PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-3174Highrdiffweb: rdiffweb vulnerable to Sensitive Cookie in HTTPS Session Without 'Secure' AttributeCVE-2022-3175Mediumrdiffweb: rdiffweb Missing Custom Error PageCVE-2022-3179Highrdiffweb: rdiffweb contains Weak Password RequirementsCVE-2022-38306Mediumlief: LIEF vulnerable to heap based buffer overflowCVE-2022-38497Mediumlief: LIEF contains a segmentation violationCVE-2022-38307Mediumlief: LIEF contains segmentation violationCVE-2022-38495Highlief: LIEF vulnerable to heap based buffer overflow via print_binary functionCVE-2022-3167Criticalrdiffweb: rdiffweb vulnerable to Improper Restriction of Rendered UI Layers or FramesCVE-2022-37189Highmei2volpiano: MEI2Volpiano is vulnerable to XML External Entity (XXE), leading to a Denial of Service (DoS)CVE-2022-23451Highbarbican: Barbican authorization flaw before v14.0.0CVE-2022-38369Mediumorg.apache.iotdb:iotdb-server: Apache IoTDB Session Fixation vulnerabilityCVE-2022-38170Mediumapache-airflow: Apache Airflow exposes arbitrary file contentCVE-2022-38054Criticalapache-airflow: Apache Airflow Session Fixation vulnerabilityCVE-2022-31020Highindy-node: Indy's NODE_UPGRADE transaction vulnerable to remote code executionCVE-2022-2996Criticalpython-scciclient: python-scciclient vulnerable to Man-in-the-middle (MITM) attacksCVE-2022-23452Mediumbarbican: openstack-barbican Denial of Service vulnerabilityCVE-2022-2806Mediumsosreport: sosreport Exposure of Sensitive Information vulnerabilityCVE-2022-34668Criticalnvflare: NVFLARE unsafe deserialization due to PickleCVE-2022-31152Highmatrix-synapse: Denial of service due to incorrect application of event authorization rulesCVE-2022-0718Mediumoslo-utils: python-oslo-utils has improper password parsingCVE-2022-38792Criticalexotel: exotel-py includes code execution backdoor inserted by a third partyCVE-2021-3427Mediumdeluge: Deluge Web-UI vulnerable to XSS through a crafted torrent fileCVE-2021-3563Criticalkeystone: Openstack Keystone Incorrect Authorization vulnerabilityCVE-2021-42521Highvtk: VTK NULL pointer dereference vulnerabilityCVE-2022-2255Highmod-wsgi: Incorrect header handling in mod-wsgi

Stop the waste.
Protect your environment with Kodem.