PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-8C6X-G4FW-8RF4MediumWhatsapp-Chat-Exporter: Whatsapp-Chat-Exporter has Cross-Site Scripting vulnerability in HTML output of chats.CVE-2023-37271HighRestrictedPython: RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escapeCVE-2023-36829Mediumsentry: Sentry CORS misconfigurationCVE-2023-32732Mediumio.grpc:grpc-protobuf: gRPC connection termination issueCVE-2023-1428Highio.grpc:grpc-protobuf: gRPC Reachable Assertion issueCVE-2023-33234Highapache-airflow-providers-cncf-kubernetes: Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configurationCVE-2023-36830Mediumsqlfluff: SQLFluff users with access to config file, using `libary_path` may call arbitrary python codeCVE-2023-36827Highethyca-fides: ethyca-fides Webserver API Path Traversal vulnerabilityCVE-2023-35934Mediumyt-dlp: yt-dlp File Downloader cookie leakCVE-2023-30776Mediumapache-superset: Apache Superset vulnerable to Exposure of Sensitive InformationCVE-2023-25504Mediumapache-superset: Apache Superset Server-Side Request Forgery vulnerabilityCVE-2023-36189Highlangchain: langchain SQL Injection vulnerabilityCVE-2023-36188Criticallangchain: langchain vulnerable to arbitrary code executionCVE-2023-36814HighProducts.CMFCore: Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal moduleCVE-2023-36809Highkiwitcms: Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with FirefoxCVE-2023-34457HighMechanicalSoup: MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML formCVE-2023-32731Highio.grpc:grpc-protobuf: Connection confusion in gRPCCVE-2023-36258Criticallangchain: langchain arbitrary code execution vulnerabilityCVE-2023-36053HighDjango: Django has regular expression denial of service vulnerability in EmailValidator/URLValidatorCVE-2023-35797Criticalapache-airflow-providers-apache-hive: Apache Airflow Hive Provider Beeline remote code execution with PrincipalCVE-2023-36807MediumPyPDF2: PyPDF2 vulnerable to possible Infinite Loop when reading malformed objectsCVE-2023-36810MediumPyPDF2: PyPDF2 quadratic runtime with malformed PDF missing xref markerCVE-2023-31543Criticalpipreqs: pipreqs vulnerable to Dependency ConfusionCVE-2023-37365Mediumhnswlib: hnswlib Double Free vulnerabilityCVE-2023-36464Mediumpypdf: pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character

Stop the waste.
Protect your environment with Kodem.