PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-4215Mediumpgadmin4: pgAdmin is affected by a multi-factor authentication bypass vulnerabilityCVE-2024-4216HighpgAdmin4: pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payloadCVE-2024-3955Criticalcbpi4: CraftBeerPi 4 allows arbitrary code executionCVE-2024-32882Lowwagtail: Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`CVE-2024-32979Highnautobot: nautobot has reflected Cross-site Scripting potential in all object list viewsCVE-2023-46960HighPyPXE: PyPXE Buffer Overflow vulnerabilityCVE-2023-1000Mediumdcnnt: dcnnt-py is vulnerable to command injection via Notification HandlerCVE-2024-33664Mediumpython-jose: python-jose denial of service via compressed JWE contentCVE-2024-33663Criticalpython-jose: python-jose algorithm confusion with OpenSSH ECDSA keysCVE-2024-32481Mediumvyper: vyper's range(start, start + N) reverts for negative numbersCVE-2024-32645Mediumvyper: vyper performs incorrect topic logging in raw_logCVE-2024-32646Mediumvyper: vyper performs double eval of the slice start/length args in certain casesCVE-2024-32647Mediumvyper: vyper performs double eval of raw_args in create_from_blueprintCVE-2024-32648Mediumvyper: vyper default functions don't respect nonreentrancy keysCVE-2024-32649Mediumvyper: vyper performs multiple eval of `sqrt()` argument built inCVE-2024-32880Criticalpyload-ng: pyLoad allows upload to arbitrary folder lead to RCECVE-2024-32879Mediumsocial-auth-app-django: social-auth-app-django affected by Improper Handling of Case SensitivityCVE-2024-31208Mediummatrix-synapse: Synapse V2 state resolution weakness allows Denial of Service (DoS)GHSA-W228-RFPX-FHM4Mediumcg: cg vulnerable to an Open Redirect Vulnerability on Referer HeaderGHSA-P72Q-H37J-3HQ7Highdbt-core: dbt uses a SQLparse version with a high vulnerabilityCVE-2024-28717Highstorlets: OpenStack Storlets arbitrary code execution vulnerabilityCVE-2024-29733Lowapache-airflow-providers-ftp: Improper Certificate Validation vulnerability in Apache Airflow FTP ProviderCVE-2024-1681Mediumflask-cors: flask-cors vulnerable to log injection when the log level is set to debugCVE-2024-32474Highsentry: Sentry vulnerable to leaking superuser cleartext password in logsCVE-2024-27306Mediumaiohttp: aiohttp Cross-site Scripting vulnerability on index pages for static file handling

Stop the waste.
Protect your environment with Kodem.