CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-19553 HIGH

SSLContext.wrap_bio() missing validation of server_hostname parameter

CVSS 7.6 EPSS 0.47% Sep 30, 2026
CVE-2026-19445 CRITICAL

Use-after-free of a server-side SSLContext when sni_callback switches contexts

CVSS 9.2 EPSS 0.51% Sep 30, 2026
CVE-2026-12345 MEDIUM

Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory

CVSS 5.9 EPSS 0.18% Sep 29, 2026
CVE-2026-82049 HIGH

tarfile extraction filters allow file modification and content disclosure via hard link to symlink

CVSS 8.4 EPSS 0.21% Sep 14, 2026
CVE-2026-87910 MEDIUM

tarfile hardlink fallback ignores custom extraction filter rejection via None

CVSS 5.7 EPSS 0.55% Sep 11, 2026
CVE-2026-15310 LOW

zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

CVSS 2.1 EPSS 0.51% Aug 25, 2026
CVE-2026-19672 MEDIUM

tarfile extraction filter bypass allows creation of directories outside the destination

CVSS 6.3 EPSS 0.52% Aug 19, 2026
CVE-2026-15806 MEDIUM

`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching

CVSS 6.0 EPSS 0.45% Aug 18, 2026
CVE-2026-17084 MEDIUM

stringprep.map_table_b2() deviates from RFC 3454 Table B.2

CVSS 6.0 EPSS 0.72% Aug 18, 2026
CVE-2026-18503 LOW

Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()

CVSS 2.4 EPSS 0.12% Aug 10, 2026
CVE-2026-6879 LOW

Quadratic Behavior in xml.etree.ElementPath Index Predicates

CVSS 2.0 EPSS 0.58% Jul 28, 2026
CVE-2026-15308 HIGH

Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations

CVSS 8.7 EPSS 0.64% Jul 9, 2026
CVE-2026-4360 LOW

Tarfile.extract() doesn't fully respect filter parameter

CVSS 2.0 EPSS 0.48% Jun 30, 2026
CVE-2026-11972 HIGH

tarfile opened in streaming mode mishandles EOF

CVSS 8.2 EPSS 0.71% Jun 23, 2026
CVE-2026-0864 MEDIUM

Configuration Injection via Carriage Return (\r) in write() method

CVSS 4.1 EPSS 0.18% Jun 23, 2026
CVE-2026-11940 HIGH

tarfile extraction filter bypass allows escaping the destination directory

CVSS 7.8 EPSS 0.75% Jun 23, 2026
CVE-2026-12003 MEDIUM

CPython >3.11 Insecure Input Validation resulting in privilege escalation

CVSS 5.3 EPSS 0.15% Jun 16, 2026
CVE-2026-9669 HIGH

bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow

CVSS 8.2 EPSS 0.60% Jun 8, 2026
CVE-2026-7774 MEDIUM

tarfile.data_filter path traversal bypass allows writing outside the extraction directory

CVSS 6.9 EPSS 0.78% Jun 4, 2026
CVE-2026-3276 MEDIUM

Potential DoS via quadratic complexity in unicodedata.normalize()

CVSS 6.3 EPSS 0.71% Jun 3, 2026
CVE-2026-8328 MEDIUM

FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address

CVSS 5.9 EPSS 0.68% May 13, 2026
CVE-2026-7210 MEDIUM

The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

CVSS 6.3 EPSS 1.35% May 11, 2026
CVE-2026-3087 MEDIUM

shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

CVSS 6.0 EPSS 0.73% Apr 27, 2026
CVE-2026-6019 LOW

BaseCookie.js_output() does not neutralize embedded characters

CVSS 2.1 EPSS 0.58% Apr 22, 2026
CVE-2026-3298 HIGH

Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes

CVSS 8.8 EPSS 0.60% Apr 21, 2026

Showing 1 to 25 CVEs · page 1 (more available)