CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-19553 HIGH

SSLContext.wrap_bio() missing validation of server_hostname parameter

CVSS 7.6 EPSS 0.47% Sep 30, 2026
CVE-2026-19445 CRITICAL

Use-after-free of a server-side SSLContext when sni_callback switches contexts

CVSS 9.2 EPSS 0.51% Sep 30, 2026
CVE-2026-12345 MEDIUM

Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory

CVSS 5.9 EPSS 0.18% Sep 29, 2026
CVE-2026-82049 HIGH

tarfile extraction filters allow file modification and content disclosure via hard link to symlink

CVSS 8.4 EPSS 0.21% Sep 14, 2026
CVE-2026-87910 MEDIUM

tarfile hardlink fallback ignores custom extraction filter rejection via None

CVSS 5.7 EPSS 0.55% Sep 11, 2026
CVE-2026-15310 LOW

zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

CVSS 2.1 EPSS 0.51% Aug 25, 2026
CVE-2026-19672 MEDIUM

tarfile extraction filter bypass allows creation of directories outside the destination

CVSS 6.3 EPSS 0.52% Aug 19, 2026
CVE-2026-15806 MEDIUM

`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching

CVSS 6.0 EPSS 0.45% Aug 18, 2026
CVE-2026-17084 MEDIUM

stringprep.map_table_b2() deviates from RFC 3454 Table B.2

CVSS 6.0 EPSS 0.72% Aug 18, 2026
CVE-2026-18503 LOW

Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()

CVSS 2.4 EPSS 0.12% Aug 10, 2026
CVE-2026-6879 LOW

Quadratic Behavior in xml.etree.ElementPath Index Predicates

CVSS 2.0 EPSS 0.58% Jul 28, 2026
CVE-2026-54058 HIGH

Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

CVSS 8.3 EPSS 0.68% Jul 14, 2026
CVE-2026-59197 HIGH

Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`

CVSS 8.2 EPSS 0.58% Jul 14, 2026
CVE-2026-59200 HIGH

Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()

CVSS 7.5 EPSS 0.66% Jul 14, 2026
CVE-2026-59198 HIGH

Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

CVSS 7.5 EPSS 0.50% Jul 14, 2026
CVE-2026-59205 HIGH

Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch

CVSS 7.5 EPSS 0.66% Jul 14, 2026
CVE-2026-59203 HIGH

Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service

CVSS 7.5 EPSS 0.66% Jul 14, 2026
CVE-2026-59199 HIGH

Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

CVSS 7.5 EPSS 0.66% Jul 14, 2026
CVE-2026-59204 HIGH

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

CVSS 8.7 EPSS 0.66% Jul 14, 2026
CVE-2026-15308 HIGH

Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations

CVSS 8.7 EPSS 0.64% Jul 9, 2026
CVE-2026-59890 MEDIUM

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

CVSS 6.1 EPSS 0.40% Jul 8, 2026
CVE-2026-55379 HIGH

Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading

CVSS 7.5 EPSS 0.65% Jul 6, 2026
CVE-2026-55380 HIGH

Pillow GdImageFile decompression bomb protection bypass

CVSS 7.5 EPSS 0.64% Jul 6, 2026
CVE-2026-54060 HIGH

Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`

CVSS 7.5 EPSS 0.64% Jul 6, 2026
CVE-2026-54059 HIGH

Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

CVSS 7.5 EPSS 0.64% Jul 6, 2026

Showing 1 to 25 CVEs · page 1 (more available)