PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-38896Criticallangchain: LangChain vulnerable to arbitrary code executionGHSA-QPPV-J76H-2RPXMediumtornado: Tornado vulnerable to HTTP request smuggling via improper parsing of `Content-Length` fields and chunk lengthsCVE-2020-35139Highryu: FaucetSDN Ryu Denial of Service VulnerabilityCVE-2020-35141Highryu: FaucetSDN Ryu Denial of Service VulnerabilityCVE-2023-39553Highapache-airflow-providers-apache-drill: apache-airflow-providers-apache-drill Improper Input Validation vulnerabilityCVE-2023-40267CriticalGitPython: GitPython vulnerable to remote code execution due to insufficient sanitization of input argumentsCVE-2023-27506Mediumintel-tensorflow: Authenticated Local Privilege Escalation vulnerability in Intel Optimization for TensorflowCVE-2023-39531Mediumsentry: Sentry vulnerable to incorrect credential validation on OAuth token requestsCVE-2023-33953Highgrpcio: Excessive Iteration in gRPCCVE-2023-39523Mediumscancodeio: ScanCode.io command injection in docker image fetch processCVE-2023-39363Criticalvyper: Vyper has incorrectly allocated named re-entrancy locksCVE-2023-39349Highsentry: Privilege escalation via ApiTokensEndpointCVE-2023-38759Highwger: wger Workout Manager Cross-Site Request Forgery vulnerabilityCVE-2023-38758Mediumwger: wger Workout Manager Cross-site Scripting vulnerabilityCVE-2023-39508Highapache-airflow: Apache Airflow Execution with Unnecessary PrivilegesCVE-2023-36095Criticallangchain: langchain Code Injection vulnerabilityCVE-2023-4138Mediumrdiffweb: RDiffWeb vulnerable to Allocation of Resources Without Limits or ThrottlingGHSA-JM77-QPHF-C4W8Lowcryptography: pyca/cryptography's wheels include vulnerable OpenSSLCVE-2023-38200Highkeylime: Keylime's registrar vulnerable to Denial-of-service attack via a single open connectionCVE-2023-38699CriticalMindsDB: MindsDB can be made to not verify SSL certificatesCVE-2023-4033Highmlflow: mlflow vulnerable to OS Command InjectionCVE-2023-38686Criticalmatrix-sydent: Sydent does not verify email server certificatesCVE-2023-38673Criticalpaddlepaddle: Command injection in PaddlePaddleCVE-2023-38672Mediumpaddlepaddle: Float point exception (FPE) in paddlepaddleCVE-2023-38671Highpaddlepaddle: Heap buffer overflow in PaddlePaddle

Stop the waste.
Protect your environment with Kodem.