PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-25669Hightensorflow: TensorFlow has Floating Point Exception in AvgPoolGrad with XLACVE-2023-25670Hightensorflow: TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantizeCVE-2023-25671Hightensorflow: TensorFlow has segmentation fault in tfg-translate CVE-2023-25672Hightensorflow: TensorFlow has Null Pointer Error in LookupTableImportV2CVE-2023-25673Hightensorflow: TensorFlow has Floating Point Exception in TensorListSplit with XLA CVE-2023-25674Hightensorflow: TensorFlow has Null Pointer Error in RandomShuffle with XLA enable CVE-2023-25675Hightensorflow: TensorFlow has Segfault in Bincount with XLACVE-2023-25676Hightensorflow: TensorFlow has null dereference on ParallelConcat with XLACVE-2023-25801Hightensorflow: TensorFlow has double free in Fractional(Max/Avg)PoolCVE-2023-27579Hightensorflow: TensorFlow has Floating Point Exception in TFLite in conv kernelCVE-2023-25658Hightensorflow: TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGradCVE-2022-3101Mediumtripleo-ansible: tripleo-ansible may disclose important configuration details from an OpenStack deploymentCVE-2022-3146Mediumtripleo-ansible: tripleo-ansible may disclose important configuration details from an OpenStack deploymentCVE-2023-28117Highsentry-sdk: Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`CVE-2018-25082Criticalweixin-python: weixin-python XML External Entity vulnerabilityCVE-2023-27586HighCairoSVG: CairoSVG improperly processes SVG files loaded from external resourcesCVE-2023-27494Mediumstreamlit: Streamlit publishes previously-patched Cross-site Scripting vulnerabilityCVE-2023-25695Mediumapache-airflow: Sensitive Information in Error Messages in Apache AirflowCVE-2023-25617Highsap-ai-sdk-base: SAP Cloud SDK for AI Python has OS Command Injection when Program Objects Execution is EnabledCVE-2017-20182Mediumdjango-ajax-utilities: Cross-site Scripting in django-ajax-utilitiesCVE-2023-27476HighOWSLib: OWSLib vulnerable to XML External Entity (XXE) InjectionCVE-2023-27522HighuWSGI: Apache HTTP Server via mod_proxy_uwsgi HTTP response smugglingCVE-2022-3277Mediumneutron: openstack-neutron uncontrolled resource consumption flawCVE-2022-4134Lowglance: OpenStack Glance Inclusion of Functionality from Untrusted Control Sphere vulnerabilityCVE-2023-27891Highpretix: Insufficient Session Expiration in pretix

Stop the waste.
Protect your environment with Kodem.