PypiCVEs & Vulnerabilities

16 CVEs affecting Pypi products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

pypi 2rootinteractive 2bsdiff4 1cloudlabeling 1cryptoasset-data-downloader 1django-navbar-client 1dr-web-engine 1drxhello 1
CVE-2022-34501CRITICAL

The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

22 Jul 2022
9.8
CVSS
CVE-2022-34500CRITICAL

The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

22 Jul 2022
9.8
CVSS
CVE-2022-34056CRITICAL

The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2022-34055CRITICAL

The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2022-34054CRITICAL

The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2022-34053CRITICAL

The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2022-33004CRITICAL

The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2022-33003CRITICAL

The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2022-33002CRITICAL

The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2022-33001CRITICAL

The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2022-33000CRITICAL

The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2022-32999CRITICAL

The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2022-32998CRITICAL

The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2022-32997CRITICAL

The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2022-32996CRITICAL

The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

25 Jun 2022
9.8
CVSS
CVE-2020-15904HIGH

A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file.

23 Jul 2020
7.8
CVSS
← PrevPage 1 / 1Next →