PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-2514Mediumfava: Fava time and filter parameters vulnerable to reflected Cross-site ScriptingCVE-2022-34749Highmistune: Mistune vulnerable to catastrophic backtrackingCVE-2022-24294Highmxnet: Apache MXNet vulnerable to potential denial-of-service by excessive resource consumptionCVE-2018-25045Mediumdjango-rest-framework: Django REST framework XSS VulnerabilityCVE-2022-33891Highorg.apache.spark:spark-parent_2.12: Apache Spark UI can allow impersonation if ACLs enabledCVE-2021-36711CriticalOctoBot: Octobot mishandles Tentacles uploadCVE-2021-42343Criticaldistributed: Workers for local Dask clusters mistakenly listened on public interfacesCVE-2022-31153Mediumopenzeppelin-cairo-contracts: OpenZeppelin Contracts for Cairo account cannot process transactions on GoerliCVE-2022-25303Mediumwhoogle-search: Whoogle Search Cross-site Scripting via string parameterCVE-2019-10800Highcodecov: Codecov does not sanitize gcov argumentsCVE-2022-31507Criticalganga: Ganga allows absolute path traversalCVE-2022-30187MediumAzure.Storage.Queues: Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption LibraryCVE-2022-35410Highmat2: mat2 before 0.13.0 allows directory traversal during the ZIP archive cleaning process.CVE-2022-31573Criticalchainerrl-visualizer: ChainerRL Visualizer 0.1.1 vulnerable to Path Traversal via unsafe use of send_file functionCVE-2022-31558Criticalshiva: Tooxie Shiva 0.10.0 allows absolute path traversal because Flask send_file function used unsafelyCVE-2022-31506Criticalopendiamond: SatyaLab opendiamond 10.1.1 vulnerable to path traversal because Flask send_file function used unsafelyCVE-2022-35411Criticalrpc.py: rpc.py vulnerable to Deserialization of Untrusted DataCVE-2021-37839Mediumapache-superset: Apache Superset allows authenticated users to access metadata they have no permission toCVE-2022-31124Mediumopenssh-key-parser: Possible leak of key's raw field if declared length is incorrectCVE-2022-2309Mediumlxml: lxml NULL Pointer Dereference allows attackers to cause a denial of serviceGHSA-C58J-88F5-H53FMediumpycares: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in pycaresCVE-2022-31116Highujson: Incorrect handling of invalid surrogate pair charactersCVE-2022-31117Mediumujson: Potential double free of buffer during string decodingCVE-2022-34265CriticalDjango: Django `Trunc()` and `Extract()` database functions vulnerable to SQL InjectionCVE-2022-31052Highmatrix-synapse: URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monoliths

Stop the waste.
Protect your environment with Kodem.