PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-4728Mediumgraphite-web: Graphite Web Cross-site Scripting vulnerabilityCVE-2022-4721Mediumrdiffweb: rdiffweb vulnerable to Special Element InjectionCVE-2022-4723Highrdiffweb: rdiffweb has no rate limit on resend email featureCVE-2022-4719Mediumrdiffweb: rdiffweb vulnerable to Business Logic ErrorsCVE-2022-4722Highrdiffweb: rdiffweb vulnerable to Authentication Bypass by Primary WeaknessCVE-2022-4724Criticalrdiffweb: rdiffweb Improper Access Control vulnerabilityCVE-2022-4720Highrdiffweb: rdiffweb vulnerable to Open RedirectCVE-2022-4729Mediumgraphite-web: Graphite Web Cross-site Scripting vulnerabilityCVE-2022-4730Mediumgraphite-web: Graphite Web Cross-site Scripting vulnerabilityGHSA-G86J-HWG9-77Q5HighSentinelOne: SentinelOne impersonated via PyPI packagesCVE-2021-4286Highsrp: cocagne pysrp vulnerable to side channel leaksCVE-2021-4287Mediumbinwalk: binwalk vulnerable to UNIX Symbolic Link (Symlink) FollowingCVE-2022-45197Highslixmpp: Slixmpp lacks SSL Certificate hostname validation in XMLStreamCVE-2022-40897Highsetuptools: pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)CVE-2022-40898Highwheel: pypa/wheel vulnerable to Regular Expression denial of service (ReDoS)CVE-2022-40899Highfuture: Python Charmers Future denial of service vulnerabilityCVE-2022-4644Mediumrdiffweb: rdiffweb Open Redirect vulnerabilityCVE-2022-4646Highrdiffweb: rdiffweb vulnerable to Cross-Site Request ForgeryCVE-2022-4638Mediumcollective.contact.widget: collective.contact.widget is vulnerable to cross-site scripting CVE-2022-38060Highkolla: OpenStack Kolla sudo privilege escalation vulnerabilityCVE-2022-46421Criticalapache-airflow-providers-apache-hive: Apache Airflow Hive Provider vulnerable to Command InjectionCVE-2022-44940Highpatchelf: Patchelf out-of-bounds readCVE-2022-4589Mediumdjango-termsandconditions: Terms and Conditions Module vulnerable to Open RedirectCVE-2022-4572Mediumubi-reader: UBI Reader vulnerable to Path TraversalCVE-2022-4526Mediumdjango-photologue: django-photologue vulnerable to Cross-site Scripting

Stop the waste.
Protect your environment with Kodem.