Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

pypi Security Advisories

Loading...
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZjM2otYzY0bS1xaGdx
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
Ecosystems: maven, nuget, npm, pypi, rubygems
Packages: org.webjars.npm:jquery, jQuery, jquery, django, jquery-rails
Source: GitHub Advisory Database
Blast Radius: 135.8
Published: about 5 years ago
High
GSA_kwCzR0hTQS1qN2hwLWg4angtNXBwcs4AA10j
libwebp: OOB write in BuildHuffmanTable
Ecosystems: nuget, cargo, pypi, go, npm
Packages: magick.net-q8-x64, magick.net-q8-openmp-x64, magick.net-q8-anycpu, magick.net-q16-x64, magick.net-q16-hdri-anycpu, magick.net-q16-anycpu, webp, Pillow, github.com/chai2010/webp, SkiaSharp, electron, libwebp-sys, libwebp-sys2
Source: GitHub Advisory Database
Blast Radius: 130.8
Published: 8 months ago
High
GSA_kwCzR0hTQS03N3JtLTl4OWgteGozZ80mxQ
NULL Pointer Dereference in Protocol Buffers
Ecosystems: maven, pypi, go, packagist, nuget
Packages: com.google.protobuf:protobuf-java, protobuf, github.com/protocolbuffers/protobuf, google/protobuf, Google.Protobuf
Source: GitHub Advisory Database
Blast Radius: 111.3
Published: over 2 years ago
High
GSA_kwCzR0hTQS1qd3Z3LXY3YzUtbTgyaM3tlQ
protobuf susceptible to buffer overflow
Ecosystems: pypi, packagist, go, maven, nuget
Packages: protobuf, google/protobuf, github.com/protocolbuffers/protobuf, com.google.protobuf:protobuf-parent, Google.Protobuf
Source: GitHub Advisory Database
Blast Radius: 94.2
Published: almost 2 years ago
High
GSA_kwCzR0hTQS02NjI4LXE2ajktdzh2Z84AA0dX
gRPC Reachable Assertion issue
Ecosystems: rubygems, pypi, maven
Packages: grpc, grpcio, io.grpc:grpc-protobuf
Source: GitHub Advisory Database
Blast Radius: 89.7
Published: 10 months ago
High
GSA_kwCzR0hTQS1jZmdwLTI5NzctMmZtbc4AA0N9
Connection confusion in gRPC
Ecosystems: rubygems, pypi, maven
Packages: grpc, grpcio, io.grpc:grpc-protobuf
Source: GitHub Advisory Database
Blast Radius: 88.5
Published: 10 months ago
Moderate
GSA_kwCzR0hTQS01ODQ0LXEzZmMtNTZyaM4AA3lZ
pubnub Insufficient Entropy vulnerability
Ecosystems: swift, pypi, pub, packagist, cargo, rubygems, nuget, go, maven, npm
Packages: github.com/pubnub/swift, pubnub, pubnub/pubnub, Pubnub, github.com/pubnub/go/v5, github.com/pubnub/go/v6, github.com/pubnub/go, github.com/pubnub/go/v7, com.pubnub:pubnub, com.pubnub:pubnub-kotlin
Source: GitHub Advisory Database
Blast Radius: 82.5
Published: 5 months ago
Moderate
GSA_kwCzR0hTQS1yOGhtLXc1Zjctd2ozOc0Wzg
Cross-site scripting vulnerability in TinyMCE plugins
Ecosystems: pypi, nuget, packagist, npm
Packages: django-tinymce, TinyMCE, tinymce/tinymce, tinymce
Source: GitHub Advisory Database
Blast Radius: 64.7
Published: over 2 years ago
High
GSA_kwCzR0hTQS14NHFyLTJmdmYtM21yNc4AAxfn
Vulnerable OpenSSL included in cryptography wheels
Ecosystems: cargo, pypi
Packages: openssl-src, cryptography
Source: GitHub Advisory Database
Blast Radius: 64.2
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS00NXg3LXB4MzYteDh3OM4AA34H
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Ecosystems: pypi, go, cargo
Packages: paramiko, golang.org/x/crypto, russh
Source: GitHub Advisory Database
Blast Radius: 63.5
Published: 5 months ago
Moderate
GSA_kwCzR0hTQS05aHhmLXBwanYtdzZycc4AA0dy
gRPC connection termination issue
Ecosystems: rubygems, pypi, maven
Packages: grpc, grpcio, io.grpc:grpc-protobuf
Source: GitHub Advisory Database
Blast Radius: 63.4
Published: 10 months ago
High
GSA_kwCzR0hTQS1wMjVtLWpwajQtcWNycs4AA127
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
Ecosystems: pypi, rubygems
Packages: grpcio, grpc
Source: GitHub Advisory Database
Blast Radius: 61.2
Published: 8 months ago
Critical
GSA_kwCzR0hTQS05ZnEyLXg5cjYtd2ZtZs4AAq9p
Numpy Deserialization of Untrusted Data
Ecosystems: pypi
Packages: numpy
Source: GitHub Advisory Database
Blast Radius: 55.7
Published: almost 2 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXd3dzItdjd4ai14cmM2
Exposure of Sensitive Information to an Unauthorized Actor in urllib3
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 55.1
Published: over 5 years ago
High
GSA_kwCzR0hTQS1yaHJ2LTY0NWgtZmpmaM4AA2Jb
Apache Avro Java SDK vulnerable to Improper Input Validation
Ecosystems: pypi, maven
Packages: avro, org.apache.avro:avro
Source: GitHub Advisory Database
Blast Radius: 54.2
Published: 7 months ago
Critical
GSA_kwCzR0hTQS1qanc1LXh4ajYtcGN2Nc4AAktO
scikit-learn Deserialization of Untrusted Data
Ecosystems: pypi
Packages: scikit-learn
Source: GitHub Advisory Database
Blast Radius: 50.5
Published: almost 2 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNwcXgtNGZxZi1qNDlm
Deserialization of Untrusted Data in PyYAML
Ecosystems: pypi
Packages: pyyaml
Source: GitHub Advisory Database
Blast Radius: 49.9
Published: about 3 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThxNTktcTY4aC02aHY0
Improper Input Validation in PyYAML
Ecosystems: pypi
Packages: PyYAML
Source: GitHub Advisory Database
Blast Radius: 49.9
Published: about 3 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTY3NTctanA4NC1neGZ4
Improper Input Validation in PyYAML
Ecosystems: pypi
Packages: pyyaml
Source: GitHub Advisory Database
Blast Radius: 49.9
Published: about 3 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJwcnctaDYydi1jMnc3
PyYAML insecurely deserializes YAML strings leading to arbitrary code execution
Ecosystems: pypi
Packages: pyyaml
Source: GitHub Advisory Database
Blast Radius: 49.9
Published: over 5 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhtcjQtbTJoNS0zM3F4
SQL injection in Django
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: about 4 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhwZnAtZjU2OS1xM3Ay
SQL Injection in Django
Ecosystems: pypi
Packages: Django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: over 2 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZyOTctY2o1NS05aHJx
SQL Injection in Django
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: over 4 years ago
Critical
GSA_kwCzR0hTQS1tdjhnLWZoaDYtNjI2N84AAYRT
Django user with hardcoded password created when running tests on Oracle
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: almost 2 years ago
Critical
GSA_kwCzR0hTQS1yM3hjLXByZ3ItbWc5cM4AAzG9
Django bypasses validation when using one form field to upload multiple files
Ecosystems: pypi
Packages: Django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: 12 months ago
Critical
GSA_kwCzR0hTQS0yZ3dqLTdqbXYtaDI2cs07Ng
SQL Injection in Django
Ecosystems: pypi
Packages: Django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: about 2 years ago
Critical
GSA_kwCzR0hTQS1wNjR4LThyeHgtd2Y2cc4AAtF-
Django `Trunc()` and `Extract()` database functions vulnerable to SQL Injection
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: almost 2 years ago
Critical
GSA_kwCzR0hTQS13MjRoLXY5cWgtOGd4as07NQ
SQL Injection in Django
Ecosystems: pypi
Packages: Django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: about 2 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZmcTYtaHE1ci0yN3I2
Django Potential account hijack via password reset form
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 49.6
Published: over 4 years ago
High
GSA_kwCzR0hTQS1janc0LTJ3OXItcjhtds4AAinR
Missing Initialization of Resource in Apache Arrow
Ecosystems: pypi, rubygems
Packages: pyarrow, red-arrow
Source: GitHub Advisory Database
Blast Radius: 49.0
Published: almost 2 years ago
High
GSA_kwCzR0hTQS04Y3cyLWp2NWMtYzgyNc4AAina
Missing Initialization of Resource in Apache Arrow
Ecosystems: pypi, rubygems
Packages: pyarrow, red-arrow
Source: GitHub Advisory Database
Blast Radius: 49.0
Published: almost 2 years ago
Critical
GSA_kwCzR0hTQS02dzRtLTJ4aGctMjY1OM4AAy-v
Buffer overflow in sponge queue functions
Ecosystems: rubygems, pypi
Packages: sha3, pysha3
Source: GitHub Advisory Database
Blast Radius: 48.7
Published: about 1 year ago
Critical
GSA_kwCzR0hTQS00N2ZjLXZtd3EtMzY2ds4AAwDK
PyTorch vulnerable to arbitrary code execution
Ecosystems: pypi
Packages: torch
Source: GitHub Advisory Database
Blast Radius: 48.6
Published: over 1 year ago
Critical
GSA_kwCzR0hTQS03NTM0LW1tNDUtYzc0ds0WKQ
Buffer Overflow in Pillow
Ecosystems: pypi
Packages: pillow
Source: GitHub Advisory Database
Blast Radius: 48.5
Published: over 2 years ago
Critical
GSA_kwCzR0hTQS04dmoyLXZ4eDMtNjY3d80hfA
Arbitrary expression injection in Pillow
Ecosystems: pypi
Packages: Pillow
Source: GitHub Advisory Database
Blast Radius: 48.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS1wNDloLWhqdm0tamczaM0W2w
PCX P mode buffer overflow in Pillow
Ecosystems: pypi
Packages: Pillow
Source: GitHub Advisory Database
Blast Radius: 48.5
Published: over 2 years ago
Critical
GSA_kwCzR0hTQS1yN3JtLThqNmgtcjkzM84AAjLe
Buffer Copy without Checking Size of Input in Pillow
Ecosystems: pypi
Packages: pillow
Source: GitHub Advisory Database
Blast Radius: 48.5
Published: almost 2 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWh2cjgtNDY2cC03NXJo
Pillow Integer overflow in ImagingResampleHorizontal
Ecosystems: pypi
Packages: Pillow
Source: GitHub Advisory Database
Blast Radius: 48.5
Published: almost 6 years ago
Critical
GSA_kwCzR0hTQS02aHJnLXFtdmMtMnhoOM4AAvFP
joblib vulnerable to arbitrary code execution
Ecosystems: pypi
Packages: joblib
Source: GitHub Advisory Database
Blast Radius: 47.9
Published: over 1 year ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW05bXEtcDJmOS1jZnF2
Bleach URI Scheme Restriction Bypass
Ecosystems: pypi
Packages: bleach
Source: GitHub Advisory Database
Blast Radius: 47.8
Published: over 5 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWh3dnEtNmdqeC1qNzk3
Special Element Injection in notebook
Ecosystems: pypi
Packages: notebook
Source: GitHub Advisory Database
Blast Radius: 47.8
Published: over 2 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW13NnYtY3JoOC04NTMz
Integer Overflow or Wraparound in Google TensorFlow
Ecosystems: pypi
Packages: tensorflow
Source: GitHub Advisory Database
Blast Radius: 47.7
Published: about 5 years ago
Critical
GSA_kwCzR0hTQS1ndzk3LWZmN2MtOXY5Ns4AAyT8
TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 47.7
Published: about 1 year ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJobTktcDl3NS1md203
PyCA Cryptography symmetrically encrypting large values can lead to integer overflow
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 46.6
Published: about 3 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg4N3ctNDVycS12eGdm
SQLAlchemy vulnerable to SQL Injection via order_by parameter
Ecosystems: pypi
Packages: SQLAlchemy
Source: GitHub Advisory Database
Blast Radius: 46.3
Published: about 5 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXI2angtOWc0OC0ycjVy
Arbitrary code execution due to YAML deserialization
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 45.8
Published: over 2 years ago
Critical
GSA_kwCzR0hTQS1oNmd3LXI1MmMtNzI0cs0oig
NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 45.8
Published: about 2 years ago
Critical
GSA_kwCzR0hTQS01N3d4LW05ODMtMmY4OM0XCw
Incomplete validation in boosted trees code
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 45.8
Published: over 2 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNnNzUtNjkzOC13eDU4
python-docutils allows insecure usage of temporary files
Ecosystems: pypi
Packages: docutils
Source: GitHub Advisory Database
Blast Radius: 45.6
Published: about 4 years ago
High
GSA_kwCzR0hTQS03ZmMyLXJtMzUtMnBwN84AAYcY
IPython vulnerable to cross site request forgery (CSRF)
Ecosystems: pypi
Packages: ipython
Source: GitHub Advisory Database
Blast Radius: 45.1
Published: almost 2 years ago
Critical
GSA_kwCzR0hTQS05ajU5LTc1cWotNzk1d80yIg
Path traversal in Pillow
Ecosystems: pypi
Packages: Pillow
Source: GitHub Advisory Database
Blast Radius: 45.0
Published: about 2 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc3Z2MtdjJ4di1ydnZo
Out-of-bounds Read in Pillow
Ecosystems: pypi
Packages: Pillow
Source: GitHub Advisory Database
Blast Radius: 45.0
Published: almost 3 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJ3djctM3Y0NS1oZzI5
Out-of-bounds Read
Ecosystems: pypi
Packages: Pillow
Source: GitHub Advisory Database
Blast Radius: 45.0
Published: almost 3 years ago
Critical
GSA_kwCzR0hTQS14N20zLWpwcmctd2M1Z84AA2Bl
Gevent allows remote attacker to escalate privileges
Ecosystems: pypi
Packages: gevent
Source: GitHub Advisory Database
Blast Radius: 44.7
Published: 7 months ago
High
GSA_kwCzR0hTQS13M2gzLTRyajctNHBoNM4AA7B3
Request smuggling leading to endpoint restriction bypass in Gunicorn
Ecosystems: pypi
Packages: gunicorn
Source: GitHub Advisory Database
Blast Radius: 44.6
Published: 18 days ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNnaDIteHc3NC1qbWN3
SQL injection in Django
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 44.5
Published: almost 4 years ago
High
GSA_kwCzR0hTQS04eDk0LWhtamgtOTdocc4AAt78
Django vulnerable to Reflected File Download attack
Ecosystems: pypi
Packages: Django
Source: GitHub Advisory Database
Blast Radius: 44.5
Published: over 1 year ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc3cDUtNTc1OS1xdjQ2
Data leak in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 44.3
Published: over 3 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc1Z2gtMndyMi1wbTZn
Denial of Service in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 44.3
Published: over 3 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg2ZmctbWp4Zy1ocXE0
Integer truncation in Shard API usage
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 44.3
Published: over 3 years ago
Critical
GSA_kwCzR0hTQS05amp3LWhmNzItM214d84AAvMC
TensorFlow vulnerable to heap out of bounds read in filesystem glob matching
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 44.3
Published: over 1 year ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhqMmotNzd4bS1tYzV2
High severity vulnerability that affects Jinja2
Ecosystems: pypi
Packages: Jinja2
Source: GitHub Advisory Database
Blast Radius: 44.1
Published: about 5 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTQ2Mnctdjk3ci00bTQ1
Jinja2 sandbox escape via string formatting
Ecosystems: pypi
Packages: Jinja2
Source: GitHub Advisory Database
Blast Radius: 44.1
Published: about 5 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTIzMnItNjZjZy03OXB4
Paramiko not properly checking authentication before processing other requests
Ecosystems: pypi
Packages: paramiko
Source: GitHub Advisory Database
Blast Radius: 44.0
Published: almost 6 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNxMjctdjd4cC1jMzU2
Buffer Overflow in pycrypto
Ecosystems: pypi
Packages: pycrypto
Source: GitHub Advisory Database
Blast Radius: 43.9
Published: over 5 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg4NHYteGNtMi01M3Bn
Insufficiently Protected Credentials in Requests
Ecosystems: pypi
Packages: requests
Source: GitHub Advisory Database
Blast Radius: 43.7
Published: over 5 years ago
Critical
GSA_kwCzR0hTQS1mZmY4LTR3OXAtN3Y3Ns4AAbau
Command Injection in Pygments
Ecosystems: pypi
Packages: Pygments
Source: GitHub Advisory Database
Blast Radius: 43.6
Published: almost 2 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZxY2otd3JmMi03djcz
Pillow Out-of-bounds Write
Ecosystems: pypi
Packages: Pillow
Source: GitHub Advisory Database
Blast Radius: 43.6
Published: about 3 years ago
High
GSA_kwCzR0hTQS12Y3FnLTNwMjkteHc3M80W2Q
Integer overflow in Pillow
Ecosystems: pypi
Packages: Pillow
Source: GitHub Advisory Database
Blast Radius: 43.6
Published: over 2 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU3aDMtOXJnci1jMjRt
Out of bounds write in Pillow
Ecosystems: pypi
Packages: Pillow
Source: GitHub Advisory Database
Blast Radius: 43.6
Published: about 3 years ago
Critical
GSA_kwCzR0hTQS1wcjc2LTVjbTUtdzljas4AA1Py
GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments
Ecosystems: pypi
Packages: GitPython
Source: GitHub Advisory Database
Blast Radius: 43.5
Published: 9 months ago
High
GSA_kwCzR0hTQS12ampwLTlyODMtMjJyY84AAe3i
Django Directory Traversal via ssi template tag
Ecosystems: pypi
Packages: django
Source: GitHub Advisory Database
Blast Radius: 43.5
Published: almost 2 years ago
Critical
GSA_kwCzR0hTQS01d3ZwLTdmM2gtNndtbc4AA3Am
PyArrow: Arbitrary code execution when loading a malicious data file
Ecosystems: pypi
Packages: pyarrow
Source: GitHub Advisory Database
Blast Radius: 42.9
Published: 6 months ago
High
GSA_kwCzR0hTQS05OHA1LXg4eDQtYzltNc0ofw
Integer overflow in TFLite
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 42.8
Published: about 2 years ago
High
GSA_kwCzR0hTQS00aHZmLWh4dmctZjY3ds0ogA
Read and Write outside of bounds in TensorFlow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 42.8
Published: about 2 years ago
High
GSA_kwCzR0hTQS05eDUyLTg4N2ctZmhjMs0oqw
Out of bounds read in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 42.8
Published: about 2 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZyeHgtMm0zMy02d2Ny
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
Ecosystems: pypi
Packages: tensorflow
Source: GitHub Advisory Database
Blast Radius: 42.8
Published: about 5 years ago
High
GSA_kwCzR0hTQS03N2dwLTNoNHItNjQyOM0ouA
Out of bounds read and write in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 42.8
Published: about 2 years ago
High
GSA_kwCzR0hTQS04amo3LTV2eGMtcGcycc0otA
Integer overflow in TensorFlow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 42.8
Published: about 2 years ago
High
GSA_kwCzR0hTQS05Yzc4LXZjcTctN3Z4cc0ogQ
Out of bounds write in TFLite
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 42.8
Published: about 2 years ago
High
GSA_kwCzR0hTQS01cXc1LTg5bXctd2NnMs0ohQ
Out of bounds write in Tensorflow
Ecosystems: pypi
Packages: tensorflow-gpu, tensorflow-cpu, tensorflow
Source: GitHub Advisory Database
Blast Radius: 42.8
Published: about 2 years ago
High
GSA_kwCzR0hTQS1mcmd3LWZnaDYtOWc1Ms4AASAP
Numpy missing input validation
Ecosystems: pypi
Packages: numpy
Source: GitHub Advisory Database
Blast Radius: 42.7
Published: almost 2 years ago
High
GSA_kwCzR0hTQS01NTQ1LTJxNnctMmdoNs0c3A
NumPy NULL Pointer Dereference
Ecosystems: pypi
Packages: numpy
Source: GitHub Advisory Database
Blast Radius: 42.7
Published: about 2 years ago
High
GSA_kwCzR0hTQS1wcTdtLTNndzctZ3E1eM0kfg
Execution with Unnecessary Privileges in ipython
Ecosystems: pypi
Packages: ipython
Source: GitHub Advisory Database
Blast Radius: 42.6
Published: over 2 years ago
High
GSA_kwCzR0hTQS12YzI5LXJqOTItZ2M3as0WUw
Out-of-bounds Write in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS1ycXhnLXh2Y3EtM3YyZs0WVA
Out-of-bounds Write in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS01cnBjLWd3aDktcTlmZ80WUg
Improper Restriction of Operations within the Bounds of a Memory Buffer in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS1xNzk5LXEyN3gtdnA3d80WOg
Out-of-bounds Write in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python-headless, opencv-contrib-python, opencv-python-headless, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS13cThmLXd2cXAteHZ2bc0WUQ
Integer Overflow or Wraparound in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS1jN2dwLTJwY2gtcWgyds0WVQ
Out-of-bounds Write in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS1tNDNjLTY0OW0tcG00OM0WTA
Integer Overflow or Wraparound in OpenCV.
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS13OTZnLTNwNjQtNjN3cs0WWA
Improper Restriction of Operations within the Bounds of a Memory Buffer in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS1mdnE2LTM5MmgtNm1qas0WWg
Out-of-bounds Read in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS0yNjd4LXc1aHgtOGhqcs0WUA
Integer Overflow or Wraparound in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS1tNnZtLThnOHYteGZqaM0WOw
Out-of-bounds Write in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python-headless, opencv-contrib-python, opencv-python-headless, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS1jdmh3LTI1OTMtNWoycc0WXg
Double Free in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS04dzN4LTQ1N3Itd2c1M80WXA
Out-of-bounds Write in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS0zM2gyLTY5ajMtcjMzNs0WWw
Out-of-bounds Read in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS02djZwLXA5N3YtZzJwN80WVg
Out-of-bounds Write in OpenCV
Ecosystems: pypi
Packages: opencv-contrib-python, opencv-python
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 2 years ago
High
GSA_kwCzR0hTQS1tNjc4LWYyNmotM2hycM4AAvjV
Execution with Unnecessary Privileges in JupyterApp
Ecosystems: pypi
Packages: jupyter-core
Source: GitHub Advisory Database
Blast Radius: 42.5
Published: over 1 year ago
Statistics
Advisories: 18,369
Packages: 8,294
Repositories: 764
Ecosystems: 12
Filter by Package
tensorflow 432 tensorflow-cpu 387 tensorflow-gpu 384 django 80 apache-airflow 78 ansible 63 salt 50 apache-superset 48 Plone 45 plone 43 rdiffweb 42 Pillow 41 vyper 38 matrix-synapse 35 mlflow 31 opencv-python 30 opencv-contrib-python 30 Django 27 moin 23 langchain 18 PaddlePaddle 17 mercurial 17 cobbler 17 pillow 16 nova 15 paddlepaddle 15 notebook 15 cryptography 15 gradio 14 modoboa 14 pyftpdlib 14 keystone 14 pyload-ng 14 neutron 13 OctoPrint 12 vantage6 12 glance 11 calibreweb 11 twisted 11 urllib3 11 aiohttp 11 onionshare-cli 11 trytond 10 wagtail 10 Flask-AppBuilder 10 zope 9 opencv-contrib-python-headless 9 opencv-python-headless 9 ethyca-fides 9 waitress 9 Zope 9 kiwitcms 9 trac 8 numpy 8 python-keystoneclient 8 aubio 8 roundup 8 nautobot 8 label-studio 8 swift 7 jupyter-server 7 pysaml2 7 pgadmin4 7 lief 7 scrapy 7 ipython 7 pip 7 matrix-sydent 7 mailman 6 apache-airflow-providers-apache-hive 6 lxml 6 Zope2 6 sentry 6 tuf 6 web2py 6 horizon 6 graphite-web 6 mindsdb 6 inventree 6 bleach 5 pyspark 5 saleor 5 lmdb 5 ckan 5 requests 5 python-gnupg 5 feedparser 5 whoogle-search 5 Products.CMFPlone 5 paramiko 5 cinder 5 jupyterhub 4 tripleo-heat-templates 4 bottle 4 Radicale 4 aws-iot-device-sdk-v2 4 Pygments 4 reportlab 4 software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk 4 markdown2 4 awsiotsdk 4 nltk 4 starlette 4 nvflare 4 datasette 4 Jinja2 4 ansible-core 4 transformers 4 esphome 4 httpie 4 Flask-Security-Too 4 grpc 4 keylime 4 grpcio 4 oauthenticator 4 FreeTAKServer-UI 4 tornado 4 PyPDF2 4 buildbot 4 pretix 4 werkzeug 4 GitPython 4 omero-web 4 yt-dlp 4 jwcrypto 4 qutebrowser 4 mistune 3 Mezzanine 3 gerapy 3 SQLAlchemy 3 copyparty 3 django-helpdesk 3 Werkzeug 3 dulwich 3 pyyaml 3 sanic 3 flask 3 pandasai 3 mayan-edms 3 barbican 3 aim 3 indy-node 3 protobuf 3 ryu 3 streamlit 3 httplib2 3 sosreport 3 zenml 3 sickrage 3 rsa 3 Weblate 3 ujson 3 openvpn-monitor 3 Keystone 3 pyarrow 3 Products.PluggableAuthService 3 changedetection.io 3 ajenti 3 fava 3 Moin 3 pycrypto 3 mitmproxy 3 keyring 3 io.grpc:grpc-protobuf 3 wger 3 apache-libcloud 3 ecdsa 3 plone.app.event 3 plone.app.theming 3 plone.app.dexterity 3 plone.supermodel 3 sqlparse 3 homeassistant 3 onnx 3 asyncua 3 torchserve 3 ansible-runner 3 localstack 3 poetry 3 bitlyshortener 3 indico 3 octavia 3 slixmpp 3 jupyterlab 3 clearml 3 docassemble.webapp 3 apache-iotdb 3 asyncssh 3 quokka 3 pywasm3 3 apache-airflow-providers-apache-spark 3 ray 3 python-jose 3 pymatgen 2 pyxdg 2 openapi-python-client 2 wagtail-2fa 2 zope2 2 py 2 ctx 2
Filter by Repository
https://github.com/tensorflow/tensorflow 432 https://github.com/apache/airflow 90 https://github.com/django/django 74 https://github.com/ansible/ansible 53 https://github.com/python-pillow/Pillow 52 https://github.com/ikus060/rdiffweb 42 https://github.com/vyperlang/vyper 38 https://github.com/plone/Products.CMFPlone 37 https://github.com/matrix-org/synapse 32 https://github.com/saltstack/salt 32 https://github.com/PaddlePaddle/Paddle 31 https://github.com/opencv/opencv 28 https://github.com/mlflow/mlflow 25 https://github.com/cobbler/cobbler 14 https://github.com/pyload/pyload 14 https://github.com/vantage6/vantage6 14 https://github.com/pyca/cryptography 14 https://github.com/langchain-ai/langchain 14 https://github.com/modoboa/modoboa 13 https://github.com/gradio-app/gradio 13 https://github.com/twisted/twisted 12 https://github.com/urllib3/urllib3 11 https://github.com/aio-libs/aiohttp 11 https://github.com/openstack/keystone 11 https://github.com/onionshare/onionshare 11 https://github.com/janeczku/calibre-web 11 https://github.com/jupyter/notebook 10 https://github.com/dpgaspar/Flask-AppBuilder 10 https://github.com/zopefoundation/Zope 10 https://github.com/wagtail/wagtail 10 https://github.com/giampaolo/pyftpdlib 9 https://github.com/Pylons/waitress 9 https://github.com/apache/superset 9 https://github.com/ethyca/fides 9 https://github.com/pgadmin-org/pgadmin4 9 https://github.com/scrapy/scrapy 8 https://github.com/nautobot/nautobot 8 https://github.com/octoprint/octoprint 8 https://github.com/numpy/numpy 8 https://github.com/kiwitcms/Kiwi 8 https://github.com/ipython/ipython 8 https://github.com/aubio/aubio 7 https://github.com/lief-project/LIEF 7 https://github.com/graphite-project/graphite-web 6 https://github.com/getsentry/sentry 6 https://github.com/jupyter-server/jupyter_server 6 https://github.com/lxml/lxml 6 https://github.com/pypa/pip 6 https://github.com/mindsdb/mindsdb 6 https://github.com/HumanSignal/label-studio 6 https://github.com/matrix-org/sydent 6 https://github.com/pallets/werkzeug 5 https://sourceforge.net/projects/sourceforge.net 5 https://github.com/openstack/nova 5 https://github.com/mozilla/bleach 5 https://github.com/TeamSeri0us/pocs 5 https://github.com/gitpython-developers/GitPython 5 https://github.com/hwchase17/langchain 5 https://github.com/tryton/trytond 5 https://github.com/keylime/keylime 5 https://github.com/OctoPrint/OctoPrint 5 https://github.com/openstack/horizon 5 https://github.com/benbusby/whoogle-search 5 https://github.com/yt-dlp/yt-dlp 4 https://github.com/jhpyle/docassemble 4 https://github.com/Flask-Middleware/flask-security 4 https://github.com/esphome/esphome 4 https://github.com/openstack/neutron 4 https://github.com/ckan/ckan 4 https://github.com/jupyterhub/oauthenticator 4 https://github.com/inventree/InvenTree 4 https://github.com/web2py/web2py 4 https://github.com/latchset/jwcrypto 4 https://github.com/aws/aws-iot-device-sdk-java-v2 4 https://github.com/WeblateOrg/weblate 4 https://github.com/Kozea/Radicale 4 https://github.com/huggingface/transformers 4 https://github.com/qutebrowser/qutebrowser 4 https://github.com/NVIDIA/NVFlare 4 https://github.com/rohe/pysaml2 4 https://github.com/ronf/asyncssh 4 https://github.com/py-pdf/pypdf 4 https://github.com/bottlepy/bottle 4 https://github.com/grpc/grpc 4 https://github.com/FreeTAKTeam/UI 4 https://github.com/simonw/datasette 4 https://github.com/tornadoweb/tornado 4 https://github.com/saleor/saleor 4 https://github.com/psf/requests 4 https://github.com/openstack/cinder 3 https://github.com/beancount/fava 3 https://github.com/encode/starlette 3 https://github.com/onnx/onnx 3 https://github.com/python/cpython 3 https://github.com/ome/omero-web 3 https://github.com/Cog-Creators/Red-DiscordBot 3 https://github.com/dgtlmoon/changedetection.io 3 https://github.com/paramiko/paramiko 3 https://github.com/pallets/jinja 3 https://github.com/rochacbruno/quokka 3 https://github.com/poezio/slixmpp 3 https://github.com/pallets/flask 3 https://github.com/django-helpdesk/django-helpdesk 3 https://github.com/run-llama/llama_index 3 https://github.com/pretix/pretix 3 https://github.com/openstack/swift 3 https://github.com/pytorch/serve 3 https://github.com/djblets/djblets 3 https://github.com/dlitz/pycrypto 3 https://github.com/openstack/python-keystoneclient 3 https://github.com/pyca/pyopenssl 3 https://github.com/openstack/octavia 3 https://github.com/pygments/pygments 3 https://github.com/pypa/advisory-db 3 https://github.com/openstack/glance 3 https://github.com/mitmproxy/mitmproxy 3 https://github.com/Gerapy/Gerapy 3 https://github.com/theupdateframework/python-tuf 3 https://github.com/theupdateframework/tuf 3 https://github.com/github/securitylab 3 https://github.com/ansible/ansible-runner 3 https://github.com/trentm/python-markdown2 3 https://github.com/gventuri/pandas-ai 3 https://github.com/andialbrecht/sqlparse 3 https://github.com/home-assistant/core 3 https://github.com/lepture/mistune 3 https://github.com/httplib2/httplib2 3 https://github.com/wasm3/wasm3 3 https://github.com/hyperledger/indy-node 3 https://github.com/IdentityPython/pysaml2 3 https://github.com/impredicative/bitlyshortener 3 https://github.com/yaml/pyyaml 3 https://github.com/9001/copyparty 3 https://github.com/zenml-io/zenml 3 https://github.com/indico/indico 3 https://github.com/jupyterlab/jupyterlab 3 https://github.com/jupyterhub/jupyterhub 3 https://github.com/streamlit/streamlit 3 https://github.com/sqlalchemy/sqlalchemy 3 https://github.com/mpdavis/python-jose 3 https://github.com/nltk/nltk 3 https://github.com/faucetsdn/ryu 3 https://github.com/moinwiki/moin-1.9 3 https://github.com/sosreport/sos 3 https://github.com/MobSF/Mobile-Security-Framework-MobSF 3 https://github.com/furlongm/openvpn-monitor 3 https://gitlab.com/mayan-edms/mayan-edms 3 https://github.com/Kozea/CairoSVG 2 https://github.com/DataDog/guarddog 2 https://github.com/dask/distributed 2 https://github.com/pretalx/pretalx 2 https://github.com/nexB/scancode.io 2 https://github.com/plone/Products.ATContentTypes 2 https://github.com/protocolbuffers/protobuf 2 https://github.com/ethereum/eth-abi 2 https://github.com/plone/plone.restapi 2 https://github.com/facebookresearch/ParlAI 2 https://github.com/IncludeSecurity/safeurl-python 2 https://github.com/cure53/DOMPurify 2 https://github.com/executablebooks/markdown-it-py 2 https://github.com/NVIDIA/NeMo 2 https://github.com/corydolphin/flask-cors 2 https://github.com/pyinstaller/pyinstaller 2 https://github.com/jupyterhub/jupyter-server-proxy 2 https://github.com/eventlet/eventlet 2 https://github.com/inventree/inventree 2 https://github.com/jrspruitt/ubi_reader 2 https://github.com/jpadilla/pyjwt 2 https://github.com/jelmer/dulwich 2 https://github.com/jdennis/keycloak-httpd-client-install 2 https://github.com/jaraco/keyring 2 https://github.com/openstack/magnum 2 https://github.com/mirumee/saleor 2 https://github.com/MirahezeBots/sopel-channelmgnt 2 https://github.com/geopython/OWSLib 2 https://github.com/moggers87/django-sendfile2 2 https://github.com/materialsproject/pymatgen 2 https://github.com/openstack/tripleo-heat-templates 2 https://github.com/goToMain/libosdp 2 https://github.com/marshmallow-code/webargs 2 https://github.com/django-wiki/django-wiki 2 https://github.com/OpenZeppelin/cairo-contracts 2 https://github.com/mongodb/mongo-python-driver 2 https://github.com/FreeTAKTeam/FreeTakServer 2 https://github.com/man-group/dtale 2 https://github.com/embedchain/embedchain 2 https://github.com/heartexlabs/label-studio 2 https://github.com/encode/uvicorn 2 https://github.com/html5lib/html5lib-python 2 https://github.com/FreeOpcUa/opcua-asyncio 2 https://github.com/httpie/httpie 2 https://github.com/Legrandin/pycryptodome 2 https://github.com/DIRACGrid/DIRAC 2 https://github.com/labd/wagtail-2fa 2 https://github.com/petl-developers/petl 2 https://github.com/Netflix/lemur 2 https://github.com/piccolo-orm/piccolo 2 https://github.com/devsnd/cherrymusic 2 https://github.com/dbt-labs/dbt-core 2