Search CVE reports


Toggle filters

261 – 270 of 829 results


CVE-2024-34078

Medium priority
Vulnerable

html-sanitizer is an allowlist-based HTML cleaner. If using `keep_typographic_whitespace=False` (which is the default), the sanitizer normalizes unicode to the NFKC form at the end. Some unicode characters normalize to chevrons;...

1 affected package

python-html-sanitizer

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-html-sanitizer Not in release Vulnerable Vulnerable Not in release
Show less packages

CVE-2024-34069

Medium priority
Fixed

Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the...

1 affected package

python-werkzeug

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-werkzeug Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-30251

Medium priority

Some fixes available 3 of 4

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server...

1 affected package

python-aiohttp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Not affected Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-33664

Medium priority
Needs evaluation

python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to...

1 affected package

python-jose

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-jose Not in release Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2024-33663

Medium priority
Needs evaluation

python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.

1 affected package

python-jose

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-jose Not in release Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2024-32879

Medium priority
Needs evaluation

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and...

1 affected package

python-social-auth

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-social-auth Not in release Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-3651

Medium priority

Some fixes available 11 of 13

A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic...

2 affected packages

python-idna, python-pip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-idna Fixed Fixed Fixed Fixed
python-pip Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-1681

Medium priority

Some fixes available 3 of 4

corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in...

1 affected package

python-flask-cors

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-flask-cors Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-27306

Medium priority

Some fixes available 4 of 5

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse...

1 affected package

python-aiohttp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-21090

Medium priority
Needs evaluation

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 8.3.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network...

1 affected package

mysql-connector-python

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mysql-connector-python Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages