PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-3389Highrdiffweb: rdiffweb Path Traversal vulnerabilityCVE-2022-3376Mediumrdiffweb: rdiffweb allows a new password to be the same as the previous passwordCVE-2022-40922Highlief: LIEF vulnerable to denial of service through segmentation faultCVE-2022-36551Highlabel-studio: Heartex - Label Studio Community Edition vulnerable to SSRF in the Data Import moduleCVE-2022-3371Highrdiffweb: rdiffweb's lack of token name length limit can result in DoS or memory corruptionCVE-2022-40923Mediumlief: LIEF vulnerable to denial of service through segmentation faultCVE-2022-39254Highmatrix-nio: When matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarderCVE-2022-3326Mediumrdiffweb: rdiffweb vulnerable to password complexity bypass leading to weak passwordsCVE-2022-3355Mediuminventree: Inventree vulnerable to Stored Cross-site ScriptingCVE-2022-3364Mediumrdiffweb: rdiffweb's unlimited length Fullname field can lead to DoSCVE-2022-3292Mediumrdiffweb: rdiffweb vulnerable to Use of Cache Containing Sensitive InformationCVE-2022-39280Highdparse: ReDoS issue in dparseCVE-2022-3301Mediumrdiffweb: rdiffweb vulnerable to Improper Cleanup on Thrown ExceptionCVE-2022-21797Criticaljoblib: joblib vulnerable to arbitrary code executionCVE-2022-3295Highrdiffweb: rdiffweb allows unlimited length of root directory name, which could result in DoSCVE-2022-3290Highrdiffweb: rdiffweb's unlimited username field length can lead to DoSCVE-2022-3272Highrdiffweb: rdiffweb's unlimited length email field can lead to DoSCVE-2022-3298Highrdiffweb: rdiffweb vulnerable to potential DoS via memory consumptionCVE-2022-3269Criticalrdiffweb: rdiffweb vulnerable to account access via session fixationCVE-2022-1941Highprotobuf: protobuf-cpp and protobuf-python have potential Denial of Service issueCVE-2022-3274Highrdiffweb: rdiffweb Cross-Site Request Forgery vulnerability can lead to user email ID being changedCVE-2022-3267Mediumrdiffweb: rdiffweb Cross-Site Request Forgery vulnerabilityCVE-2022-40604Highapache-airflow: Apache Airflow vulnerable to Use of Externally-Controlled Format StringCVE-2022-40754Mediumapache-airflow: Apache Airflow contains open redirectCVE-2022-2872LowOctoPrint: OctoPrint vulnerable to Unrestricted Upload of File with Dangerous Type

Stop the waste.
Protect your environment with Kodem.