PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-46695HighDjango: Django potential denial of service vulnerability in UsernameField on WindowsCVE-2023-46250Mediumpypdf: Possible Infinite Loop when PdfWriter(clone_from) is used with a PDFCVE-2023-43796Mediummatrix-synapse: Synapse vulnerable to leak of remote user device informationCVE-2023-46215Highapache-airflow-providers-celery: Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerabilityCVE-2023-41893Mediumhomeassistant: Home Assistant vulnerable to account takeover via auth_callback loginCVE-2023-46137Mediumtwisted: twisted.web has disordered HTTP pipeline responseCVE-2023-5752Mediumpip: Command Injection in pip when used with MercurialCVE-2023-46136Mediumwerkzeug: Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginningCVE-2023-46134Mediumdtale: dtale vulnerable to Remote Code Execution through the Custom Filter InputCVE-2023-46128Highnautobot: Nautobot vulnerable to exposure of hashed user passwords via REST APICVE-2023-46126Lowethyca-fides: Fides JavaScript Injection Vulnerability in Privacy Center URLCVE-2023-46125Mediumethyca-fides: Fides Information Disclosure Vulnerability in Config API EndpointCVE-2023-46124Highethyca-fides: Fides Server-Side Request Forgery Vulnerability in Custom Integration UploadCVE-2023-46288Mediumapache-airflow: Apache Airflow vulnerable to Exposure of Sensitive InformationCVE-2021-46898Mediumdjango-grappelli: Django Grappelli Open Redirect vulnerabilityCVE-2021-46897Mediumcoderedcms: Wagtail CRX CodeRed Extensions vulnerable to Path TraversalCVE-2023-32786Highlangchain: Langchain Server-Side Request Forgery vulnerabilityCVE-2023-32785Criticallangchain: Langchain SQL Injection vulnerabilityCVE-2023-45805Highpdm: PDM Trojan LockfileCVE-2023-5690Mediummodoboa: modoboa Cross-Site Request Forgery vulnerabilityCVE-2023-5688Criticalmodoboa: modoboa Cross-site Scripting vulnerabilityCVE-2023-5689Highmodoboa: modoboa Cross-site Scripting vulnerabilityCVE-2023-44690Mediummycli: mycli has Inadequate Encryption StrengthCVE-2023-45815Higharchivebox: Viewing wget extractor output while logged in as an admin allows archived JS to execute in the admins contextCVE-2023-45809Lowwagtail: Wagtail vulnerable to disclosure of user names via admin bulk action views

Stop the waste.
Protect your environment with Kodem.