Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Python Number Of NVD 124 CRITICAL 17 HIGH 51 MEDIUM 51 LOW 5
URL https://www.python.org/
Explanation A universally usable scripting language that does not require compilation and is executed by an interpreter.
It can be programmed in a variety of formats such as object-oriented, imperative, procedural, and functional.
It can be programmed in various formats such as object-oriented, imperative, procedural, and functional, and can be easily used as it is initially installed on most Unix and Linux distributions.
The language specification is simple and designed so that anyone can write the same kind of code, and it is the language of choice for many projects and companies.

It is widely used in the following applications due to its rich library.

AI (Deep Learning, Machine Learning, Deep Learning)
Web applications
Scripts for server administration

It is my personal favorite language.

Basically, it is supported for 5 years after its release.
Tag
  • Python Software Foundation License
  • オープンソース

Add Information URL
No Type Name URL
1 https://www.python.org/downloads/
2 https://devguide.python.org/devcycle/#end-of-life-branches
3 https://devguide.python.org/
4 https://github.com/python

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
61 Python3.12 3.12.12 Oct. 9, 2025 Oct. 2, 2023 Oct. 31, 2028 0 2 2 0
62 Python3.11 3.11.14 Oct. 9, 2025 Oct. 24, 2022 Oct. 31, 2027 0 9 3 0
63 Python3.10 3.10.19 Oct. 9, 2025 Oct. 4, 2021 Oct. 31, 2026 2 12 7 0
64 Python3.9 3.9.25 Oct. 31, 2025 Oct. 5, 2020 Oct. 5, 2025 6 15 11 0
65 Python3.8 3.8.20 Sept. 6, 2024 Oct. 14, 2019 Oct. 14, 2024 8 18 15 0
66 Python3.7 3.7.17 June 6, 2023 June 27, 2018 June 27, 2023 9 25 20 0
67 Python3.6 3.6.15 Sept. 3, 2021 Dec. 23, 2016 Dec. 23, 2021 9 24 20 0
68 Python3.5 3.5.10 Sept. 5, 2020 Sept. 13, 2015 Sept. 13, 2020 9 25 19 0
69 Python3.4 3.4.10 March 18, 2019 March 17, 2014 March 18, 2019 8 26 20 1
70 Python3.3 3.3.7 Sept. 19, 2017 Sept. 29, 2012 Sept. 29, 2017 7 22 24 1
71 Python3.2 3.2.6 Oct. 12, 2014 Feb. 20, 2011 Feb. 20, 2016 5 19 27 2
72 Python2.7 2.7.18 April 20, 2020 July 3, 2010 Jan. 1, 2020 10 25 31 3
73 Python3.1 3.1.5 Aug. 17, 2009 June 26, 2009 April 9, 2012 4 19 33 1
74 Python3.0 3.0.1 Feb. 13, 2009 Dec. 19, 2008 June 27, 2009 4 18 24 1
75 Python2.6 2.6.9 Jan. 29, 2013 4 15 26 3
76 Python2.5 2.5.6 Jan. 1, 2000 4 25 29 2
77 Python2.4 2.4.6 Jan. 1, 2000 4 24 26 3
78 Python2.3 2.3.7 Jan. 1, 2000 4 23 25 3
79 Python2.2 2.2.3 Jan. 1, 2000 4 24 26 3
80 Python2.1 2.1.3 Jan. 1, 2000 4 22 26 3
81 Python2.0 2.0.1 Jan. 1, 2000 4 22 26 3
82 Python1.6 1.6.1 Jan. 1, 2000 3 22 21 3
83 Python1.5 1.5.2 Jan. 1, 2000 3 22 21 3
84 Python1.4 1.4 Jan. 1, 2000 3 21 21 3
85 Python1.3 1.3 Jan. 1, 2000 3 21 21 3
86 Python1.2 1.2 Jan. 1, 2000 3 21 21 3
87 Python1.1 1.1.1 Jan. 1, 2000 3 21 21 3
88 Python1.0 1.0.2 Jan. 1, 2000 3 21 21 3
89 Python0.9 0.9.9 Jan. 1, 2000 3 21 21 3
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
61 7.5
5.0
HIGH
Network
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of s… NVD-CWE-noinfo
CVE-2018-1061 cpe:2.3:a:python:python:3.7.0:rc1
cpe:2.3:a:python:python:3.7.0:beta5
cpe:2.3:a:python:python:3.7.0:beta4
cpe:…

3.0
3.6
3.5.0


3.6.4
3.5.5



2.7.15
3.4.9

2024-11-21 12:59
2018-06-19
Show GitHub Exploit DB Packet Storm
62 7.5
5.0
HIGH
Network
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service. NVD-CWE-noinfo
CVE-2018-1060 cpe:2.3:a:python:python:*:* 2.7.0
3.5.0
3.0.0






3.6.0
2.7.15
3.5.6
3.4.9
3.6.5
2024-11-21 12:59
2018-06-18
Show GitHub Exploit DB Packet Storm
63 9.8
7.5
CRITICAL
Network
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50. CWE-190
 Integer Overflow or Wraparound
CVE-2016-9063 cpe:2.3:a:python:python:*:* 3.6.0
3.5.0
3.4.0
3.3.0
2.7.0








3.6.2
3.5.4
3.4.7
3.3.7
2.7.15
2024-11-21 12:00
2018-06-12
Show GitHub Exploit DB Packet Storm
64 6.7
7.2
MEDIUM
Local
Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, li… CWE-120
Classic Buffer Overflow
CVE-2018-1000117 cpe:2.3:a:python:python:3.7.0:beta5
cpe:2.3:a:python:python:3.7.0:beta4
cpe:2.3:a:python:python:3.7.0:beta3
cp…
3.2.0
3.5.0
3.6.0




3.4.9
3.5.6
3.6.5
2024-11-21 12:39
2018-03-7
Show GitHub Exploit DB Packet Storm
65 6.5
4.3
MEDIUM
Network
The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exceptio… CWE-369
 Divide By Zero
CVE-2017-18207 cpe:2.3:a:python:python:*:* 3.6.4 2024-11-21 12:19
2018-03-1
Show GitHub Exploit DB Packet Storm
66 3.6
3.3
LOW
Local
Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be … CWE-787
CWE-416
 Out-of-bounds Write
 Use After Free
CVE-2018-1000030 cpe:2.3:a:python:python:*:* 2.7.14 2024-11-21 12:39
2018-02-9
Show GitHub Exploit DB Packet Storm
67 8.8
6.8
HIGH
Network
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-… CWE-74
Injection
CVE-2017-17522 cpe:2.3:a:python:python:*:* 3.6.3 2024-11-21 12:18
2017-12-15
Show GitHub Exploit DB Packet Storm
68 9.8
7.5
CRITICAL
Network
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code ex… CWE-190
 Integer Overflow or Wraparound
CVE-2017-1000158 cpe:2.3:a:python:python:*:*
3.5.0
3.4.0




2.7.15
3.5.5
3.4.8
2024-11-21 12:04
2017-11-17
Show GitHub Exploit DB Packet Storm
69 5.9
4.3
MEDIUM
Network
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negati… CWE-129
 Improper Validation of Array Index
CVE-2014-4616 cpe:2.3:a:python:python:*:* 3.3.0
2.7.0
3.0.0
3.4.0






3.3.6
2.7.7
3.2.6
3.4.1
2024-11-21 11:10
2017-08-25
Show GitHub Exploit DB Packet Storm
70 7.5
5.0
HIGH
Network
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an … CWE-611
CWE-835
XXE
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2017-9233 cpe:2.3:a:python:python:*:* 3.6.0
3.5.0
3.4.0
3.3.0
2.7.0








3.6.2
3.5.4
3.4.7
3.3.7
2.7.15
2024-11-21 12:35
2017-07-26
Show GitHub Exploit DB Packet Storm