PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-23732Mediumembedchain: ReDoS in EmbedchainCVE-2024-23731Criticalembedchain: Code execution in EmbedchainCVE-2024-23730Criticalllama-hub: Unsafe yaml deserialization in llama-hubCVE-2024-0521Criticalpaddlepaddle: Code Injection in paddlepaddleCVE-2023-50447CriticalPillow: Arbitrary Code Execution in PillowCVE-2024-22421Highjupyterlab: JupyterLab vulnerable to potential authentication and CSRF tokens leakCVE-2024-22420Mediumjupyterlab: JupyterLab vulnerable to SXSS in Markdown PreviewCVE-2024-22419Highvyper: concat built-in can corrupt memory in vyperCVE-2024-22416Criticalpyload-ng: Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalationCVE-2024-22415Highjupyter-lsp: Unsecured endpoints in the jupyter-lsp server extensionCVE-2024-0669HighPlone: Cross-Frame Scripting vulnerability has been found on Plone CMSGHSA-XGFM-FJX6-62MJMediumreadthedocs-sphinx-search: readthedocs-sphinx-search vulnerable to cross-site scripting when including search results from malicious projectsCVE-2023-6395Mediumtemplated_dictionary: Privilege escalation for users that can access mock configurationCVE-2023-46226Highorg.apache.iotdb:iotdb-core: Remote Code Execution vulnerability in Apache IoTDB via UDFCVE-2023-52289Highflaskcode: Path traversal in flaskcodeCVE-2023-52288Highflaskcode: Path traversal in flaskcodeGHSA-8QW9-GF7W-42X5Mediumstreamlit: Minor fix to previous patch for CVE-2022-35918CVE-2016-20021Highportage: Gentoo Portage missing PGP validation of executed codeCVE-2024-22195Mediumjinja2: Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterCVE-2024-22194Lowcdo-local-uuid: cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration codeCVE-2024-22190HighGitPython: Untrusted search path under some conditions on Windows allows arbitrary code executionCVE-2024-21669Criticalaries-cloudagent: Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VCCVE-2023-45139Highfonttools: fonttools XML External Entity Injection (XXE) VulnerabilityCVE-2023-50974Mediumappwrite-cli: Apprite CLI makes Use of Hard-coded CredentialsCVE-2024-21644Highpyload-ng: pyload Unauthenticated Flask Configuration Leakage vulnerability

Stop the waste.
Protect your environment with Kodem.