PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-40637Lowdbt-core: dbt has an implicit override for built-in materializations from installed packagesCVE-2024-31411Highorg.apache.streampipes:streampipes-parent: Apache StreamPipes has potential remote code execution (RCE) via file uploadCVE-2024-31979Mediumorg.apache.streampipes:streampipes-parent: Apache StreamPipes has possibility of SSRF in pipeline element installation processCVE-2024-30471Mediumorg.apache.streampipes:streampipes-parent: Apache StreamPipes potentially allows creation of multiple identical accountsCVE-2024-39877Highapache-airflow: Apache Airflow has DAG Author Code Execution possibility in airflow-schedulerCVE-2024-39863Mediumapache-airflow: Apache Airflow Potential Cross-site Scripting VulnerabilityGHSA-Q5FM-55C2-V6J9Criticalfiona: Fiona affected by CVE-2023-45853 related to MiniZip madler-zlibGHSA-G4M4-9Q4C-MFW6Highfiona: Fiona affected by CVE-2020-14152 related to madler-zlibCVE-2024-39887Mediumapache-superset: Apache Superset vulnerable to improper SQL authorizationCVE-2024-40627Mediumfastapi-opa: OpaMiddleware does not filter HTTP OPTIONS requestsCVE-2024-21513Criticallangchain-experimental: langchain-experimental vulnerable to Arbitrary Code ExecutionCVE-2024-6345Highsetuptools: setuptools vulnerable to Command Injection via package URLGHSA-5GRR-72F9-678VHighcipherbcrypt: Malware package cipherbcryptCVE-2024-39903Highsolara: Local File Inclusion in SolaraCVE-2024-39905MediumRed-DiscordBot: Red-DiscordBot vulnerable to Incorrect Authorization in commands APICVE-2024-39317Highwagtail: Wagtail regular expression denial-of-service via search query parsingCVE-2024-39614HighDjango: Django vulnerable to Denial of ServiceCVE-2024-39330HighDjango: Django Path Traversal vulnerabilityCVE-2024-39329MediumDjango: Django vulnerable to user enumeration attackCVE-2024-38875HighDjango: Django vulnerable to Denial of ServiceCVE-2024-5569Mediumzipp: zipp Denial of Service vulnerabilityCVE-2024-6227Highaim: Aim denial of service vulnerabilityGHSA-564J-V29W-RQR6Mediumkhoj-assistant: Khoj Open Redirect Vulnerability in Login PageGHSA-3V33-3WMW-3785Lowyt-dlp: yt-dlp has dependency on potentially malicious third-party code in Douyu extractorsCVE-2024-5753Highvanna: Vanna vulnerable to SQL Injection

Stop the waste.
Protect your environment with Kodem.