PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-45053Highethyca-fides: Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating EngineCVE-2024-45052Lowethyca-fides: Timing-Based Username Enumeration Vulnerability in Fides Webserver AuthenticationCVE-2024-45399Mediumindico: Indico has a Cross-Site-Scripting during account creationGHSA-H4GH-QQ45-VH27Mediumcryptography: pyca/cryptography has a vulnerable OpenSSL included in cryptography wheelsGHSA-2R6G-7R83-JG72Highspam: `spam` project on PyPI compromised, malicious releases madeGHSA-QR4W-53VH-M672Highopencv-python: opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863GHSA-CXJF-X6JP-P7MCHighopencv-contrib-python: opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863GHSA-JH2J-J4J9-CRG3Highopencv-python-headless: opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863GHSA-W2PJ-9CGH-MQ2CHighopencv-contrib-python-headless: opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863GHSA-XM4R-5RJ9-2PG3Highgratient: gratient 0.5 contains credential harvesting codeGHSA-X6XG-3FJ2-4PQ3Highexotel: `exotel` project on PyPI compromised, malicious release madeGHSA-F3Q4-GGFP-JV34MediumAdyen: Adyen APIs Library for Python timing attack vulnerabilityCVE-2023-26043HighGeoNode: GeoServer style upload functionality vulnerable to XML External Entity (XXE) injectionCVE-2023-23611Lowlti-consumer-xblock: LTI 1.3 Grade Pass Back Implementation has Missing Authorization VulnerabilityCVE-2021-21401Highnanopb: nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOCCVE-2020-15100Lowfreewvs: freewvs vulnerable to denial of service through large filesCVE-2020-15101Lowfreewvs: freewvs's nested directory structure can interrupt scanCVE-2020-11093Highindy-node: Hyperledger Indy's update process of a DID does not check who signs the requestCVE-2024-43805Highjupyterlab: HTML injection in Jupyter Notebook and JupyterLab leading to DOM ClobberingCVE-2024-47833Mediumtaipy: Taipy has a Session Cookie without Secure and HTTPOnly flagsGHSA-PP84-V3MW-GG4WHightaipy: Taipy 3.1.1 affected by CVEs on flask-core and pymongoCVE-2024-42816Mediumfastapi-admin: FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product functionCVE-2024-42818Mediumfastapi-admin: FastAPI Admin Cross-site Scripting vulnerability in the Config-Create functionCVE-2024-45188Mediummage-ai: Mage AI Path Traversal vulnerabilityCVE-2024-45187Mediummage-ai: Mage AI incorrectly gives privileges to users with deleted accounts

Stop the waste.
Protect your environment with Kodem.