CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-15308 HIGH

Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations

CVSS 8.7 EPSS 0.64% Jul 9, 2026
CVE-2026-4360 LOW

Tarfile.extract() doesn't fully respect filter parameter

CVSS 2.0 EPSS 0.48% Jun 30, 2026
CVE-2026-0864 MEDIUM

Configuration Injection via Carriage Return (\r) in write() method

CVSS 4.1 EPSS 0.18% Jun 23, 2026
CVE-2026-7210 MEDIUM

The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

CVSS 6.3 EPSS 1.35% May 11, 2026
CVE-2026-3087 MEDIUM

shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

CVSS 6.0 EPSS 0.73% Apr 27, 2026
CVE-2026-6019 LOW

BaseCookie.js_output() does not neutralize embedded characters

CVSS 2.1 EPSS 0.58% Apr 22, 2026
CVE-2026-4519 HIGH

webbrowser.open() allows leading dashes in URLs

CVSS 7.0 EPSS 0.39% Mar 20, 2026
CVE-2026-4224 MEDIUM

Stack overflow parsing XML with deeply nested DTD content models

CVSS 6.0 EPSS 1.21% Mar 16, 2026
CVE-2026-3644 MEDIUM

Incomplete control character validation in http.cookies

CVSS 6.0 EPSS 0.65% Mar 16, 2026
CVE-2025-13462 LOW

tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling

CVSS 2.0 EPSS 0.16% Mar 12, 2026
CVE-2025-12781 MEDIUM

base64.b64decode() always accepts "+/" characters, despite setting altchars

CVSS 6.3 EPSS 0.57% Jan 21, 2026
CVE-2025-12084 MEDIUM

Quadratic complexity in node ID cache clearing

CVSS 6.3 EPSS 0.80% Dec 3, 2025
CVE-2025-13837 LOW

Out-of-memory when loading Plist

CVSS 2.1 EPSS 0.22% Dec 1, 2025
CVE-2025-13836 MEDIUM

Excessive read buffering DoS in http.client

CVSS 6.3 EPSS 1.63% Dec 1, 2025
CVE-2025-6075 LOW

Quadratic complexity in os.path.expandvars() with user-controlled template

CVSS 1.8 EPSS 0.14% Oct 31, 2025
CVE-2024-9287 MEDIUM

Virtual environment (venv) activation scripts don't quote paths

CVSS 5.3 EPSS 0.65% Oct 22, 2024
CVE-2024-6232 HIGH

Regular-expression DoS when parsing TarFile headers

CVSS 7.5 EPSS 2.20% Sep 3, 2024
CVE-2024-7592 HIGH

Quadratic complexity parsing cookies with backslashes

CVSS 7.5 EPSS 2.30% Aug 19, 2024
CVE-2023-6507 MEDIUM

Groups not dropped before running subprocess when using empty 'extra_groups' parameter

CVSS 6.1 EPSS 1.34% Dec 8, 2023
CVE-2023-40217 HIGH

python: TLS handshake bypass

CVSS 8.6 EPSS 0.80% Aug 25, 2023
CVE-2023-41105 HIGH

python: file path truncation at \0 characters

CVSS 7.5 EPSS 2.59% Aug 23, 2023
CVE-2022-48566 MEDIUM

python: constant-time-defeating optimisations issue in the compare_digest function in Lib/hmac.p

CVSS 5.9 EPSS 1.30% Aug 22, 2023
CVE-2022-48565 CRITICAL

python: XML External Entity in XML processing plistlib module

CVSS 9.8 EPSS 5.07% Aug 22, 2023
CVE-2022-48564 MEDIUM

python: DoS when processing malformed Apple Property List files in binary format

CVSS 6.5 EPSS 1.65% Aug 22, 2023
CVE-2022-48560 HIGH

python: use after free in heappushpop() of heapq module

CVSS 7.5 EPSS 1.77% Aug 22, 2023

Showing 1 to 25 CVEs · page 1 (more available)