PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-43804Highurllib3: `Cookie` HTTP header isn't stripped on cross-origin redirectsCVE-2023-44463Mediumpretix: pretix potential IP address spoofing vulnerabilityCVE-2023-43654Criticaltorchserve: TorchServe Server-Side Request Forgery vulnerabilityGHSA-4MQG-H5JF-J9M7Criticaltorchserve: TorchServe Pre-Auth Remote Code ExecutionCVE-2023-5289Highrdiffweb: Rdiffweb Allocation of Resources Without Limits or Throttling vulnerabilityCVE-2023-44464Highpretix: pretix allows Pillow to parse EPS filesCVE-2023-26145Criticalpydash: pydash Command Injection vulnerabilityCVE-2023-42460Mediumvyper: Vyper's `_abi_decode` input not validated in complex expressionsCVE-2023-42453Mediummatrix-synapse: matrix-synapse vulnerable to improper validation of receipts allows forged read receiptsCVE-2023-41335Lowmatrix-synapse: matrix-synapse vulnerable to temporary storage of plaintext passwords during password changesCVE-2023-43364Criticalsearchor: Searchor CLI's Search vulnerable to Arbitrary Code using EvalCVE-2023-40581Highyt-dlp: yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`CVE-2023-41419Criticalgevent: Gevent allows remote attacker to escalate privilegesCVE-2023-1636Mediumbarbican: OpenStack Barbican information disclosure vulnerabilityCVE-2023-1633Mediumbarbican: OpenStack Barbican credential leak flawCVE-2023-1625Highopenstack-heat: OpenStack Heat information leak vulnerabilityCVE-2023-5002Mediumpgadmin4: pgAdmin failed to properly control the server code GHSA-HC5C-R8M5-2GFHLowplone.restapi: plone.restapi vulnerable to Stored Cross Site Scripting with SVG image in user portraitCVE-2023-41048Lowplone.namedfile: plone.namedfile vulnerable to Stored Cross Site Scripting with SVG imagesGHSA-V8GR-M533-GHJ9Lowcryptography: Vulnerable OpenSSL included in cryptography wheelsCVE-2023-42457Mediumplone.rest: plone.rest vulnerable to Denial of Service when ++api++ is used many timesCVE-2023-42458LowZope: Zope vulnerable to Stored Cross Site Scripting with SVG imagesCVE-2023-42443Highvyper: Vyper vulnerable to memory corruption in certain builtins utilizing `msize`CVE-2023-42439HighGeoNode: GeoNode vulnerable to SSRF Bypass to return internal host dataCVE-2019-19450Criticalreportlab: ReportLab vulnerable to remote code execution via paraparser

Stop the waste.
Protect your environment with Kodem.