Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Python

First CVE: Oct 4, 2002Active for: 24 yearsTotal CVEs: 315
47.1
VTI Score
High

Python's vulnerability footprint is concentrated in a small set of core libraries and tools—the Python interpreter itself alongside widely embedded packages such as Pillow, urllib3, Requests, and Keyring—that collectively sit deep in the software supply chain and power countless applications, services, and development workflows. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting both the native-code components within these libraries and their foundational role in application security and data handling. The recurring weakness classes, including improper input validation, integer overflow, and out-of-bounds reads, are characteristic of the parsing, serialization, and memory-handling logic essential to a runtime and its ecosystem of I/O and cryptographic packages. Defenders should prioritize Python interpreter and core-library updates broadly, as remediation typically requires coordinated patching across dependent applications; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
315
Total CVEs
More Total CVEs than 100% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Python over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2002
23 years ago
Most Recent CVE
Jul 14, 2026
12 days ago

Products(29 total)

Top CVEs

Signals from CVEs in this vendor scope (315 CVEs).

315 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-0224HIGH
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to
Jun 5, 20147.483NOYES
CVE-2016-2183HIGH
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which mak
Sep 1, 20167.577NONO
CVE-2018-25032HIGH
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Mar 25, 20227.556NONO
CVE-2014-4650CRITICAL
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script sou
Feb 20, 20209.851NOYES
CVE-2008-4864HIGH
Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary co
Nov 1, 20087.546NOYES
CVE-2007-4559CRITICAL
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files
Aug 28, 20079.846NONO
CVE-2008-1721HIGH
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers in
Apr 10, 20087.544NOYES
CVE-2021-3177CRITICAL
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-poi
Jan 19, 20219.842NONO
CVE-2018-1000802CRITICAL
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shut
Sep 18, 20189.841NONO
CVE-2014-1912HIGH
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to exec
Mar 1, 20147.539NOYES
View all 315 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products315 CVEs
40%
44%
11%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCriticalNone
Attack Vector
Local41 (13.0%)
Network208 (66.0%)
Unknown64 (20.3%)
Physical0 (0.0%)
Adjacent Network2 (0.6%)
Attack Complexity
Low221 (70.2%)
High30 (9.5%)
Unknown64 (20.3%)
User Interaction
None190 (60.3%)
Unknown64 (20.3%)
Required56 (17.8%)
Privileges Required
Low28 (8.9%)
High7 (2.2%)
None216 (68.6%)
Unknown64 (20.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (315 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.3% of CVEs· 97th percentile
Nuclei
1 CVE
0.3% of CVEs· 95th percentile
ExploitDB
10 CVEs
3.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Python.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Python — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Python's Products

View all 11 CNAs →

Top CWEs