pyup records
2 published records for vendor pyup.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption1
- CWE-807 Reliance on Untrusted Inputs in a Security Decision1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2022-39280No exploit | Regular expression denial of service in dparsepyup · dependency parser · CWE-400 | High7.5 | — | 1.3% | Oct 6, 2022 |
16Monitor | CVE-2020-5252No exploit | Malicious package may avoid detection in python auditingpyup · safety · CWE-807 | Medium4.1 | — | 0.4% | Mar 23, 2020 |
- CVE-2022-3928030Monitor
Regular expression denial of service in dparse
HighCVSS 7.5No exploitEPSS 1%pyup · dependency parserOct 6, 2022
- CVE-2020-525216Monitor
Malicious package may avoid detection in python auditing
MediumCVSS 4.1No exploitEPSS 0%pyup · safetyMar 23, 2020