PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-33146Mediumweb2py: Open redirect in web2pyCVE-2022-26477Highorg.apache.systemds:systemds: SystemDS CPU exhaustion vulnerabilityCVE-2022-22967Highsalt: Salt's PAM auth fails to reject locked accountsCVE-2022-31605Criticalnvflare: Unsafe yaml deserialization in NVFlareCVE-2022-31604Criticalnvflare: Unsafe deserialisation in the PKI implementation scheme of NVFlareCVE-2021-46823Mediumpython-ldap: Denial of Service in python-ldapCVE-2022-2112Highinventree: CSV Injection in inventreeGHSA-85Q9-7467-R53QHighinventree: XSS Vulnerability in Markdown EditorGHSA-7RQ4-QCPW-74GQMediuminventree: Formula Injection in Exported DataCVE-2022-2111Highinventree: Unrestricted Attachment UploadGHSA-RM89-9G65-4FFRHighinventree: Insufficient HTML SanitizationCVE-2022-29241Highjupyter-server: Jupyter server Token bruteforcingCVE-2022-29238Mediumnotebook: Token bruteforcing.CVE-2022-2054HighNuitka: Command Injection in NuitkaCVE-2022-32563Criticalcouchbase: Couchbase Sync Gateway admin credentials not verified when using X.509 client cert authenticationGHSA-X9JP-4W8M-4F3CHighdjango-jsonform: Cross Site Scripting vulnerability in django-jsonform's admin form.CVE-2022-24065Criticalcookiecutter: OS Command Injection in cookiecutterCVE-2022-31313Criticalapi-res-py: Backdoor in api-res-pyCVE-2022-24840Criticaldjango-s3file: Path Traversal in django-s3fileCVE-2022-29255Highvyper: Multiple evaluation of contract address in call in vyperCVE-2022-31027Mediumoauthenticator: Authorization Bypass Through User-Controlled Key when using CILogonOAuthenticator oauthenticatorCVE-2022-29773Mediumaleksis-core: Access control issue in AlekSIS-CoreCVE-2022-31799Criticalbottle: Denial of service in bottleCVE-2022-30034Highflower: Flower OAuth authentication bypassCVE-2022-31015Highwaitress: Uncaught Exception (due to a data race) leads to process termination in Waitress

Stop the waste.
Protect your environment with Kodem.