PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-42441Mediumvyper: Vyper has incorrect re-entrancy lock when key is empty stringCVE-2023-41626Mediumgradio: Gradio arbitrary file upload vulnerabilityCVE-2023-41267Highapache-airflow-providers-apache-hdfs: Apache HDFS Provider error message suggestedCVE-2023-4785Highgrpc: Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)CVE-2023-40712Highapache-airflow: Apache Airflow information exposure vulnerabilityCVE-2023-40611Mediumapache-airflow: Apache Airflow Incorrect Authorization vulnerabilityCVE-2023-4863Highlibwebp-sys2: libwebp: OOB write in BuildHuffmanTableCVE-2023-41885Mediumpiccolo: Piccolo's current `BaseUser.login` implementation is vulnerable to time based user enumerationCVE-2023-41329Loworg.wiremock:wiremock-standalone: Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modesCVE-2023-41319Highethyca-fides: Remote Code Execution in Custom Integration UploadCVE-2023-41050MediumAccessControl: Information disclosure in AccessControlCVE-2023-39265Mediumapache-superset: Apache Superset Improper Input Validation vulnerabilityCVE-2023-32672Mediumapache-superset: Apache Superset has incorrect authorization checkCVE-2023-37941Mediumapache-superset: Apache Superset Deserialization of Untrusted Data vulnerabilityCVE-2023-36388Mediumapache-superset: Apache Superset Server Side Request Forgery vulnerabilityCVE-2023-27523Mediumapache-superset: Apache Superset vulnerable to improper data authorizationCVE-2023-27526Mediumapache-superset: Apache Superset users may incorrectly create resources using the import charts feature CVE-2023-39264Mediumapache-superset: Apache Superset may expose internal traces on REST API endpointsCVE-2023-36387Mediumapache-superset: Apache Superset has improper default REST API permission for Gamma usersCVE-2023-38201Highkeylime: Keylime registrar and (untrusted) Agent can be bypassed by an attackerCVE-2023-20897Mediumsalt: Salt vulnerable to denial of serviceCVE-2023-20898Mediumsalt: Salt can cause Git Providers to get wrong dataCVE-2023-41057Lowhyper-bump-it: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-itCVE-2023-41052Mediumvyper: incorrect order of evaluation of side effects for some builtinsCVE-2023-40015Mediumvyper: Vyper: reversed order of side effects for some operations

Stop the waste.
Protect your environment with Kodem.