PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-35374Criticalmocodo: Mocodo vulnerable to SQL injection in `/web/generate.php`CVE-2024-28188Mediumjupyter-scheduler: jupyter-scheduler's endpoint is missing authenticationCVE-2024-32969Lowvantage6: vantage6 collaboration admins can extend their influence by expanding the collaborationCVE-2024-35061Highait-core: NASA AIT-Core uses unencrypted channels to exchange data over the networkCVE-2024-35059Criticalait-core: NASA AIT-Core vulnerable to remote code executionCVE-2024-35058Criticalait-core: NASA AIT-Core vulnerable to remote code executionCVE-2024-35057Criticalait-core: NASA AIT-Core vulnerable to remote code executionCVE-2024-35056Criticalait-core: NASA AIT-Core vulnerable to SQL InjectionCVE-2024-36039Criticalpymysql: PyMySQL SQL Injection vulnerabilityCVE-2024-1727Mediumgradio: Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading filesCVE-2024-35180Mediumomero-web: OMERO.web must check that the JSONP callback is a valid functionCVE-2024-35195Mediumrequests: Requests `Session` object does not verify requests after making first request with verify=FalseCVE-2024-34083Mediumaiosmtpd: aiosmtpd STARTTLS unencrypted commands injectionCVE-2024-4264Highlitellm: litellm passes untrusted data to `eval` function without sanitizationCVE-2024-5023Criticalconsoleme: ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git commandCVE-2024-3848Highmlflow: MLflow has a Local File Read/Path Traversal bypassCVE-2024-4263Mediummlflow: MLflow allows low privilege users to delete any artifactCVE-2024-4181Highllama-index: RunGptLLM class in LlamaIndex has a command injectionCVE-2024-4078Highlollms: LoLLMS Command Injection vulnerabilityGHSA-23J4-MW76-5V7HMediumScrapy: Scrapy allows redirect following in protocols other than HTTPGHSA-JM3V-QXMH-HXWVMediumScrapy: Scrapy's redirects ignoring scheme-specific proxy settingsCVE-2024-1968MediumScrapy: Scrapy leaks the authorization header on same-domain but cross-origin redirectsCVE-2024-32977HighOctoPrint: OctoPrint has an Authentication Bypass via X-Forwarded-For Header when autologinLocal is enabledCVE-2024-32077Mediumapache-airflow: Apache Airflow: XSS vulnerability in Task Instance Log/Log DetailsCVE-2024-34707Highnautobot: Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages

Stop the waste.
Protect your environment with Kodem.