PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-6569Criticalh2o: External Control of File Name or Path in h2oai/h2o-3CVE-2023-50248Mediumckan: Out of memory error when submitting the dataset form with a specially-crafted fieldCVE-2023-50263Lownautobot: Unauthenticated db-file-storage viewsGHSA-6X4H-9622-FQR6Highmeraki: Improper validation in merakiCVE-2023-50423Criticalsap-xssec: Improper Privilege Management in sap-xssecCVE-2023-46247Highvyper: incorrect storage layout for contracts containing large arraysCVE-2023-5764Mediumansible-core: Ansible template injection vulnerabilityCVE-2023-6753Highmlflow: Path traversal in MLflowCVE-2023-35625Mediummltable: Exposure of Sensitive Information in mltableCVE-2023-6709Highmlflow: Jinja2 template injection in mlflowCVE-2023-49796Mediummindsdb: Improper Input Validation in mindsdbCVE-2023-49795Mediummindsdb: Server-Side Request Forgery in mindsdbCVE-2023-49797Highpyinstaller: Local Privilege Escalation in WindowsGHSA-J4G3-3Q8X-JXQPLowdbt-core: dbt-core's secret env vars written to package-lock.json in plaintextCVE-2023-48311Mediumdockerspawner: DockerSpawner allows any image by defaultCVE-2023-6568Mediummlflow: Cross-site Scripting (XSS) in MLflowCVE-2023-26154Mediumpubnub: pubnub Insufficient Entropy vulnerabilityCVE-2023-49297LowPyDrive2: PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code executionCVE-2023-49080Mediumjupyter-server: jupyter-server errors include tracebacks with path informationCVE-2023-43472Highmlflow: Information exposure in MLflowGHSA-7VWR-G6PM-9HC8Highfastapi-proxy-lib: Cookie leakage between different users in fastapi-proxy-libCVE-2023-49277MediumDpaste: Reflected XSS Vulnerability in dpasteCVE-2023-49083Mediumcryptography: cryptography vulnerable to NULL-dereference when loading PKCS7 certificatesCVE-2023-40610Highapache-superset: Apache Superset - Elevation of PrivilegeCVE-2023-42504Mediumapache-superset: Apache Superset Allocation of Resources Without Limits or Throttling vulnerability

Stop the waste.
Protect your environment with Kodem.