PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-45190Mediummage-ai: Mage AI Path Traversal vulnerabilityCVE-2024-45189Mediummage-ai: Mage AI Path Traversal vulnerabilityCVE-2024-8113Highpretix: pretix Stored Cross-site Scripting vulnerabilityCVE-2024-45201Criticalllama-index-core: LlamaIndex includes an exec call for `import {cls_name}`CVE-2024-8072Mediummage-ai: Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary usersCVE-2024-41937Mediumapache-airflow: Apache Airflow Cross-site Scripting VulnerabilityCVE-2024-43371Mediumckan: Potential access to sensitive URLs via CKAN extensions (SSRF)CVE-2024-41675Mediumckan: CKAN has Cross-site Scripting vector in the Datatables view pluginCVE-2024-41674Mediumckan: CKAN may leak Solr credentials via error message in package_search actionCVE-2024-43406Highgithub.com/lf-edge/ekuiper: LF Edge eKuiper has a SQL Injection in sqlKvStoreCVE-2024-43396Mediumkhoj: Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)CVE-2024-43399Highmobsf: Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library FilesCVE-2024-6221HighFlask-Cors: Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by defaultCVE-2024-42353Mediumwebob: WebOb's location header normalization during redirect leads to open redirectCVE-2024-42474Mediumstreamlit: Path traveral in Streamlit on windowsCVE-2024-42367Mediumaiohttp: In aiohttp, compressed files as symlinks are not protected from path traversalCVE-2024-41942Highjupyterhub: JupyterHub has a privilege escalation vulnerability with the `admin:users` scopeCVE-2024-6706Mediumopen-webui: Open WebUI Stored Cross-Site Scripting VulnerabilityCVE-2024-7143Highpulpcore: Pulp incorrectly assigns RBAC permissions in tasks that create objectsCVE-2024-42005CriticalDjango: Django SQL injection vulnerabilityCVE-2024-41989MediumDjango: Django memory consumption vulnerabilityCVE-2024-41990MediumDjango: Django vulnerable to a denial-of-service attackCVE-2024-41991MediumDjango: Django vulnerable to denial-of-service attackCVE-2024-42447Lowapache-airflow-providers-fab: Apache Airflow Providers FAB Insufficient Session Expiration vulnerabilityCVE-2024-7319Mediumopenstack-heat: openstack-heat may disclose sensitive information

Stop the waste.
Protect your environment with Kodem.