CVE-2023-42453

matrix-synapse vulnerable to improper validation of receipts allows forged read receipts

LOW 3.7
PyPI

CVE-2023-26112

configobj ReDoS exploitable by developer using values in a server-side configuration file

Ready to move

Start Securing

Free, no credit card | First findings in minutes