PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-4527Mediumcollective.task: collective.task Cross-site Scripting vulnerabilityCVE-2022-4495Mediumcollective.dms.basecontent: collective.dms.basecontent Cross-site Scripting vulnerabilityCVE-2022-4223Highpgadmin4: pgadmin4 vulnerable to Code InjectionCVE-2022-23485Mediumsentry: Sentry vulnerable to invite code reuse via cookie manipulationCVE-2022-4314Criticalrdiffweb: Improper Privilege Management in rdiffwebCVE-2022-4396MediumpyRdfa3: pyRdfa3 Cross-site Scripting vulnerabilityCVE-2022-23491Mediumcertifi: Certifi removing TrustCor root certificateCVE-2022-46741Criticalpaddlepaddle: PaddlePaddle Out-of-bounds Read vulnerabilityCVE-2022-46742Criticalpaddlepaddle: PaddlePaddle vulnerable to Code InjectionCVE-2022-44900Criticalpy7zr: py7zr directory traversal vulnerabilityCVE-2022-23472HighPasseo: Passeo uses insecure random number generatorCVE-2022-24439CriticalGitPython: GitPython vulnerable to Remote Code Execution due to improper user input validationCVE-2022-23530Lowguarddog: GuardDog vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI packageCVE-2022-46147Highxblock-drag-and-drop-v2: XBlock vulnerable to Cross-Site Scripting (XSS) CVE-2022-23531Lowguarddog: GuardDog vulnerable to arbitrary file write when scanning a specially-crafted PyPI packageGHSA-GGRH-GRJ3-VFVWLowbitlyshortener: Package discontinued because Bitly lowered the free quotaCVE-2022-41954Lownet.sf.mpxj:mpxj: Temporary File Information Disclosure vulnerability in MPXJCVE-2022-45908Criticalpaddlepaddle: PaddlePaddle vulnerable to code injection via winstrCVE-2022-45907Criticaltorch: PyTorch vulnerable to arbitrary code executionCVE-2022-2650Criticalwger: wger vulnerable to brute force attemptsCVE-2022-38649Criticalapache-airflow: OS Command Injection in Apache AirflowCVE-2022-40189Criticalapache-airflow: OS Command Injection in Apache AirflowCVE-2022-40954Mediumapache-airflow: OS Command Injection in Apache AirflowCVE-2022-41131Highapache-airflow-providers-apache-hive: OS Command Injection in Apache AirflowCVE-2022-43685Highckan: CKAN contains Improper Authentication leading to account takeover

Stop the waste.
Protect your environment with Kodem.