Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.1
CVE-2026-73030
- EPSS 0.38%
- Veröffentlicht 10.08.2026 20:09:44
- Zuletzt bearbeitet 11.08.2026 18:18:25
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can...
7.8
CVE-2023-45805
- EPSS 0.51%
- Veröffentlicht 20.10.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:27:23
pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could allow e.g. an insider or a malicious open source project to appear to depend on a trusted PyPI project, ...
1