PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-34359Criticalllama-cpp-python: llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model MetadataCVE-2024-32874Criticalfrigate: Malicious Long Unicode filenames may cause a Multiple Application-level Denial of ServiceCVE-2024-28148Mediumapache-superset: Apache Superset Incorrect Authorization vulnerabilityCVE-2024-34252Criticalpywasm3: pywasm3 contains a global buffer overflow which leads to segmentation faultCVE-2024-34249Criticalpywasm3: pywasm3 contains a heap buffer overflow which leads to segmentation faultCVE-2024-34078Highhtml-sanitizer: Arbitrary HTML present after sanitization because of unicode normalizationCVE-2024-34069HighWerkzeug: Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domainCVE-2024-34064MediumJinja2: Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterCVE-2024-32982Highlitestar: Litestar and Starlite vulnerable to Path TraversalCVE-2024-34528Mediumwordops: WordOps has TOCTOU race conditionCVE-2024-34529Mediumnebari: Nebari prints temporary Keycloak root passwordCVE-2024-34510Highgradio: Gradio allows credential leakage on WindowsCVE-2024-34511Mediumgradio: Gradio's Component Server does not properly consider` _is_server_fn` for functionsCVE-2024-34489Highryu: Ryu Infinite Loop vulnerabilityCVE-2024-34486Highryu: Ryu Infinite Loop vulnerabilityCVE-2024-34488Highryu: Ryu Infinite Loop vulnerabilityCVE-2024-34484Mediumryu: Ryu Infinite Loop vulnerabilityCVE-2024-34487Mediumryu: Ryu Infinite Loop vulnerabilityCVE-2024-34483Highryu: Ryu Infinite Loop vulnerabilityCVE-2024-34073Highsagemaker: sagemaker-python-sdk Command Injection vulnerabilityCVE-2024-34072Highsagemaker: sagemaker-python-sdk vulnerable to Deserialization of Untrusted DataCVE-2024-34062Lowtqdm: tqdm CLI arguments injection attackCVE-2024-31636Lowlief: LIEF obtain sensitive information via the name parameterCVE-2024-34061Mediumchangedetection.io: changedetection.io Cross-site Scripting vulnerabilityCVE-2024-30251Highaiohttp: aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

Stop the waste.
Protect your environment with Kodem.