Vulnerability search
Batch lookup →160 matches
- CVE-2021-4189Python vulnerabilitiesmediumEPSS 3.2%128.78.187.2%2026-07-06 11:48 UTC
- CVE-2026-21441Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)2 sources· osv_advisoryhighEPSS 3%124.87.585.3%2026-07-07 16:03 UTC
- CVE-2019-9636urlsplit does not handle NFKC normalization3 sources· cve · osv_advisorycriticalEPSS 8.8%105.99.894.9%2019-03-08 21:29 UTC
- CVE-2019-9948urllib module local_file:// scheme3 sources· cve · osv_advisorycriticalEPSS 12%103.09.195.8%2019-03-23 18:29 UTC
- CVE-2026-44432urllib3 vulnerabilities3 sources· osv_advisory · ubuntu_usnhighEPSS 0.7%98.77.549.9%2026-06-03 13:50 UTC
- CVE-2018-25032Nokogiri affected by zlib's Out-of-bounds Write vulnerability6 sources· osv_advisory · cve · siemens_advisoryhighEPSS 52%97.97.598.9%2022-03-26 00:00 UTC
- CVE-2016-2183Sweet32 attack (DES, 3DES)2 sources· cve · osv_advisoryhighEPSS 96%97.47.599.9%2016-09-01 00:00 UTC
- CVE-2014-0224OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict…highEPSS 95%96.97.499.9%2014-06-05 21:00 UTC
- CVE-2025-13836When reading an HTTP response from a server, if no read amount is specified, the default behavior…highEPSS 1.6%96.07.574.8%2025-12-01 18:02 UTC
- CVE-2015-20107mailcap shell command injection2 sources· osv_advisory · cvehighEPSS 7.1%95.27.693.8%2022-04-13 00:00 UTC
- CVE-2019-6690Improper Input Validation python-gnupg5 sources· cve · osv_advisoryhighEPSS 8.6%94.37.594.7%2020-03-13 20:05 UTC
- CVE-2025-69534Python vulnerabilitieshighEPSS 0.6%93.67.544.7%2026-07-27 16:37 UTC
- CVE-2019-15903In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to…highEPSS 6.6%93.67.593.4%2019-09-04 05:59 UTC
- CVE-2019-9674Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service…highEPSS 5.5%92.97.592.3%2020-02-04 14:05 UTC
- CVE-2026-54058Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA…2 sources· osv_advisorycriticalEPSS 0.5%90.09.142.2%2026-07-23 11:41 UTC
- CVE-2019-11324The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA…2 sources· cvehighEPSS 2.8%89.07.585.8%2019-04-18 21:29 UTC
- CVE-2019-9740HTTP Header Injection (follow-up of CVE-2016-5699)3 sources· cve · osv_advisorymediumEPSS 5.3%85.86.192.1%2019-03-13 03:29 UTC
- CVE-2019-9947HTTP Header Injection (follow-up of CVE-2016-5699)3 sources· cve · osv_advisorymediumEPSS 5.3%85.76.192.1%2019-03-23 18:29 UTC
- CVE-2019-6802CRLF Injection in pypiserver4 sources· cve · osv_advisorymediumEPSS 3.8%84.26.189.3%2019-01-30 20:56 UTC
- CVE-2019-11236In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker…2 sources· cvemediumEPSS 2.1%78.76.180.3%2019-04-15 15:29 UTC
- CVE-2026-3644Incomplete control character validation in http.cookies3 sources· osv_advisoryhighEPSS 0.5%78.17.539.4%2026-03-18 08:55 UTC
- CVE-2026-42311Debian pillow: security update5 sources· debian_dsa · ubuntu_usn · osv_advisory …highEPSS 0.1%75.77.84.5%2026-06-21 00:00 UTC
- CVE-2025-13462tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling3 sources· osv_advisorylowEPSS 0.2%73.63.35.9%2026-03-14 08:49 UTC
- CVE-2026-4519webbrowser.open() allows leading dashes in URLs3 sources· osv_advisoryhighEPSS 0.3%69.17.123.1%2026-03-25 08:52 UTC
- CVE-2014-1912Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before…3 sources· cve · osv_advisorynoneEPSS 28%58.8—98.0%2014-03-01 00:55 UTC