PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-23637MediumOctoPrint: OctoPrint Unverified Password Change via Access Control SettingsCVE-2023-47116Mediumlabel-studio: Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` ProtectionsCVE-2024-22193Lowvantage6: vantage6 may create unencrypted tasks in encrypted collaborationCVE-2024-21671Lowvantage6-server: vantage6 vulnerable to username timing attackCVE-2024-21653Mediumvantage6: vantage6 has insecure SSH configuration for node and server containersCVE-2024-21649Highvantage6: vantage6 remote code execution vulnerabilityCVE-2024-24567Mediumvyper: Vyper's raw_call `value=` kwargs not disabled for static and delegate callsCVE-2024-23334Highaiohttp: aiohttp is vulnerable to directory traversalCVE-2024-23829Mediumaiohttp: aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separatorsCVE-2024-0960Mediumai-flow: ai-flow Deserialization of Untrusted Data vulnerabilityCVE-2024-0937Criticalsynthcity: Deserialization of untrusted data in synthcityCVE-2024-0727Mediumcryptography: Null pointer dereference in PKCS12 parsingCVE-2023-50944Highapache-airflow: Apache Airflow: Bypass permission verification to read code of other dagsCVE-2023-51702Mediumapache-airflow: Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged…CVE-2023-50943Highapache-airflow: Apache Airflow: pickle deserialization vulnerability in XComsCVE-2024-23633Mediumlabel-studio: Cross-site Scripting Vulnerability on Data ImportCVE-2023-47115Highlabel-studio: Cross-site Scripting Vulnerability on Avatar UploadCVE-2023-49657Criticalapache-superset: Cross-site Scripting in Apache supersetCVE-2024-23345Highnautobot: XSS potential in rendered Markdown fields (comments, description, notes, etc.)CVE-2024-23329Lowchangedetection.io: changedetection.io API endpoint is not secured with API tokenCVE-2024-23342Highecdsa: Minerva timing attack on P-256 in python-ecdsaCVE-2024-23341MediumTuiTse-TsuSin: html injection vulnerability in the `tuitse_html` function.CVE-2024-23751Criticalllama-index: SQL injection in llama-indexCVE-2024-23752Criticalpandasai: Code execution in pandasaiCVE-2024-23750Highmetagpt: Code execution in metagpt

Stop the waste.
Protect your environment with Kodem.