Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Malicious code in runtime-vitals (PyPI)
Malicious code in quicklytookerv (PyPI)
CVE-2026-44513
Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components
CVE-2026-44520
docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler
CVE-2026-44504
Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR)
CVE-2026-44503
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
CVE-2026-44484
Compromise of PyTorch Lightning PyPi Package Versions
CVE-2026-44264
Weblate vulnerable to XSS via crafted Markdown
CVE-2026-44263
Weblate Vulnerable to Private Translation Enumeration via Screenshot API
CVE-2026-44439
Playwright Capture permits access to local files and internal network resources during page capture
axonflow-sdk-python: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
CVE-2026-0897
Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)
CVE-2026-44368
pyquorum: Timing side‑channel in mul_mod
CVE-2026-44364
misp-modules website - Missing CSRF protection in the website home blueprint
CVE-2026-44363
misp-modules has nsafe remote resource fetching in expansion
CVE-2026-44334
PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)
CVE-2026-44335
PraisonAI has an SSRF bypass
aiograpi has dependency on vulnerable orjson 3.11.4 (CVE-2025-67221)
CVE-2026-44244
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
CVE-2026-42561
python-multipart has Denial of Service via unbounded multipart part headers
Showing 1 - 20 of 1,000+ results