PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-51649Lownautobot: Nautobot missing object-level permissions enforcement when running Job ButtonsCVE-2023-51449Highgradio: Gradio makes the `/file` secure against file traversal and server-side request forgery attacksCVE-2023-49920Mediumapache-airflow: Apache Airflow Cross-Site Request Forgery vulnerabilityCVE-2023-50783Mediumapache-airflow: Apache Airflow Improper Access Control vulnerabilityCVE-2023-48291Mediumapache-airflow: Apache Airflow vulnerable to Exposure of Resource to Wrong SphereCVE-2023-47265Mediumapache-airflow: Apache Airflow has a stored cross-site scripting vulnerabilityCVE-2023-7018Hightransformers: transformers has a Deserialization of Untrusted Data vulnerabilityCVE-2023-6975Criticalmlflow: MLFlow Path Traversal VulnerabilityCVE-2023-6977Highmlflow: MLflow Local File Disclosure VulnerabilityCVE-2023-6974Criticalmlflow: MLflow Server-Side Request Forgery (SSRF)CVE-2023-6976Highmlflow: MLflow Path Traversal VulnerabilityCVE-2023-6909Highmlflow: MLflow Path Traversal VulnerabilityGHSA-9WGG-M99Q-HHFCHighemailproxy: Expired tokens can be renewed without validating the account passwordCVE-2023-6730Criticaltransformers: transformers has a Deserialization of Untrusted Data vulnerabilityCVE-2023-46104Mediumapache-superset: Apache Superset uncontrolled resource consumptionCVE-2023-49734Highapache-superset: Apache Superset incorrect write permissions vulnerabilityCVE-2023-49736Mediumapache-superset: Apache Superset SQL injection vulnerabilityCVE-2023-6940Highmlflow: mlflow Command Injection vulnerabilityGHSA-4H72-34J6-J8X7Mediummalojaserver: Maloja error page XSS vulnerabilityCVE-2023-48795Mediumrussh: Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka TerrapinGHSA-HFMC-7525-MJ55Mediumasyncssh: AsyncSSH vulnerable to Prefix Truncation Attack (a.k.a. Terrapin Attack) against ChaCha20-Poly1305 and Encrypt-then-MACCVE-2023-50715Mediumhomeassistant: User accounts disclosed to unauthenticated actors on the LANCVE-2023-50731Highmindsdb: GitHub Security Lab (GHSL) Vulnerability Report: Arbitary write GHSL-2023-182 CVE-2023-6831Criticalmlflow: Path traversal in MLflowCVE-2023-6572Criticalgradio: Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Stop the waste.
Protect your environment with Kodem.