CVE-2021-34141Medium· 5.3▾ SunlitAn incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior i…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.6%
An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."
numpy < 1.22.0communications_cloud_native_core_policy = 22.1.3Upgrade past the affected range:
numpy 1.22.0Connected by shared product, vendor, weakness, or advisory.
CVE-2019-6446Critical· 9.8Numpy Deserialization of Untrusted Data
CVE-2026-106252High· 8.8Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page
CVE-2026-71892Medium· 6.9In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a message using RFC 9709 content-encryption…
CVE-2026-101912Medium· 6.3ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript
CVE-2026-101913Medium· 6.3ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript
CVE-2026-85292Medium· 4.8InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments