PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-22432Mediumweb2py: Open redirect in web2pyCVE-2023-26051MediumSaleor: Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python ExceptionsCVE-2023-26052Lowsaleor: Saleor Unauthenticated Information Disclosure Vulnerability via Python ExceptionsCVE-2023-30797Highlemur: Lemur subject to insecure random generationCVE-2023-23929Highvantage6: vantage6 refresh tokens do not expireCVE-2023-22738Highvantage6: vantage6 vulnerable to Improper Preservation of PermissionsCVE-2022-39228Mediumvantage6: vantage6 vulnerable to Observable Response DiscrepancyCVE-2023-25691Criticalapache-airflow-providers-google: Apache Airflow Google Provider Improper Input Validation vulnerabilityCVE-2023-25696Criticalapache-airflow-providers-apache-hive: Apache Airflow Hive Provider Improper Input Validation vulnerabilityCVE-2023-25693Criticalapache-airflow-providers-apache-sqoop: Apache Airflow Sqoop Provider Improper Input Validation vulnerabilityCVE-2023-25692Highapache-airflow-providers-google: Apache Airflow Google Provider Improper Input Validation vulnerabilityCVE-2023-25956Highapache-airflow-providers-amazon: Apache Airflow AWS Provider Generates Error Message Containing Sensitive InformationCVE-2023-25823Mediumgradio: Update share links to use FRP instead of SSH tunnelingCVE-2023-26302Highmarkdown-it-py: markdown-it-py Denial of Service vulnerability in the command line interfaceCVE-2023-26303Highmarkdown-it-py: markdown-it-py Denial of Service vulnerabilityCVE-2023-0949Mediummodoboa: modoboa Cross-site Scripting vulnerabilityCVE-2023-25657Highnautobot: Nautobot vulnerable to remote code execution via Jinja2 template renderingCVE-2023-24769Mediumchangedetection.io: Stored cross site scripting in changedetection.ioCVE-2021-33926HighPlone: Server-Side Request Forgery in Plone CMSCVE-2023-0860Highmodoboa: Improper Restriction of Excessive Authentication Attempts in modoboaCVE-2023-25156Highkiwitcms: No protection against brute-force attacks on login pageCVE-2023-25171Highkiwitcms: Denial of service vulnerability on Password reset pageCVE-2023-25578Highstarlite: Denial of service vulnerability when parsing multipart request bodyCVE-2023-23934LowWerkzeug: Incorrect parsing of nameless cookies leads to __Host- cookies bypassCVE-2023-25577HighWerkzeug: High resource usage when parsing multipart form data with many fields

Stop the waste.
Protect your environment with Kodem.