PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-29033Highoauthenticator: GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspaceCVE-2024-29032Mediumqiskit-ibm-runtime: `qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary codeGHSA-CQ96-9974-V8HMLowqiskit-ibm-runtime: Dynamic Variable Evaluation in qiskit-ibm-runtimeCVE-2024-28179Criticaljupyter-server-proxy: Jupyter Server Proxy's Websocket Proxying does not require authenticationCVE-2024-21503Mediumblack: Black vulnerable to Regular Expression Denial of Service (ReDoS)CVE-2024-28865Highwiki: Denial of service via regular expressionCVE-2024-28237MediumOctoPrint: XSS via the "Snapshot Test" feature in Classic Webcam plugin settingsCVE-2023-41334Highastropy: RCE in TranformGraph().to_dot_graph functionCVE-2024-29156Mediumyaql: Information leakage in YAQLCVE-2024-22513Lowdjangorestframework-simplejwt: Improper Privilege Management in djangorestframework-simplejwtCVE-2024-27351Mediumdjango: Regular expression denial-of-service in DjangoGHSA-879P-8GW4-MCPWLowfgr: fgr Vulnerable to Insecure Default Variable InitializationCVE-2024-24770Mediumvantage6: vantage6 vulnerable to a username timing attack on recover password/MFA tokenCVE-2024-23823Mediumvantage6: vantage6's CORS settings overly permissiveCVE-2024-22203Criticalwhoogle-search: Whoogle Search Path Traversal vulnerabilityCVE-2024-22204Mediumwhoogle-search: Whoogle Search Path Traversal vulnerabilityCVE-2024-22205Criticalwhoogle-search: Whoogle Search Server-Side Request Forgery vulnerabilityCVE-2024-22417Mediumwhoogle-search: Whoogle Search Cross-site Scripting vulnerabilityCVE-2024-28746Mediumapache-airflow: Apache Airflow: Ignored Airflow PermissionCVE-2024-27305Mediumaiosmtpd: aiosmtpd vulnerable to SMTP smugglingCVE-2024-27097Mediumckan: Potential log injection in reset user endpoint in CKANCVE-2024-26164Highmssql-django: Remote Code Execution Vulnerability in Microsoft Django Backend for SQL ServerCVE-2024-28184Highweasyprint: WeasyPrint allows the attachment of arbitrary files and URLs to a PDFCVE-2024-52288Mediumlibosdp: LibOSDP RMAC revert to the beginning of the sessionCVE-2024-52296Mediumlibosdp: LibOSDP vulnerable to a null pointer deref in osdp_reply_name

Stop the waste.
Protect your environment with Kodem.