PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-42505Mediumapache-superset: Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityCVE-2023-42502Mediumapache-superset: Apache Superset Open Redirect vulnerabilityCVE-2023-48022Criticalray: Ray has arbitrary code execution via jobs submission APICVE-2023-49081Mediumaiohttp: aiohttp's ClientSession is vulnerable to CRLF injection via versionCVE-2023-49082Mediumaiohttp: aiohttp's ClientSession is vulnerable to CRLF injection via methodGHSA-PJJW-QHG8-P2P9Mediumaiohttp: aiohttp has vulnerable dependency that is vulnerable to request smugglingCVE-2023-42501Mediumapache-superset: Apache Superset has Incorrect Default PermissionsCVE-2023-43701Mediumapache-superset: Apache Superset Cross-site Scripting vulnerabilityGHSA-RQR8-PXH7-CQ3GMediumeth-abi: Ethereum ABI decoder DoS when parsing ZSTCVE-2023-48796Highorg.apache.dolphinscheduler:dolphinscheduler: Apache DolphinScheduler sensitive information disclosureCVE-2023-48705Highnautobot: Cross-site Scripting potential in custom links, job buttons, and computed fieldsCVE-2023-37924Criticalapache-submarine: SQL injection in Apache SubmarineCVE-2023-48700Mediumnautobot-device-onboarding: Clear Text Credentials Exposed via Onboarding TaskCVE-2023-47890Highpyload-ng: Download to arbitrary folder can lead to RCECVE-2023-48699Highfastbots: Eval Injection in fastbotsCVE-2023-48299Mediumtorchserve: TorchServe ZipSlipCVE-2023-48051Highupydev: upydev has weak encryption paddingCVE-2023-46302Criticalapache-submarine: Deserialization of Untrusted Data in apache-submarineGHSA-X563-6HQV-26MRCriticalibis-framework: Ibis PyArrow dependency allows arbitrary code execution when loading a malicious data fileCVE-2023-6014Criticalmlflow: MLflow authentication requirement bypass can allow a user to arbitrarily create an accountCVE-2023-6020Criticalray: Ray Missing Authorization vulnerabilityCVE-2023-48056Highpypinksign: PyPinkSign uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryptionCVE-2023-6018Criticalmlflow: Remote Code Execution due to Full Controled File Write in mlflowCVE-2023-6015Criticalmlflow: MLflow allowed arbitrary files to be PUT onto the serverCVE-2023-6019Criticalray: Ray OS Command Injection vulnerability

Stop the waste.
Protect your environment with Kodem.