PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-0435Criticalpyload-ng: Excessive Attack Surface in pyload-ngCVE-2023-0434Mediumpyload-ng: Improper Input Validation in pyload-ngCVE-2023-22884Criticalapache-airflow: Command Injection in Apache Airflow and Apache Airflow MySQL ProviderCVE-2023-0406Mediummodoboa: Cross-Site Request Forgery in modoboaCVE-2023-0398Mediummodoboa: Modoboa is vulnerable to Cross-Site Request ForgeryCVE-2022-47950Mediumswift: OpenStack Swift XML external entities (XXE) InjectionCVE-2021-32837Highmechanize: mechanize Regular Expression Denial of Service vulnerabilityCVE-2023-22298Mediumpgadmin4: pgAdmin 4 Open Redirect vulnerabilityCVE-2022-43718Mediumapache-superset: Apache Superset is vulnerable to Cross-Site Scripting (XSS) CVE-2022-43719Highapache-superset: Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpointsCVE-2022-43717Mediumapache-superset: Apache Superset vulnerable to Cross-site ScriptingCVE-2022-41703Mediumapache-superset: Apache Superset's SQL Alchemy connector vulnerable to SQL InjectionCVE-2022-43721Mediumapache-superset: Apache Superset Open Redirect vulnerabilityCVE-2022-43720Mediumapache-superset: Apache Superset vulnerable to InjectionCVE-2022-45438Mediumapache-superset: Apache Superset has Improper Access ControlCVE-2023-0297Criticalpyload-ng: Code Injection in pyload-ngCVE-2023-0227Mediumpyload-ng: Pyload Insufficient Session Expiration vulnerabilityGHSA-H6P3-P4VX-WR8QMediumdompurify: dompurify vulnerable to Cross-site ScriptingGHSA-PGJV-JRG2-GQ3VMediumdompurify: dompurify vulnerable to Cross-site ScriptingCVE-2022-4885Highjefferson: sviehb/jefferson vulnerable to path traversalCVE-2019-25095Mediumldapcherry: LdapCherry Cross-site Scripting vulnerbailityCVE-2016-15010Mediumdjango-ucamlookup: django-ucamlookup Cross-site Scripting vulnerabilityCVE-2023-0057Mediumpyload-ng: pyLoad vulnerable to Improper Restriction of Rendered UI Layers or FramesCVE-2023-0055Mediumpyload-ng: Pyload contains Sensitive Cookie in HTTPS Session Without 'Secure' AttributeCVE-2019-25091Mediumnsupdate: nsupdate.info has Sensitive Cookie Without 'HttpOnly' Flag

Stop the waste.
Protect your environment with Kodem.