PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-28397Highjs2py: js2py allows remote code executionCVE-2024-34693Mediumapache-superset: Apache Superset server arbitrary file read CVE-2024-38356Mediumtinymce: TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp optionCVE-2024-38357Mediumtinymce: TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elementsCVE-2024-37891Mediumurllib3: urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirectsCVE-2024-34694Highlnbits: LNbits improperly handles potential network and payment failures when using Eclair backendCVE-2024-38459Highlangchain-experimental: langchain_experimental Code Execution via Python REPL accessCVE-2024-25142Lowapache-airflow: Apache Airflow does not return the "Cache-Control" header for dynamic contentGHSA-HJX6-F647-MVF9Mediuminvenio-communities: Invenio-Communities has a Cross-Site Scripting (XSS) vulnerability in React componentsCVE-2024-37300Highoauthenticator: Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0CVE-2024-36265Criticalorg.apache.submarine:submarine-server-core: Apache Submarine Server Core Incorrect Authorization vulnerabilityCVE-2024-36264Mediumorg.apache.submarine:submarine-commons-utils: Apache Submarine Commons Utils has a hard-coded secretCVE-2024-4315Criticallollms: parisneo/lollms Local File Inclusion (LFI) attackCVE-2024-35225Criticaljupyter-server-proxy: Jupyter Server Proxy has a reflected XSS issue in host parameterCVE-2024-37301Highdocument-merge-service: document-merge-service vulnerable to Remote Code Execution via Server-Side Template InjectionCVE-2024-35255Mediumazure-identity: Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege VulnerabilityCVE-2024-37014Highlangflow: Langflow remote code execution vulnerabilityCVE-2024-37568Highauthlib: Authlib has algorithm confusion with asymmetric public keysCVE-2024-4680Lowzenml: zenml-io/zenml does not expire the session after password resetCVE-2024-37388Highebookmeta: ebookmeta XML External Entity vulnerabilityCVE-2024-36827Highebookmeta: ebookmeta XML External Entity vulnerabilityGHSA-W235-7P84-XX57Mediumtornado: Tornado has a CRLF injection in CurlAsyncHTTPClient headersGHSA-753J-MPMX-QQ6GMediumtornado: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornadoCVE-2024-3429Highlollms: LoLLMS Path Traversal vulnerabilityCVE-2024-3408Highdtale: Authentication bypass in dtale

Stop the waste.
Protect your environment with Kodem.