Skip to content
Noroxi

pypi records

16 published records for vendor pypi.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
43.8%
Median publish → KEV
No record has entered KEV

Records by year

  1. 20
  2. 22

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

16 records
  • The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · watertoolsJun 24, 2022

  • The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · cloudlabelingJun 24, 2022

  • The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · aamilesJun 24, 2022

  • The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · exploreJun 24, 2022

  • The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · watoolsJun 24, 2022

  • The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · dr-web-engineJun 24, 2022

  • The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · drxhelloJun 24, 2022

  • The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · cryptoasset-data-downloaderJun 24, 2022

  • The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · django-navbar-clientJun 24, 2022

  • The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · rootinteractiveJun 24, 2022

  • The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · beginnerJun 24, 2022

  • The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · perdidoJun 24, 2022

  • The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · ml-scannerJun 24, 2022

  • The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

    CriticalCVSS 9.8No exploitEPSS 2%

    pypi · pypiJul 22, 2022

  • The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

    CriticalCVSS 9.8No exploitEPSS 1%

    pypi · pypiJul 22, 2022

  • A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a

    HighCVSS 7.8No exploitEPSS 1%

    pypi · bsdiff4Jul 22, 2020