PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-45813Mediumtorbot: TorBot vulnerable to Inefficient Regular Expression Complexity in validate_linkCVE-2023-46229Highlangchain: LangChain Server Side Request Forgery vulnerabilityCVE-2023-45803Mediumurllib3: urllib3's request body not stripped after redirect from 303 status changes request method to GETCVE-2023-41881Lowvantage6: vantage6 does not properly delete linked resources when deleting a collaborationCVE-2018-25091Mediumurllib3: Authorization Header forwarded on redirectCVE-2023-45348Mediumapache-airflow: Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-onlyCVE-2023-42792Mediumapache-airflow: Apache Airflow vulnerable to privilege escalationCVE-2023-42780Mediumapache-airflow: Apache Airflow vulnerable to sensitive information exposure when users list warnings for all DAGsCVE-2023-42663Mediumapache-airflow: Apache Airflow vulnerable to sensitive information exposureCVE-2023-45853Criticalpyminizip: pyminizip affected by zlib's integer overflow/heap based buffer overflow vulnerability due to vulnerable dependencyCVE-2023-28635Mediumvantage6: Defining resource name as integer may give unintended access in vantage6CVE-2023-41882Mediumvantage6: Improper Access Control in vantage6CVE-2023-23930Highvantage6: Pickle serialization vulnerable to Deserialization of Untrusted DataCVE-2023-45129Mediummatrix-synapse: matrix-synapse vulnerable to denial of service due to malicious server ACL eventsCVE-2023-41047HighOctoPrint: OctoPrint vulnerable to Improper Neutralization of Special Elements Used in a Template EngineCVE-2023-36566MediumMicrosoft.CommonDataModel.ObjectModel: Microsoft Common Data Model SDK Denial of Service VulnerabilityCVE-2023-44467Criticallangchain-experimental: langchain_experimental vulnerable to arbitrary code execution via PALChain in the python exec methodGHSA-F9PM-4G9P-6VM3Highwebp: Bundled libwebp in pywebp vulnerableCVE-2023-4570Highni-measurementlink-service: NI MeasurementLink Python Services Improper Access Restriction vulnerabilityGHSA-94VC-P8W7-5P49Highimagecodecs: Bundled libwebp in imagecodecs vulnerableCVE-2023-44389LowZope: Zope management interface vulnerable to stored cross site scripting via the title propertyCVE-2023-4237Mediumansible-core: Ansible may expose private keyCVE-2023-26151Highasyncua: asyncua vulnerable to denial of service via infinite loopCVE-2023-26150Highasyncua: asyncua Improper Authentication vulnerabilityCVE-2023-43810Highopentelemetry-instrumentation: opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics

Stop the waste.
Protect your environment with Kodem.