Python

Vendor:

First CVE: Oct 4, 2002 · Active for 23 years

185
Total CVEs
More Total CVEs than 49% of tracked products
7.7
Avg CVEs / Year
Bottom 1%
6.7
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Python over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2002
23 years ago
Most Recent CVE
Jul 9, 2026
17 days ago

CVE Severity & Scoring

Python185 CVEs
All CVEs352,713 CVEs
LowMediumHighCriticalNone
Attack Vector
Local21 (11.4%)
Network115 (62.2%)
Unknown48 (25.9%)
Physical0 (0.0%)
Adjacent Network1 (0.5%)
Attack Complexity
Low116 (62.7%)
High21 (11.4%)
Unknown48 (25.9%)
User Interaction
None107 (57.8%)
Unknown48 (25.9%)
Required25 (13.5%)
Privileges Required
Low19 (10.3%)
High6 (3.2%)
None112 (60.5%)
Unknown48 (25.9%)

Top CVEs

Signals from CVEs in this product scope (185 CVEs).

185 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to
Jun 5, 20147.483NOYES
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which mak
Sep 1, 20167.577NONO
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Mar 25, 20227.556NONO
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script sou
Feb 20, 20209.851NOYES
Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary co
Nov 1, 20087.546NOYES
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files
Aug 28, 20079.846NONO
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers in
Apr 10, 20087.544NOYES
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-poi
Jan 19, 20219.842NONO
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shut
Sep 18, 20189.841NONO
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to exec
Mar 1, 20147.539NOYES

Exploit Exposure

Signals from CVEs in this product scope (185 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.5% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
5.4% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (185 CVEs).

Media Mentions

Signals from CVEs in this product scope (185 CVEs).

Top CNAs Publishing CVEs For Python

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.9.027.81.0%00
3.8.417.80.9%00
3.8.029.05.0%00
3.7.047.34.3%00
3.6.017.54.7%00
3.5.128.218.1%01
3.5.028.218.1%01
3.4.428.218.1%01
3.4.337.515.5%01
3.4.256.310.0%01
3.4.156.310.0%01
3.4.056.310.0%01
3.435.910.5%01
3.3.656.310.0%01
3.3.565.66.5%01
3.3.465.77.4%01
3.3.386.17.4%02
3.3.2106.18.8%02
3.3.1106.07.2%02
3.3.0106.57.0%02