PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-36004Mediumtensorflow: TensorFlow vulnerable to `CHECK` fail in `tf.random.gamma`CVE-2022-36016Lowtensorflow: TensorFlow vulnerable to `CHECK`-fail in `tensorflow::full_type::SubstituteFromAttrs`CVE-2022-36014Mediumtensorflow: TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`CVE-2022-36015Lowtensorflow: TensorFlow vulnerable to integer overflow in math opsCVE-2022-36012Mediumtensorflow: TensorFlow vulnerable to assertion fail on MLIR empty edge namesCVE-2022-35987Mediumtensorflow: TensorFlow vulnerable to `CHECK` fail in `DenseBincount`CVE-2022-35941Mediumtensorflow: TensorFlow vulnerable to `CHECK` failure in `AvgPoolOp`CVE-2022-36026Mediumtensorflow: TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`CVE-2022-36018Mediumtensorflow: TensorFlow vulnerable to `CHECK` fail in `RaggedTensorToVariant`CVE-2022-36019Mediumtensorflow: TensorFlow vulnerable to `CHECK` fail in `FakeQuantWithMinMaxVarsPerChannel`CVE-2022-36027Mediumtensorflow: TensorFlow segfault TFLite converter on per-channel quantized transposed convolutionsCVE-2022-35939Hightensorflow: TensorFlow vulnerable to OOB write in `scatter_nd` in TF LiteCVE-2022-35937Hightensorflow: TensorFlow vulnerable to OOB read in `Gather_nd` in TF LiteCVE-2022-36087Mediumoauthlib: OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URICVE-2022-35934Mediumtensorflow: TensorFlow vulnerable to `CHECK` failure in tf.reshape via overflowsCVE-2022-35935Mediumtensorflow: TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validationCVE-2022-31006Highindy-node: Hyperledger indy-node vulnerable to denial of serviceCVE-2022-36069Highpoetry: Poetry Argument Injection can lead to Local Code ExecutionCVE-2022-35997Mediumtensorflow: TensorFlow vulnerable to `CHECK` fail in `tf.sparse.cross`CVE-2022-35999Mediumtensorflow: TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`CVE-2022-36082Mediummangadex-downloader: mangadex-downloader vulnerable to unauthorized file readingCVE-2022-40023Highmako: mako is vulnerable to Regular Expression Denial of ServiceCVE-2022-36436Criticalvncauthproxy: VNCAuthProxy authentication bypass vulnerabilityCVE-2022-3221Highrdiffweb: rdiffweb CSRF vulnerability in profile's SSH keys can lead to unauthorized accessGHSA-R7VQ-6425-J94WLowtuf: Python-TUF vulnerable to incorrect threshold signature computation for new root metadata

Stop the waste.
Protect your environment with Kodem.