PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-39374Highmatrix-synapse: Synapse Denial of service due to incorrect application of event authorization rules during state resolutionCVE-2022-39335Highmatrix-synapse: Synapse does not apply enough checks to servers requesting auth events of events in a roomCVE-2023-32681Mediumrequests: Unintended leak of Proxy-Authorization header in requestsCVE-2023-32675Mediumvyper: Vyper's nonpayable default functions are sometimes payableCVE-2023-33185Lowdjango-ses: Incorrect signature verification in django-sesCVE-2023-32686Mediumkiwitcms: kiwitcms vulnerable to stored XSS via unrestricted files uploadCVE-2023-2800Mediumtransformers: transformers has Insecure Temporary FileCVE-2023-2780Criticalmlflow: mlflow Path Traversal vulnerabilityCVE-2023-29159Mediumstarlette: Starlette has Path Traversal vulnerability in StaticFilesCVE-2023-32309Highpymdown-extensions: Any file can be included with the pymdown-snippets extensionCVE-2023-32758Highgit-url-parse: git-url-parse Regular Expression Denial of ServiceCVE-2023-32303Highplanet: Planet's secret file is created with excessive permissionsCVE-2023-31146Highvyper: Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignmentCVE-2023-32058Highvyper: Vyper vulnerable to integer overflow in loopCVE-2023-32059Highvyper: Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal callsGHSA-JJGP-WHRP-GQ8MMediumin-toto: in-toto: PGP trust model not (fully) consideredCVE-2023-32076Mediumin-toto: in-toto vulnerable to Configuration Read From Local DirectoryCVE-2023-30172Highmlflow: mflow vulnerable to directory traversalCVE-2023-25754Criticalapache-airflow: Apache Airflow vulnerable to Privilege Context Switching ErrorCVE-2023-29247Mediumapache-airflow: Apache Airflow vulnerable to stored Cross-site ScriptingCVE-2023-31047CriticalDjango: Django bypasses validation when using one form field to upload multiple filesCVE-2023-31143Highmage-ai: Mage-ai missing user authenticationCVE-2023-30837Highvyper: vyper vulnerable to storage allocator overflowCVE-2023-32007Highorg.apache.spark:spark-parent_2.12: Apache Spark UI vulnerable to Command InjectionCVE-2023-30861Highflask: Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header

Stop the waste.
Protect your environment with Kodem.