PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-83FM-W79M-64R5Criticalmlflow: Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIsCVE-2023-2356Highmlflow: Relative path traversal in mlflowCVE-2022-37454Criticalpysha3: Buffer overflow in sponge queue functionsCVE-2023-30613Highkiwitcms: Unrestricted file upload in kiwi TCMSCVE-2023-30629Highvyper: Incorrect success value returned in vyperCVE-2023-27524Highapache-superset: Apache superset missing check for default SECRET_KEYCVE-2023-30544Lowkiwitcms: kiwi TCMS has possibility for user to update email address to unverified oneCVE-2023-30608Mediumsqlparse: sqlparse contains a regular expression that is vulnerable to Regular Expression Denial of ServiceCVE-2023-2228Highmodoboa: modoboa vulnerable to Cross-Site Request ForgeryCVE-2023-2227Criticalmodoboa: Improper Authorization in modoboaCVE-2023-28459Highpretalx: pretalx vulnerable to path traversal in HTML exportCVE-2023-28458Mediumpretalx: pretalx allows path traversal in HTML exportCVE-2023-2160Mediummodoboa: Modoboa has Weak Password RequirementsCVE-2023-27525Mediumapache-superset: Apache Superset vulnerable to Improper AuthorizationCVE-2023-24831Criticalorg.apache.iotdb:iotdb-grafana-connector: Apache IoTDB Grafana Connector vulnerable to Improper AuthenticationCVE-2023-22946Criticalorg.apache.spark:spark-core_2.12: Apache Spark vulnerable to Improper Privilege ManagementCVE-2021-34337Highmailman: Mailman Core vulnerable to timing attacksCVE-2022-2525Mediumcalibreweb: Improper Restriction of Excessive Authentication Attempts in calibrewebCVE-2023-2106Highcalibreweb: Weak Password Requirements in calibrewebCVE-2023-29005HighFlask-AppBuilder: Flask-AppBuilder Has No Rate Limiting on Login AUTH DBCVE-2023-25392Mediumbigflow: Allegro Tech BigFlow vulnerable to Missing SSL Certificate ValidationCVE-2023-28707Highapache-airflow-providers-apache-drill: Apache Airflow Drill Provider vulnerable to improper input validation CVE-2023-28710Highapache-airflow-providers-apache-spark: Apache Airflow Spark Provider vulnerable to improper input validationCVE-2023-28706Criticalapache-airflow-providers-apache-hive: Apache Airflow Hive Provider vulnerable to code injectionCVE-2023-29374Criticallangchain: LangChain vulnerable to code injection

Stop the waste.
Protect your environment with Kodem.