PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-24580HighDjango: Resource exhaustion in DjangoCVE-2023-30798Highstarlette: MultipartParser denial of service with too many fields or filesGHSA-344M-QCJQ-XGRFHighsgx-dcap-quote-verify-python: Vulnerable OpenSSL included in sgx-dcap-quote-verify-pythonCVE-2023-0777Criticalmodoboa: Authentication Bypass in modoboaCVE-2023-24816Lowipython: IPython vulnerable to command injection via set_term_titleCVE-2023-0286Highcryptography: Vulnerable OpenSSL included in cryptography wheelsCVE-2022-47419Mediummayan-edms: Mayan EDMS DMS XSS vulnerabilityCVE-2023-23931Mediumcryptography: Cipher.update_into can corrupt memory if passed an immutable python object as the outbufCVE-2020-36660MediumEVE-SRP: Exposure of Sensitive Information in EVE-SRPCVE-2022-45786Highgithub.com/apache/age/drivers/golang: Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injectionCVE-2019-25101CriticalTurboGears: Header injection in TurboGearsCVE-2023-23940Mediumopenzeppelin-cairo-contracts: OpenZeppelin Contracts contains Improper Verification of Cryptographic SignatureCVE-2023-23969Highdjango: Django contains Uncontrolled Resource Consumption via cached headerCVE-2023-0591Mediumubi-reader: Path traversal in ubi-readerCVE-2021-4315HighpsiTurk: NYUCCL psiTurk IS vulnerable to Improper Neutralization of Special ElementsCVE-2023-24622Mediumsafeurl-python: safeurl-python contains Server-Side Request ForgeryCVE-2022-47951Mediumcinder: OpenStack Cinder, glance, and Nova vulnerable to Path TraversalCVE-2023-0509Highpyload-ng: Improper Certificate Validation in pyload-ngCVE-2023-0488Mediumpyload-ng: Cross-site Scripting in pyload-ngCVE-2023-0470Mediummodoboa: Cross-site Scripting in modoboaCVE-2023-0519Mediummodoboa: Cross-site Scripting in modoboaCVE-2022-25882Highonnx: Directory Traversal in onnxCVE-2022-4510Highbinwalk: Path traversal in binwalkCVE-2023-23608Mediumspotipy: Path traversal in spotipyCVE-2023-0438Mediummodoboa: Cross-Site Request Forgery in modoboa

Stop the waste.
Protect your environment with Kodem.