PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-24772Mediumapache-superset: Apache Superset: Improper Neutralization of custom SQL on embedded contextCVE-2024-27315Mediumapache-superset: Apache Superset: Improper error handling on alertsCVE-2024-25723Highzenml: ZenML Server Remote Privilege Escalation VulnerabilityCVE-2024-25711Mediumdiffoscope: diffoscope Path Traversal vulnerabilityCVE-2024-24564Lowvyper: Vyper's `extract32` can ready dirty memoryCVE-2024-26149Lowvyper: Vyper's `_abi_decode` vulnerable to Memory OverflowGHSA-P4M5-32PR-2HQRLowpypop-genomics: PyPop C extensions possible vulnerability: missing arguments and redundant null pointersCVE-2024-27444Criticallangchain-experimental: LangChain Experimental vulnerable to arbitrary code executionCVE-2024-27447Mediumpretix: pretix mishandles file validationCVE-2024-27454Highorjson: orjson does not limit recursion for deeply nested JSON documentsCVE-2024-0243Lowlangchain: langchain Server-Side Request Forgery vulnerabilityCVE-2024-21502Highfastecdsa: Uninitialized Variable in fastecdsaCVE-2024-27133Criticalmlflow: MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code ExecutionCVE-2024-27132Criticalmlflow: Cross-site Scripting in MLFlowCVE-2024-27319Mediumonnx: Onnx Out-of-bounds Read vulnerabilityCVE-2024-27318Highonnx: Onnx Directory Traversal vulnerabilityCVE-2024-1729Mediumgradio: Gradio apps vulnerable to timing attacks to guess passwordCVE-2024-26152Mediumlabel-studio: Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config GHSA-RC4P-P3J9-6577Highpypqc: pypqc private key retrieval vulnerabilityCVE-2024-26151Highmjml: Potentially untrusted input is rendered as HTML in final outputCVE-2024-26130Highcryptography: cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private…CVE-2024-23346Criticalpymatgen: pymatgen vulnerable to arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_stringCVE-2024-26134Highcbor2: Potential buffer overflow in CBOR2 decoderCVE-2024-25141Criticalapache-airflow-providers-mongo: Improper Certificate Validation in apache airflow mongo hookCVE-2024-1647Highpyhtml2pdf: Cross-site Scripting in Pyhtml2pdf

Stop the waste.
Protect your environment with Kodem.