PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-77HH-43CM-V8J6Lowtuf: tuf's Metadata API: Targets.get_delegated_role() is missing input validationCVE-2024-3572Highscrapy: Scrapy decompression bomb vulnerabilityCVE-2024-3574Highscrapy: Scrapy authorization header leakage on cross-domain redirectCVE-2024-1892Highscrapy: Scrapy vulnerable to ReDoS via XMLFeedSpiderCVE-2024-24762Highpython-multipart: python-multipart vulnerable to Content-Type Header ReDoSGHSA-C4CM-R9FH-JGJ9Lowcommonground-api-common: commonground-api-common unexploitable privilege escalation in JWT authentication middlewareCVE-2024-21624Mediumnonebot2: NoneBot Potential Information Leak in User-Constructed Message TemplatesCVE-2024-1314Highkinto-attachment: Kinto Attachment's attachments can be replaced on read-only recordsCVE-2024-24825CriticalDIRAC: DIRAC's TokenManager does not check permissions on cached tokensCVE-2024-24811CriticalProducts.SQLAlchemyDA: SQLAlchemyDA unauthenticated arbitrary SQL query executionCVE-2024-24563Criticalvyper: Vyper negative array index bounds checksCVE-2024-24680Highdjango: Django denial-of-service attack in the intcomma template filterCVE-2024-24591Highclearml: Allegro AI ClearML path traversal vulnerabilityCVE-2024-24590Highclearml: Allegro AI ClearML vulnerable to deserialization of untrusted dataCVE-2024-0690Mediumansible-core: Ansible-core information disclosure flawCVE-2024-24595Mediumclearml: Allegro AI ClearML Stores Credentials in Plaintext in MongoDB InstanceCVE-2024-0964Highgradio: Gradio Path Traversal vulnerabilityCVE-2024-24808Mediumpyload-ng: pyLoad open redirect vulnerability due to improper validation of the is_safe_url functionCVE-2023-50782Highcryptography: Python Cryptography package vulnerable to Bleichenbacher timing oracle attackCVE-2023-50781Mediumm2crypto: m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657CVE-2024-24559Lowvyper: Vyper sha3 codegen bugCVE-2024-24560Lowvyper: Vyper's external calls can overflow return data to return input bufferCVE-2024-21485Mediumdash-core-components: Dash apps vulnerable to Cross-site ScriptingCVE-2024-24561Criticalvyper: Vyper's bounds check on built-in `slice()` function can be overflowedCVE-2024-1141Mediumglance-store: glance-store logs s3 access keys

Stop the waste.
Protect your environment with Kodem.