PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-39631Criticallangchain: Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr libraryCVE-2023-41039HighRestrictedPython: Sandbox escape via various forms of "format".CVE-2023-41040MediumGitPython: GitPython blind local file inclusionCVE-2023-36811Mediumborgbackup: Archive spoofing vulnerability in borgbackupCVE-2023-39968Mediumjupyter-server: Open Redirect Vulnerability in jupyter-serverCVE-2023-40170Mediumjupyter-server: cross-site inclusion (XSSI) of files in jupyter-serverCVE-2023-40590Highgitpython: GitPython untrusted search path on Windows systems leading to arbitrary code executionCVE-2023-40889Criticalzbar: Heap-based buffer overflow in ZBarCVE-2023-40195Highapache-airflow-providers-apache-spark: Apache Airflow vulnerable arbitrary code execution via Spark serverCVE-2023-27604Highapache-airflow-providers-apache-sqoop: Airflow Sqoop Provider RCE VulnerabilityCVE-2023-40587Mediumpyramid: Pyramid static view path traversal up one directoryCVE-2023-40273Highapache-airflow: Apache Airflow Session Fixation vulnerabilityCVE-2023-37379Highapache-airflow: Apache Airflow denial of service vulnerabilityCVE-2023-39441Mediumapache-airflow-providers-smtp: Apache Airflow missing Certificate ValidationCVE-2022-25024Highjson2xml: json2xml Uncaught Exception vulnerabilityCVE-2023-36281Criticallangchain: langchain vulnerable to arbitrary code executionCVE-2022-45582Mediumhorizon: Horizon Web Dashboard Open Redirect vulnerabilityCVE-2023-40570Mediumdatasette: Datasette 1.0 alpha series leaks names of databases and tables to unauthenticated usersCVE-2023-39660Highpandasai: pandasai vulnerable to prompt injectionCVE-2023-40272Highapache-airflow-providers-apache-spark: Apache Airflow Spark Provider Improper Input Validation vulnerabilityCVE-2023-40024Mediumscancodeio: Scancode.io Reflected Cross-Site Scripting (XSS) in license endpointCVE-2023-39661Criticalpandasai: PandasAI vulnerable to arbitrary code executionCVE-2023-39662Criticalllama-index: llama-index vulnerable to arbitrary code executionCVE-2023-38860Criticallangchain: LangChain vulnerable to arbitrary code executionCVE-2023-39659Criticallangchain: LangChain vulnerable to arbitrary code execution

Stop the waste.
Protect your environment with Kodem.