CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Tarfile.extract() doesn't fully respect filter parameter
Configuration Injection via Carriage Return (\r) in write() method
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
BaseCookie.js_output() does not neutralize embedded characters
webbrowser.open() allows leading dashes in URLs
Stack overflow parsing XML with deeply nested DTD content models
Incomplete control character validation in http.cookies
tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling
base64.b64decode() always accepts "+/" characters, despite setting altchars
Quadratic complexity in node ID cache clearing
Out-of-memory when loading Plist
Excessive read buffering DoS in http.client
Quadratic complexity in os.path.expandvars() with user-controlled template
Virtual environment (venv) activation scripts don't quote paths
Regular-expression DoS when parsing TarFile headers
Quadratic complexity parsing cookies with backslashes
Groups not dropped before running subprocess when using empty 'extra_groups' parameter
python: TLS handshake bypass
python: file path truncation at \0 characters
python: constant-time-defeating optimisations issue in the compare_digest function in Lib/hmac.p
python: XML External Entity in XML processing plistlib module
python: DoS when processing malformed Apple Property List files in binary format
python: use after free in heappushpop() of heapq module
Showing 1 to 25 CVEs · page 1 (more available)