PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-28837Mediumwagtail: Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large filesCVE-2022-38072Highadmesh: ADMesh improper array index validationCVE-2023-28836Highwagtail: Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin viewsCVE-2023-26112Lowconfigobj: configobj ReDoS exploitable by developer using values in a server-side configuration fileCVE-2022-4899Highgithub.com/facebook/zstd: zstd vulnerable to buffer overrunCVE-2023-30620Highmindsdb: mindsdb arbitrary file write when extracting a remotely retrieved TarballCVE-2023-27489Highkiwitcms: Kiwi TCMS Stored Cross-site Scripting via SVG fileCVE-2022-23522Mediummindsdb: Arbitrary file write in mindsdb when Extracting Tarballs retrieved from a remote location CVE-2023-1712Criticalfarm-haystack: Use of hard-coded, security-relevant constants in deepset-ai/haystackCVE-2023-0241Mediumpgadmin4: pgAdmin 4 vulnerable to directory traversal CVE-2023-25661Mediumtensorflow: TensorFlow Denial of Service vulnerabilityCVE-2023-28859Highredis: redis-py Race Condition due to incomplete fixCVE-2023-28858Mediumredis: redis-py Race Condition vulnerabilityGHSA-CPMR-MW4J-99R7Highlabel-studio: Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/CVE-2023-1176Mediummlflow: Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIsCVE-2023-1177Criticalmlflow: mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIsCVE-2023-25659Hightensorflow: TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitchCVE-2023-25660Hightensorflow: TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`CVE-2023-25662Hightensorflow: TensorFlow vulnerable to integer overflow in EditDistanceCVE-2023-25663Hightensorflow: TensorFlow has Null Pointer Error in TensorArrayConcatV2CVE-2023-25664Hightensorflow: TensorFlow has Heap-buffer-overflow in AvgPoolGrad CVE-2023-25665Hightensorflow: TensorFlow has Null Pointer Error in SparseSparseMaximumCVE-2023-25666Hightensorflow: TensorFlow has Floating Point Exception in AudioSpectrogram CVE-2023-25667Mediumtensorflow: TensorFlow vulnerable to segfault when opening multiframe gifCVE-2023-25668Criticaltensorflow: TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation

Stop the waste.
Protect your environment with Kodem.