PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-2319Mediumdjango-markdownx: Django MarkdownX Cross-Site Scripting (XSS) vulnerabilityCVE-2024-2044CriticalpgAdmin4: pgAdmin 4 vulnerable to Unsafe Deserialization and Remote Code Execution by an Authenticated userCVE-2024-0818Criticalpaddlepaddle: PaddlePaddle Path Traversal vulnerabilityCVE-2024-0917Criticalpaddlepaddle: PaddlePaddle vulnerable to remote code executionCVE-2024-0815Highpaddlepaddle: PaddlePaddle command injection in paddle.utils.download._wget_download CVE-2024-0817Highpaddlepaddle: PaddlePaddle command injection vulnerabilityCVE-2024-28102Mediumjwcrypto: JWCrypto vulnerable to JWT bomb Attack in `deserialize` functionCVE-2024-27758Highrpyc: RPyC's missing security check results in code execution when using numpy.array on the server-side.CVE-2024-27287Mediumesphome: esphome vulnerable to stored Cross-site Scripting in edit configuration file APICVE-2024-22889MediumPlone: Phone information disclosure vulnerabilityGHSA-3QWC-47JF-5RF7Mediumeth-abi: eth-abi is vulnerable to recursive DoSCVE-2024-28088Lowlangchain: LangChain directory traversal vulnerabilityCVE-2024-27081Highesphome: ESPHome vulnerable to remote code execution via arbitrary file writeCVE-2024-26280Mediumapache-airflow: Apache Airflow: Incorrect Default Permissions in audit logs for Ops and Viewers usersCVE-2024-27290Mediumdocassemble.webapp: Docassemble HTML and javascript injectionCVE-2024-27291Mediumdocassemble.webapp: Docassemble open redirectCVE-2024-27292Highdocassemble.webapp: Docassemble unauthorized access through URL manipulationCVE-2024-27906Mediumapache-airflow: Apache Airflow: DAG Code and Import Error Permissions IgnoredCVE-2024-25169MediumMezzanine: Mezzanine allows attackers to bypass access control mechanismsCVE-2024-25170MediumMezzanine: Mezzanine allows attackers to bypass access controls via manipulating the Host headerCVE-2024-25128CriticalFlask-AppBuilder: Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID CVE-2024-27083MediumFlask-AppBuilder: Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)CVE-2024-24779Mediumapache-superset: Apache Superset: Improper data authorization when creating a new datasetCVE-2024-26016Mediumapache-superset: Apache Superset: Improper authorization validation on dashboards and charts importCVE-2024-24773Mediumapache-superset: Apache Superset: Improper validation of SQL statements allows for unauthorized access to data

Stop the waste.
Protect your environment with Kodem.