PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-37063Highydata-profiling: ydata cross-site scriptingCVE-2024-37062Highydata-profiling: ydata unsafe deserializationCVE-2024-37064Highydata-profiling: ydata unsafe deserializationCVE-2024-37060Highmlflow: MLFlow unsafe deserializationCVE-2024-37061Highmlflow: MLFlow improper input validationCVE-2024-37058Highmlflow: MLFlow unsafe deserializationCVE-2024-37059Highmlflow: MLFlow unsafe deserializationCVE-2024-37057Highmlflow: MLFlow unsafe deserializationCVE-2024-37054Highmlflow: MLFlow unsafe deserializationCVE-2024-37055Highmlflow: MLFlow unsafe deserializationCVE-2024-37052Highmlflow: MLFlow unsafe deserializationCVE-2024-37056Highmlflow: MLFlow unsafe deserializationCVE-2024-37053Highmlflow: MLFlow unsafe deserializationCVE-2024-3829Criticalqdrant-client: qdrant input validation failure CVE-2024-4330Mediumlollms: path traversal vulnerability was identified in the parisneo/lollms-webui CVE-2024-3924Mediumtext-generation: code injection vulnerability exists in the huggingface/text-generation-inference repositoryCVE-2024-35228Mediumwagtail: Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`CVE-2024-35196Lowsentry: Slack integration leaks sensitive information in logsCVE-2024-35189Mediumethyca-fides: Sensitive Data Disclosure Vulnerability in Connection Configuration EndpointsCVE-2024-5565Criticalvanna: Vanna prompt injection code executionCVE-2024-36112Mediumnautobot: Nautobot dynamic-group-members doesn't enforce permission restrictions on member objectsCVE-2024-34715Lowethyca-fides: Fides Webserver Logs Hosted Database Password Partial Exposure VulnerabilityCVE-2024-36110Highansibleguy-webui: ansibleguy-webui Cross-site Scripting vulnerabilityCVE-2022-4969Mediumrockhopper: rockhopper Buffer Overflow vulnerabilityCVE-2024-36105Mediumdbt-core: dbt allows Binding to an Unrestricted IP Address via socketsocket

Stop the waste.
Protect your environment with Kodem.