| Django |
CVE-2022-28346 |
严重 |
2.2.15 |
2.2.28, 3.2.13, 4.0.4 |
Django: SQL injection in QuerySet.annotate(),aggregate() and extra()
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-28346
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-04-12 05:15 修改: 2024-11-21 06:57
|
| Django |
CVE-2022-28347 |
严重 |
2.2.15 |
2.2.28, 3.2.13, 4.0.4 |
Django: SQL injection via QuerySet.explain(options) on PostgreSQL
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-28347
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-04-12 05:15 修改: 2024-11-21 06:57
|
| Django |
CVE-2025-64459 |
严重 |
2.2.15 |
5.2.8, 5.1.14, 4.2.26 |
django: Django SQL injection
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-64459
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2025-11-05 15:15 修改: 2025-11-10 18:25
|
| Pillow |
CVE-2021-25289 |
严重 |
7.2.0 |
8.1.1 |
python-pillow: insufficent fix for CVE-2020-35654 due to incorrect error checking in TiffDecode.c
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-25289
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-03-19 04:15 修改: 2024-11-21 05:54
|
| Pillow |
CVE-2021-34552 |
严重 |
7.2.0 |
8.3.0 |
python-pillow: Buffer overflow in image convert function
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-34552
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-07-13 17:15 修改: 2024-11-21 06:10
|
| Pillow |
CVE-2022-22817 |
严重 |
7.2.0 |
9.0.1 |
python-pillow: PIL.ImageMath.eval allows evaluation of arbitrary expressions
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-22817
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-01-10 14:12 修改: 2024-11-21 06:47
|
| Pillow |
CVE-2023-50447 |
严重 |
7.2.0 |
10.2.0 |
pillow: Arbitrary Code Execution via the environment parameter
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50447
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-01-19 20:15 修改: 2024-11-21 08:37
|
| Django |
CVE-2021-31542 |
高危 |
2.2.15 |
2.2.21, 3.1.9, 3.2.1 |
django: Potential directory-traversal via uploaded files
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-31542
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-05-05 15:15 修改: 2024-11-21 06:05
|
| Django |
CVE-2021-33571 |
高危 |
2.2.15 |
2.2.24, 3.1.12, 3.2.4 |
django: Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addresses
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-33571
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-06-08 18:15 修改: 2024-11-21 06:09
|
| Django |
CVE-2021-45115 |
高危 |
2.2.15 |
2.2.26, 3.2.11, 4.0.1 |
django: Denial-of-service possibility in UserAttributeSimilarityValidator
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-45115
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-01-05 00:15 修改: 2024-11-21 06:31
|
| Django |
CVE-2021-45116 |
高危 |
2.2.15 |
2.2.26, 3.2.11, 4.0.1 |
django: Potential information disclosure in dictsort template filter
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-45116
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-01-05 00:15 修改: 2025-05-22 19:15
|
| Django |
CVE-2022-23833 |
高危 |
2.2.15 |
2.2.27, 3.2.12, 4.0.2 |
django: Denial-of-service possibility in file uploads
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-23833
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-02-03 02:15 修改: 2024-11-21 06:49
|
| Django |
CVE-2022-36359 |
高危 |
2.2.15 |
3.2.15, 4.0.7 |
An issue was discovered in the HTTP FileResponse class in Django 3.2 b ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-36359
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-08-03 14:15 修改: 2024-11-21 07:12
|
| Django |
CVE-2025-57833 |
高危 |
2.2.15 |
4.2.24, 5.1.12, 5.2.6 |
django: Django SQL injection in FilteredRelation column aliases
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-57833
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2025-09-03 21:15 修改: 2025-11-04 22:16
|
| Django |
CVE-2025-64458 |
高危 |
2.2.15 |
5.2.8, 5.1.14, 4.2.26 |
Django: Denial-of-service vulnerability in Django on Windows
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-64458
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2025-11-05 15:15 修改: 2025-11-10 18:33
|
| CairoSVG |
CVE-2021-21236 |
高危 |
2.0.3 |
2.5.1 |
CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter base ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-21236
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-01-06 17:15 修改: 2024-11-21 05:47
|
| CairoSVG |
CVE-2023-27586 |
高危 |
2.0.3 |
2.7.0 |
CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Pr ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-27586
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-03-20 16:15 修改: 2024-11-21 07:53
|
| CairoSVG |
CVE-2026-31899 |
高危 |
2.0.3 |
2.9.0 |
CairoSVG: CairoSVG: Denial of Service via recursive <use> element amplification
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31899
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-03-13 19:54 修改: 2026-03-18 15:16
|
| Django |
CVE-2020-24583 |
高危 |
2.2.15 |
2.2.16, 3.0.10, 3.1.1 |
django: incorrect permissions on intermediate-level directories on Python 3.7+
漏洞详情: https://avd.aquasec.com/nvd/cve-2020-24583
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2020-09-01 13:15 修改: 2024-11-21 05:15
|
| Pillow |
CVE-2020-35653 |
高危 |
7.2.0 |
8.1.0 |
python-pillow: Buffer over-read in PCX image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2020-35653
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-01-12 09:15 修改: 2024-11-21 05:27
|
| Pillow |
CVE-2020-35654 |
高危 |
7.2.0 |
8.1.0 |
python-pillow: decoding crafted YCbCr files could result in heap-based buffer overflow
漏洞详情: https://avd.aquasec.com/nvd/cve-2020-35654
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-01-12 09:15 修改: 2024-11-21 05:27
|
| Pillow |
CVE-2021-23437 |
高危 |
7.2.0 |
8.3.2 |
python-pillow: possible ReDoS via the getrgb function
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-23437
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-09-03 16:15 修改: 2024-11-21 05:51
|
| Pillow |
CVE-2021-25287 |
高危 |
7.2.0 |
8.2.0 |
python-pillow: Out-of-bounds read in J2K image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-25287
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-06-02 16:15 修改: 2024-11-21 05:54
|
| Pillow |
CVE-2021-25288 |
高危 |
7.2.0 |
8.2.0 |
python-pillow: Out-of-bounds read in J2K image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-25288
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-06-02 16:15 修改: 2024-11-21 05:54
|
| Pillow |
CVE-2021-25290 |
高危 |
7.2.0 |
8.1.1 |
python-pillow: Negative-offset memcpy in TIFF image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-25290
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-03-19 04:15 修改: 2024-11-21 05:54
|
| Pillow |
CVE-2021-25291 |
高危 |
7.2.0 |
8.2.0 |
python-pillow: out-of-bounds read in TiffReadRGBATile in TiffDecode.c
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-25291
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-03-19 04:15 修改: 2024-11-21 05:54
|
| Pillow |
CVE-2021-25293 |
高危 |
7.2.0 |
8.1.1 |
python-pillow: Out-of-bounds read in SGI RLE image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-25293
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-03-19 04:15 修改: 2024-11-21 05:54
|
| Pillow |
CVE-2021-27921 |
高危 |
7.2.0 |
8.1.2 |
python-pillow: Excessive memory allocation in BLP image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-27921
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-03-03 09:15 修改: 2025-08-15 05:15
|
| Pillow |
CVE-2021-27922 |
高危 |
7.2.0 |
8.1.2 |
python-pillow: Excessive memory allocation in ICNS image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-27922
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-03-03 09:15 修改: 2025-08-15 05:15
|
| Pillow |
CVE-2021-27923 |
高危 |
7.2.0 |
8.1.2 |
python-pillow: Excessive memory allocation in ICO image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-27923
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-03-03 09:15 修改: 2025-08-15 05:15
|
| Pillow |
CVE-2021-28675 |
高危 |
7.2.0 |
8.2.0 |
python-pillow: Excessive memory allocation in PSD image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-28675
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-06-02 15:15 修改: 2024-11-21 06:00
|
| Pillow |
CVE-2021-28676 |
高危 |
7.2.0 |
8.2.0 |
python-pillow: Infinite loop in FLI image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-28676
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-06-02 16:15 修改: 2024-11-21 06:00
|
| Pillow |
CVE-2021-28677 |
高危 |
7.2.0 |
8.2.0 |
python-pillow: Excessive CPU use in EPS image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-28677
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-06-02 16:15 修改: 2024-11-21 06:00
|
| Pillow |
CVE-2022-24303 |
高危 |
7.2.0 |
9.0.1 |
python-pillow: temporary directory with a space character allows removal of unrelated file after im.show() and related actions
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-24303
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-03-28 02:15 修改: 2024-11-21 06:50
|
| Pillow |
CVE-2022-45198 |
高危 |
7.2.0 |
9.2.0 |
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GI ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-45198
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-11-14 07:15 修改: 2024-11-21 07:28
|
| Pillow |
CVE-2023-44271 |
高危 |
7.2.0 |
10.0.0 |
python-pillow: uncontrolled resource consumption when textlength in an ImageDraw instance operates on a long text argument
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-44271
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-11-03 05:15 修改: 2024-11-21 08:25
|
| Pillow |
CVE-2023-4863 |
高危 |
7.2.0 |
10.0.1 |
libwebp: Heap buffer overflow in WebP Codec
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-4863
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-09-12 15:15 修改: 2025-10-24 14:07
|
| Pillow |
CVE-2024-28219 |
高危 |
7.2.0 |
10.3.0 |
python-pillow: buffer overflow in _imagingcms.c
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-28219
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-04-03 03:15 修改: 2025-11-04 19:17
|
| PyJWT |
CVE-2022-29217 |
高危 |
1.7.1 |
2.4.0 |
python-jwt: Key confusion through non-blocklisted public key formats
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-29217
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-05-24 15:15 修改: 2024-11-21 06:58
|
| PyJWT |
CVE-2026-32597 |
高危 |
1.7.1 |
2.12.0 |
pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32597
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-03-13 19:55 修改: 2026-05-05 18:16
|
| PyJWT |
CVE-2026-48526 |
高危 |
1.7.1 |
2.13.0 |
python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48526
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-05-28 16:16 修改: 2026-06-01 17:45
|
| Pygments |
CVE-2021-20270 |
高危 |
2.2.0 |
2.7.4 |
python-pygments: Infinite loop in SML lexer may lead to DoS
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-20270
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-03-23 17:15 修改: 2024-11-21 05:46
|
| Pygments |
CVE-2021-27291 |
高危 |
2.2.0 |
2.7.4 |
python-pygments: ReDoS in multiple lexers
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-27291
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-03-17 13:15 修改: 2024-11-21 05:57
|
| celery |
CVE-2021-23727 |
高危 |
4.3.0 |
5.2.2 |
celery: stored command injection vulnerability may allow privileges escalation
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-23727
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-12-29 17:15 修改: 2024-11-21 05:51
|
| certifi |
CVE-2023-37920 |
高危 |
2020.6.20 |
2023.7.22 |
python-certifi: Removal of e-Tugra root certificate
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-37920
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-07-25 21:15 修改: 2025-02-13 13:50
|
| cryptography |
CVE-2020-25659 |
高危 |
2.3.1 |
3.2 |
python-cryptography: Bleichenbacher timing oracle attack against RSA decryption
漏洞详情: https://avd.aquasec.com/nvd/cve-2020-25659
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-01-11 16:15 修改: 2024-11-21 05:18
|
| cryptography |
CVE-2023-0286 |
高危 |
2.3.1 |
39.0.1 |
openssl: X.400 address type confusion in X.509 GeneralName
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-0286
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-02-08 20:15 修改: 2025-11-04 20:16
|
| cryptography |
CVE-2023-50782 |
高危 |
2.3.1 |
42.0.0 |
python-cryptography: Bleichenbacher timing oracle attack against RSA decryption - incomplete fix for CVE-2020-25659
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50782
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-02-05 21:15 修改: 2026-03-24 12:16
|
| cryptography |
CVE-2026-26007 |
高危 |
2.3.1 |
46.0.5 |
cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-26007
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-02-10 22:17 修改: 2026-02-23 15:40
|
| cryptography |
GHSA-537c-gmf6-5ccf |
高危 |
2.3.1 |
48.0.1 |
Vulnerable OpenSSL included in cryptography wheels
漏洞详情: https://github.com/advisories/GHSA-537c-gmf6-5ccf
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-06-15 20:12 修改: 2026-06-15 20:12
|
| lxml |
CVE-2026-41066 |
高危 |
4.5.2 |
6.1.0 |
lxml: python: lxml: Information disclosure via untrusted XML input leading to local file read
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41066
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-04-24 17:16 修改: 2026-04-27 17:59
|
| pip |
CVE-2021-3572 |
高危 |
20.2.3 |
21.1 |
python-pip: Incorrect handling of unicode separators in git references
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-3572
镜像层: sha256:22ee430ae506ec901fe175b712925a5ddcb63190f4587ddef46869964027ed2f
发布日期: 2021-11-10 18:15 修改: 2024-11-21 06:21
|
| setuptools |
CVE-2022-40897 |
高危 |
50.3.0 |
65.5.1 |
pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-40897
镜像层: sha256:22ee430ae506ec901fe175b712925a5ddcb63190f4587ddef46869964027ed2f
发布日期: 2022-12-23 00:15 修改: 2025-11-04 16:15
|
| setuptools |
CVE-2024-6345 |
高危 |
50.3.0 |
70.0.0 |
pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-6345
镜像层: sha256:22ee430ae506ec901fe175b712925a5ddcb63190f4587ddef46869964027ed2f
发布日期: 2024-07-15 01:15 修改: 2026-04-15 00:35
|
| setuptools |
CVE-2025-47273 |
高危 |
50.3.0 |
78.1.1 |
setuptools: Path Traversal Vulnerability in setuptools PackageIndex
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-47273
镜像层: sha256:22ee430ae506ec901fe175b712925a5ddcb63190f4587ddef46869964027ed2f
发布日期: 2025-05-17 16:15 修改: 2025-06-12 16:29
|
| sqlparse |
CVE-2024-4340 |
高危 |
0.3.1 |
0.5.0 |
sqlparse: parsing heavily nested list leads to denial of service
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-4340
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-04-30 15:15 修改: 2026-04-15 00:35
|
| uWSGI |
CVE-2023-27522 |
高危 |
2.0.19.1 |
2.0.22 |
httpd: mod_proxy_uwsgi HTTP response splitting
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-27522
镜像层: sha256:253a8682af7ba9e8b77fab1f1bc3c639139f5e36e908c6d86541ed5dd7fc4c91
发布日期: 2023-03-07 16:15 修改: 2025-05-01 15:34
|
| urllib3 |
CVE-2021-33503 |
高危 |
1.25.9 |
1.26.5 |
python-urllib3: ReDoS in the parsing of authority part of URL
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-33503
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-06-29 11:15 修改: 2024-11-21 06:08
|
| urllib3 |
CVE-2023-43804 |
高危 |
1.25.9 |
2.0.6, 1.26.17 |
python-urllib3: Cookie request header isn't stripped during cross-origin redirects
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-43804
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-10-04 17:15 修改: 2025-11-03 22:16
|
| urllib3 |
CVE-2025-66418 |
高危 |
1.25.9 |
2.6.0 |
urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66418
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2025-12-05 16:15 修改: 2025-12-10 16:08
|
| urllib3 |
CVE-2025-66471 |
高危 |
1.25.9 |
2.6.0 |
urllib3: urllib3 Streaming API improperly handles highly compressed data
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66471
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2025-12-05 17:16 修改: 2025-12-10 16:10
|
| urllib3 |
CVE-2026-21441 |
高危 |
1.25.9 |
2.6.3 |
urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-21441
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-01-07 22:15 修改: 2026-01-23 09:15
|
| urllib3 |
CVE-2026-44431 |
高危 |
1.25.9 |
2.7.0 |
urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44431
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-05-13 16:16 修改: 2026-05-14 13:56
|
| wheel |
CVE-2022-40898 |
高危 |
0.35.1 |
0.38.1 |
python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-40898
镜像层: sha256:22ee430ae506ec901fe175b712925a5ddcb63190f4587ddef46869964027ed2f
发布日期: 2022-12-23 00:15 修改: 2025-04-15 16:15
|
| Django |
CVE-2025-48432 |
中危 |
2.2.15 |
5.2.2, 5.1.10, 4.2.22 |
django: Django Path Injection Vulnerability
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-48432
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2025-06-05 03:15 修改: 2025-10-15 17:47
|
| PyJWT |
CVE-2026-48522 |
中危 |
1.7.1 |
2.13.0 |
python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48522
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-05-28 16:16 修改: 2026-06-02 17:16
|
| Jinja2 |
CVE-2020-28493 |
中危 |
2.11.2 |
2.11.3 |
python-jinja2: ReDoS vulnerability in the urlize filter
漏洞详情: https://avd.aquasec.com/nvd/cve-2020-28493
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-02-01 20:15 修改: 2024-11-21 05:22
|
| Jinja2 |
CVE-2024-22195 |
中危 |
2.11.2 |
3.1.3 |
jinja2: HTML attribute injection when passing user input as keys to xmlattr filter
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-22195
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-01-11 03:15 修改: 2025-11-03 22:16
|
| Pygments |
CVE-2022-40896 |
中危 |
2.2.0 |
2.15.0 |
pygments: ReDoS in pygments
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-40896
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-07-19 15:15 修改: 2024-11-21 07:22
|
| bleach |
CVE-2021-23980 |
中危 |
3.1.5 |
3.3.0 |
python-bleach: Mutation cross-site scripting in bleach.clean
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-23980
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-02-16 22:15 修改: 2025-03-19 16:15
|
| bleach |
GHSA-gj48-438w-jh9v |
中危 |
3.1.5 |
6.4.0 |
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
漏洞详情: https://github.com/advisories/GHSA-gj48-438w-jh9v
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-06-16 14:07 修改: 2026-06-16 14:07
|
| Jinja2 |
CVE-2024-34064 |
中危 |
2.11.2 |
3.1.4 |
jinja2: accepts keys containing non-attribute characters
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34064
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-05-06 15:15 修改: 2025-11-03 22:16
|
| Jinja2 |
CVE-2024-56326 |
中危 |
2.11.2 |
3.1.5 |
jinja2: Jinja has a sandbox breakout through indirect reference to format method
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56326
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-12-23 16:15 修改: 2025-11-03 20:16
|
| certifi |
CVE-2022-23491 |
中危 |
2020.6.20 |
2022.12.07 |
python-certifi: untrusted root certificates
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-23491
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-12-07 22:15 修改: 2025-02-12 17:36
|
| Jinja2 |
CVE-2025-27516 |
中危 |
2.11.2 |
3.1.6 |
jinja2: Jinja sandbox breakout through attr filter selecting format method
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-27516
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2025-03-05 21:15 修改: 2025-11-03 20:18
|
| Markdown |
CVE-2025-69534 |
中危 |
3.1.1 |
3.8.1 |
python-markdown: denial of service via malformed HTML-like sequences
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-69534
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-03-05 15:16 修改: 2026-03-13 01:25
|
| Django |
CVE-2020-24584 |
中危 |
2.2.15 |
2.2.16, 3.0.10, 3.1.1 |
django: permission escalation in intermediate-level directories of the file system cache on Python 3.7+
漏洞详情: https://avd.aquasec.com/nvd/cve-2020-24584
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2020-09-01 13:15 修改: 2024-11-21 05:15
|
| Django |
CVE-2021-28658 |
中危 |
2.2.15 |
2.2.20, 3.0.14, 3.1.8 |
django: potential directory-traversal via uploaded files
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-28658
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-04-06 15:15 修改: 2024-11-21 06:00
|
| Django |
CVE-2021-32052 |
中危 |
2.2.15 |
2.2.22, 3.1.10, 3.2.2 |
django: header injection possibility since URLValidator accepted newlines in input on Python 3.9.5+
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-32052
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-05-06 16:15 修改: 2024-11-21 06:06
|
| cryptography |
CVE-2023-23931 |
中危 |
2.3.1 |
39.0.1 |
python-cryptography: memory corruption via immutable objects
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-23931
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-02-07 21:15 修改: 2025-11-03 22:16
|
| cryptography |
CVE-2024-0727 |
中危 |
2.3.1 |
42.0.2 |
openssl: denial of service via null dereference
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-0727
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-01-26 09:15 修改: 2026-05-12 12:16
|
| idna |
CVE-2024-3651 |
中危 |
2.8 |
3.7 |
python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode()
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-3651
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-07-07 18:15 修改: 2025-11-04 22:16
|
| idna |
CVE-2026-45409 |
中危 |
2.8 |
3.15 |
Internationalized Domain Names in Applications (IDNA) for Python provi ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45409
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-06-05 23:16 修改: 2026-06-15 18:52
|
| Django |
CVE-2021-3281 |
中危 |
2.2.15 |
2.2.18, 3.1.6, 3.0.12 |
django: Potential directory-traversal via archive.extract()
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-3281
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-02-02 07:15 修改: 2024-11-21 06:21
|
| lxml |
CVE-2020-27783 |
中危 |
4.5.2 |
4.6.2 |
python-lxml: mXSS due to the use of improper parser
漏洞详情: https://avd.aquasec.com/nvd/cve-2020-27783
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2020-12-03 17:15 修改: 2025-12-17 21:15
|
| lxml |
CVE-2021-28957 |
中危 |
4.5.2 |
4.6.3 |
python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-28957
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-03-21 05:15 修改: 2025-12-17 22:15
|
| lxml |
CVE-2021-43818 |
中危 |
4.5.2 |
4.6.5 |
python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-43818
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-12-13 18:15 修改: 2024-11-21 06:29
|
| lxml |
CVE-2022-2309 |
中危 |
4.5.2 |
4.9.1 |
lxml: NULL Pointer Dereference in lxml
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-2309
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-07-05 10:15 修改: 2025-11-04 16:15
|
| Django |
CVE-2021-33203 |
中危 |
2.2.15 |
2.2.24, 3.1.12, 3.2.4 |
django: Potential directory traversal via ``admindocs``
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-33203
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-06-08 18:15 修改: 2024-11-21 06:08
|
| pip |
CVE-2023-5752 |
中危 |
20.2.3 |
23.3 |
pip: Mercurial configuration injectable in repo revision when installing via pip
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-5752
镜像层: sha256:22ee430ae506ec901fe175b712925a5ddcb63190f4587ddef46869964027ed2f
发布日期: 2023-10-25 18:17 修改: 2025-11-03 18:15
|
| pip |
CVE-2025-8869 |
中危 |
20.2.3 |
25.3 |
pip: pip missing checks on symbolic link extraction
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8869
镜像层: sha256:22ee430ae506ec901fe175b712925a5ddcb63190f4587ddef46869964027ed2f
发布日期: 2025-09-24 15:15 修改: 2026-04-15 00:35
|
| pip |
CVE-2026-3219 |
中危 |
20.2.3 |
26.1 |
pip: pip: Incorrect file installation due to improper archive handling
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3219
镜像层: sha256:22ee430ae506ec901fe175b712925a5ddcb63190f4587ddef46869964027ed2f
发布日期: 2026-04-20 16:16 修改: 2026-04-20 21:16
|
| pip |
CVE-2026-6357 |
中危 |
20.2.3 |
26.1 |
pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6357
镜像层: sha256:22ee430ae506ec901fe175b712925a5ddcb63190f4587ddef46869964027ed2f
发布日期: 2026-04-27 15:16 修改: 2026-04-27 23:16
|
| psd-tools |
CVE-2026-27809 |
中危 |
1.8.31 |
1.12.2 |
psd-tools is a Python package for working with Adobe Photoshop PSD fil ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27809
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-02-26 00:16 修改: 2026-03-02 18:55
|
| requests |
CVE-2023-32681 |
中危 |
2.22.0 |
2.31.0 |
python-requests: Unintended leak of Proxy-Authorization header
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-32681
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-05-26 18:15 修改: 2025-02-13 17:16
|
| requests |
CVE-2024-35195 |
中危 |
2.22.0 |
2.32.0 |
requests: subsequent requests to the same host ignore cert verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-35195
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-05-20 21:15 修改: 2026-04-15 00:35
|
| requests |
CVE-2024-47081 |
中危 |
2.22.0 |
2.32.4 |
requests: Requests vulnerable to .netrc credentials leak via malicious URLs
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47081
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2025-06-09 18:15 修改: 2026-04-15 00:35
|
| requests |
CVE-2026-25645 |
中危 |
2.22.0 |
2.33.0 |
requests: Requests: Security bypass due to predictable temporary file creation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25645
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-03-25 17:16 修改: 2026-03-30 14:23
|
| Django |
CVE-2021-44420 |
中危 |
2.2.15 |
2.2.25, 3.1.14, 3.2.10 |
django: potential bypass of an upstream access control based on URL paths
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-44420
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-12-08 00:15 修改: 2024-11-21 06:30
|
| Django |
CVE-2021-45452 |
中危 |
2.2.15 |
2.2.26, 3.2.11, 4.0.1 |
django: Potential directory-traversal via Storage.save()
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-45452
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-01-05 00:15 修改: 2024-11-21 06:32
|
| Pillow |
CVE-2020-35655 |
中危 |
7.2.0 |
8.1.0 |
python-pillow: Buffer over-read in SGI RLE image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2020-35655
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-01-12 09:15 修改: 2024-11-21 05:27
|
| Pillow |
CVE-2021-25292 |
中危 |
7.2.0 |
8.1.1 |
python-pillow: Regular expression DoS in PDF format parser
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-25292
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-03-19 04:15 修改: 2024-11-21 05:54
|
| sqlparse |
CVE-2023-30608 |
中危 |
0.3.1 |
0.4.4 |
sqlparse: Parser contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service)
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-30608
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-04-18 22:15 修改: 2025-11-03 22:16
|
| sqlparse |
GHSA-27jp-wm6q-gp25 |
中危 |
0.3.1 |
0.5.4 |
sqlparse: formatting list of tuples leads to denial of service
漏洞详情: https://github.com/advisories/GHSA-27jp-wm6q-gp25
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-02-13 16:16 修改: 2026-02-13 16:16
|
| Pillow |
CVE-2021-28678 |
中危 |
7.2.0 |
8.2.0 |
python-pillow: Excessive looping in BLP image reader
漏洞详情: https://avd.aquasec.com/nvd/cve-2021-28678
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-06-02 16:15 修改: 2024-11-21 06:00
|
| Pillow |
CVE-2022-22815 |
中危 |
7.2.0 |
9.0.0 |
python-pillow: improperly initializes ImagePath.Path in path_getbbox() in path.c
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-22815
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-01-10 14:12 修改: 2024-11-21 06:47
|
| Pillow |
CVE-2022-22816 |
中危 |
7.2.0 |
9.0.0 |
python-pillow: buffer over-read during initialization of ImagePath.Path in path_getbbox() in path.c
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-22816
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-01-10 14:12 修改: 2024-11-21 06:47
|
| Pillow |
CVE-2026-42308 |
中危 |
7.2.0 |
12.2.0 |
Pillow: python: Pillow: Denial of Service via integer overflow in font processing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42308
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-05-09 06:16 修改: 2026-05-12 17:57
|
| Pillow |
CVE-2026-42310 |
中危 |
7.2.0 |
12.2.0 |
Pillow: Pillow: Denial of Service via malicious PDF processing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42310
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-05-09 06:16 修改: 2026-05-12 17:55
|
| Pillow |
GHSA-jgpv-4h4c-xhw3 |
中危 |
7.2.0 |
8.1.2 |
Uncontrolled Resource Consumption in pillow
漏洞详情: https://github.com/advisories/GHSA-jgpv-4h4c-xhw3
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2021-04-23 16:54 修改: 2021-04-22 17:01
|
| Django |
CVE-2022-22818 |
中危 |
2.2.15 |
2.2.27, 3.2.12, 4.0.2 |
django: Possible XSS via '{% debug %}' template tag
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-22818
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-02-03 02:15 修改: 2024-11-21 06:47
|
| urllib3 |
CVE-2023-45803 |
中危 |
1.25.9 |
2.0.7, 1.26.18 |
urllib3: Request body not stripped after redirect from 303 status changes request method to GET
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45803
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-10-17 20:15 修改: 2025-11-03 22:16
|
| urllib3 |
CVE-2024-37891 |
中危 |
1.25.9 |
1.26.19, 2.2.2 |
urllib3: proxy-authorization request header is not stripped during cross-origin redirects
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-37891
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-06-17 20:15 修改: 2026-01-06 16:52
|
| urllib3 |
CVE-2025-50181 |
中危 |
1.25.9 |
2.5.0 |
urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-50181
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2025-06-19 01:15 修改: 2025-12-22 19:15
|
| Django |
CVE-2024-45231 |
中危 |
2.2.15 |
5.1.1, 5.0.9, 4.2.16 |
python-django: Potential user email enumeration via response status on password reset
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-45231
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-10-08 16:15 修改: 2025-03-17 18:15
|
| zipp |
CVE-2024-5569 |
中危 |
1.2.0 |
3.19.1 |
github.com/jaraco/zipp: Denial of Service (infinite loop) via crafted zip file in jaraco/zipp
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-5569
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2024-07-09 00:15 修改: 2026-04-15 00:35
|
| pip |
CVE-2026-1703 |
低危 |
20.2.3 |
26.0 |
pip: pip: Information disclosure via path traversal when installing crafted wheel archives
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1703
镜像层: sha256:22ee430ae506ec901fe175b712925a5ddcb63190f4587ddef46869964027ed2f
发布日期: 2026-02-02 15:16 修改: 2026-04-15 00:35
|
| cryptography |
GHSA-5cpq-8wj7-hf2v |
低危 |
2.3.1 |
41.0.0 |
Vulnerable OpenSSL included in cryptography wheels
漏洞详情: https://github.com/advisories/GHSA-5cpq-8wj7-hf2v
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-06-02 17:13 修改: 2023-06-02 17:13
|
| cryptography |
GHSA-jm77-qphf-c4w8 |
低危 |
2.3.1 |
41.0.3 |
pyca/cryptography's wheels include vulnerable OpenSSL
漏洞详情: https://github.com/advisories/GHSA-jm77-qphf-c4w8
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2023-08-01 22:34 修改: 2023-08-01 22:34
|
| Pillow |
GHSA-4fx9-vc88-q2xc |
低危 |
7.2.0 |
9.0.0 |
Infinite loop in Pillow
漏洞详情: https://github.com/advisories/GHSA-4fx9-vc88-q2xc
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2022-03-11 23:39 修改: 2022-03-11 23:39
|
| bleach |
GHSA-8rfp-98v4-mmr6 |
低危 |
3.1.5 |
6.4.0 |
Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output
漏洞详情: https://github.com/advisories/GHSA-8rfp-98v4-mmr6
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-06-16 14:06 修改: 2026-06-16 14:06
|
| Pygments |
CVE-2026-4539 |
低危 |
2.2.0 |
2.20.0 |
pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4539
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-03-22 06:16 修改: 2026-04-29 01:00
|
| PyJWT |
CVE-2026-48524 |
低危 |
1.7.1 |
2.13.0 |
python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48524
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-05-28 16:16 修改: 2026-06-01 17:44
|
| cryptography |
CVE-2026-34073 |
低危 |
2.3.1 |
46.0.6 |
python-cryptography: Cryptography: Security bypass due to improper DNS name constraint validation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34073
镜像层: sha256:20e2f81215ee80ecb39199c9cfc4ec9bd16c8cd1b4db96fd4ae698499b2d4de9
发布日期: 2026-03-31 03:15 修改: 2026-04-06 15:30
|