Python
Vendor:
First CVE: Oct 4, 2002 · Active for 23 years
185
Total CVEs
More Total CVEs than 49% of tracked products
7.7
Avg CVEs / Year
Bottom 1%
6.7
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Python over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2002
23 years ago
Most Recent CVE
Jul 9, 2026
17 days ago
CVE Severity & Scoring
Python185 CVEs
43%
42%
10%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCriticalNone
Attack Vector
Local21 (11.4%)
Network115 (62.2%)
Unknown48 (25.9%)
Physical0 (0.0%)
Adjacent Network1 (0.5%)
Attack Complexity
Low116 (62.7%)
High21 (11.4%)
Unknown48 (25.9%)
User Interaction
None107 (57.8%)
Unknown48 (25.9%)
Required25 (13.5%)
Privileges Required
Low19 (10.3%)
High6 (3.2%)
None112 (60.5%)
Unknown48 (25.9%)
Top CVEs
Signals from CVEs in this product scope (185 CVEs).
185 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0224HIGH OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to | Jun 5, 2014 | 7.4 | 83 | NO | YES |
CVE-2016-2183HIGH The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which mak | Sep 1, 2016 | 7.5 | 77 | NO | NO |
CVE-2018-25032HIGH zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. | Mar 25, 2022 | 7.5 | 56 | NO | NO |
CVE-2014-4650CRITICAL The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script sou | Feb 20, 2020 | 9.8 | 51 | NO | YES |
CVE-2008-4864HIGH Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary co | Nov 1, 2008 | 7.5 | 46 | NO | YES |
CVE-2007-4559CRITICAL Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files | Aug 28, 2007 | 9.8 | 46 | NO | NO |
CVE-2008-1721HIGH Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers in | Apr 10, 2008 | 7.5 | 44 | NO | YES |
CVE-2021-3177CRITICAL Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-poi | Jan 19, 2021 | 9.8 | 42 | NO | NO |
CVE-2018-1000802CRITICAL Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shut | Sep 18, 2018 | 9.8 | 41 | NO | NO |
CVE-2014-1912HIGH Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to exec | Mar 1, 2014 | 7.5 | 39 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (185 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.5% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
5.4% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (185 CVEs).
Media Mentions
Signals from CVEs in this product scope (185 CVEs).
Top CNAs Publishing CVEs For Python
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.9.0 | 2 | 7.8 | 1.0% | 0 | 0 |
| 3.8.4 | 1 | 7.8 | 0.9% | 0 | 0 |
| 3.8.0 | 2 | 9.0 | 5.0% | 0 | 0 |
| 3.7.0 | 4 | 7.3 | 4.3% | 0 | 0 |
| 3.6.0 | 1 | 7.5 | 4.7% | 0 | 0 |
| 3.5.1 | 2 | 8.2 | 18.1% | 0 | 1 |
| 3.5.0 | 2 | 8.2 | 18.1% | 0 | 1 |
| 3.4.4 | 2 | 8.2 | 18.1% | 0 | 1 |
| 3.4.3 | 3 | 7.5 | 15.5% | 0 | 1 |
| 3.4.2 | 5 | 6.3 | 10.0% | 0 | 1 |
| 3.4.1 | 5 | 6.3 | 10.0% | 0 | 1 |
| 3.4.0 | 5 | 6.3 | 10.0% | 0 | 1 |
| 3.4 | 3 | 5.9 | 10.5% | 0 | 1 |
| 3.3.6 | 5 | 6.3 | 10.0% | 0 | 1 |
| 3.3.5 | 6 | 5.6 | 6.5% | 0 | 1 |
| 3.3.4 | 6 | 5.7 | 7.4% | 0 | 1 |
| 3.3.3 | 8 | 6.1 | 7.4% | 0 | 2 |
| 3.3.2 | 10 | 6.1 | 8.8% | 0 | 2 |
| 3.3.1 | 10 | 6.0 | 7.2% | 0 | 2 |
| 3.3.0 | 10 | 6.5 | 7.0% | 0 | 2 |