Vulnerability search
Batch lookup →66 matches
- CVE-2026-21441Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)2 sources· osv_advisoryhighEPSS 3%124.87.585.3%2026-07-07 16:03 UTC
- CVE-2026-44432urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API2 sources· osv_advisoryhighEPSS 0.7%98.77.549.9%2026-05-13 16:16 UTC
- CVE-2018-25032Nokogiri affected by zlib's Out-of-bounds Write vulnerability2 sources· osv_advisoryhighEPSS 52%97.97.598.9%2022-03-26 00:00 UTC
- CVE-2016-2183Sweet32 attack (DES, 3DES)highEPSS 96%97.47.599.9%2016-09-01 00:00 UTC
- CVE-2015-20107mailcap shell command injectionhighEPSS 7.1%95.27.693.7%2022-04-13 00:00 UTC
- CVE-2026-54058Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA…2 sources· osv_advisorycriticalEPSS 0.5%90.09.142.2%2026-07-23 11:41 UTC
- CVE-2026-3644Incomplete control character validation in http.cookies3 sources· osv_advisoryhighEPSS 0.5%78.17.539.4%2026-03-18 08:55 UTC
- CVE-2025-13462tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling3 sources· osv_advisorylowEPSS 0.2%73.63.35.9%2026-03-14 08:49 UTC
- CVE-2026-42311Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)2 sources· osv_advisoryhighEPSS 0.1%70.47.84.5%2026-05-09 06:16 UTC
- CVE-2026-4519webbrowser.open() allows leading dashes in URLs3 sources· osv_advisoryhighEPSS 0.3%69.17.123.1%2026-03-25 08:52 UTC
- CVE-2014-1912socket.recvfrom_into() overflownoneEPSS 28%58.8—98.0%2014-02-28 18:00 UTC
- CVE-2013-0340CVE-2013-0340 Billion Laughs fixed in Expat 2.4.0noneEPSS 19%58.3—97.2%2014-01-21 18:00 UTC
- CVE-2010-2089audioop input validationnoneEPSS 15%57.80.096.4%2010-05-27 19:00 UTC
- CVE-2007-4965rgbimg and imageop overflowsnoneEPSS 14%57.40.096.3%2007-09-18 22:00 UTC
- CVE-2019-9948urllib module local_file:// schemecriticalEPSS 12%57.49.195.8%2019-03-23 17:07 UTC
- CVE-2026-42310Pillow has a PDF Parsing Trailer Infinite Loop (DoS)2 sources· osv_advisorymediumEPSS 0.1%57.15.52.6%2026-07-13 15:02 UTC
- CVE-2019-9636urlsplit does not handle NFKC normalizationcriticalEPSS 8.8%56.79.894.8%2019-03-08 21:00 UTC
- CVE-2019-6690Improper Input Validation python-gnupg3 sources· osv_advisoryhighEPSS 8.6%56.67.594.7%2020-03-13 20:05 UTC
- CVE-2012-0876Expat 2.2.1noneEPSS 5.7%55.30.092.5%2012-07-03 19:00 UTC
- CVE-2012-0845XML-RPC DoSnoneEPSS 5.4%55.20.092.1%2012-10-05 21:00 UTC
- CVE-2019-9947HTTP Header Injection (follow-up of CVE-2016-5699)mediumEPSS 5.3%55.06.192.1%2019-03-23 17:06 UTC
- CVE-2013-4238ssl: NULL in subjectAltNamesnoneEPSS 5.3%55.00.092.1%2013-08-18 01:00 UTC
- CVE-2019-9740HTTP Header Injection (follow-up of CVE-2016-5699)mediumEPSS 5.3%55.06.192.0%2019-03-13 03:00 UTC
- CVE-2013-7338zipfile DoS using invalid file sizenoneEPSS 5.1%54.80.091.7%2014-04-22 14:00 UTC
- CVE-2012-1150Hash DoSnoneEPSS 5.1%54.80.091.7%2012-10-05 21:00 UTC