PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-41885Mediumtensorflow: Overflow in `FusedResizeAndPadConv2D`CVE-2022-41884Mediumtensorflow: Seg fault in `ndarray_tensor_bridge` due to zero and large inputsCVE-2022-41883Mediumtensorflow: Out of bounds segmentation fault due to unequal op inputs in TensorflowCVE-2022-43171Highlief: LIEF heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bindCVE-2022-4018Lowrdiffweb: Rdiffweb vulnerable to Missing Authentication for Critical FunctionCVE-2022-41905Highwsgidav: Cross Site Scripting vulnerability in wsgidav when directory browsing is enabledCVE-2022-3362Highrdiffweb: rdiffweb vulnerable to Insufficient Session ExpirationCVE-2022-45402Mediumapache-airflow: Apache Airflow Contains Open RedirectCVE-2022-45198Highpillow: Pillow vulnerable to Data Amplification attack.CVE-2022-45199Highpillow: Pillow subject to DoS via SAMPLESPERPIXEL tagCVE-2022-40127Highapache-airflow: Apache Airflow vulnerable to OS Command Injection via example DAGsCVE-2022-27949Highapache-airflow: Apache Airflow subject to Exposure of Sensitive InformationCVE-2022-41892Higharches: Arches vulnerable to execution of arbitrary SQLCVE-2022-42965Mediumsnowflake-connector-python: snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)CVE-2022-42966Mediumcleo: cleo is vulnerable to Regular Expression Denial of Service (ReDoS)CVE-2022-42964Mediumpymatgen: pymatgen is vulnerable to Regular Expression Denial of Service (ReDoS)CVE-2022-44244MediumLin-CMS: Lin CMS vulnerable to Improper AuthenticationCVE-2022-33684Highpulsar-client: Apache Pulsar Disabled Certificate Validation for OAuth Client Credential Requests makes C++/Python Clients vulnerable to MITM attackCVE-2021-39432Mediumdiplib: diplib Double FreeCVE-2022-43982Mediumapache-airflow: Apache Airflow Cross-site Scripting vulnerabilityCVE-2022-43985Mediumapache-airflow: Apache Airflow Open Redirect vulnerabilityGHSA-39HC-V87J-747XMediumcryptography: Vulnerable OpenSSL included in cryptography wheelsCVE-2022-31777Mediumpyspark: Apache Spark vulnerable to Log InjectionCVE-2022-39366Criticalacryl-datahub: acryl-datahub missing JWT signature checkCVE-2022-44020Mediumsushy-tools: OpenStack Sushy-Tools and VirtualBMC Improper Preservation of Permissions

Stop the waste.
Protect your environment with Kodem.