PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-29198Mediumtensorflow: Missing validation causes denial of service via `SparseTensorToCSRSparseMatrix`CVE-2022-29197Mediumtensorflow: Missing validation causes denial of service via `UnsortedSegmentJoin`CVE-2022-29196Mediumtensorflow: Missing validation causes denial of service via `Conv3DBackpropFilterV2`CVE-2022-29195Mediumtensorflow: Missing validation causes denial of service via `StagePeek`CVE-2022-29194Mediumtensorflow: Missing validation causes denial of service via `DeleteSessionTensor`CVE-2022-29192Mediumtensorflow: Missing validation crashes `QuantizeAndDequantizeV4Grad`CVE-2022-29191Mediumtensorflow: Missing validation causes denial of service via `GetSessionTensor`CVE-2021-29002Mediumplone: Plone XSS VulnerabilityCVE-2014-4678Criticalansible: Ansible Code Injection VulnerabilityCVE-2019-18835Highmatrix-synapse: Improper Verification of Cryptographic Signature in matrix-synapseCVE-2013-5123Highpip: Improper Authentication in pipCVE-2019-6446Criticalnumpy: Numpy Deserialization of Untrusted DataCVE-2019-17626Criticalreportlab: XML Injection in ReportLabCVE-2019-16227Criticallmdb: py-lmdb Invalid write operationCVE-2021-44144Highasterix_decoder: Asterix Heap-based Buffer OverflowCVE-2021-42250Highapache-superset: Improper Encoding or Escaping of Output in Apache SupersetCVE-2021-41972Highapache-superset: Apache Superset allowed for database connections password leak for authenticated usersCVE-2021-32609Mediumapache-superset: Apache Superset Cross-site Scripting (XSS) vulnerability on the Explore pageCVE-2021-41971Highapache-superset: Apache Superset SQL Injection when template processing is enabledCVE-2021-40720Criticalops-cli: Ops CLI Deserialization of Untrusted Data vulnerabilityCVE-2021-31605Highopenvpn-monitor: furlongm openvpn-monitor command injectionCVE-2021-31604Mediumopenvpn-monitor: furlongm openvpn-monitor allows CSRF to disconnect an arbitrary clientCVE-2021-31606Highopenvpn-monitor: furlongm openvpn-monitor allows Authorization Bypass to disconnect arbitrary clientsCVE-2021-32297Highlief: LIEF heap-buffer-overflowCVE-2021-40347Mediumpostorius: GNU Mailman Postorius Access Control Issues

Stop the waste.
Protect your environment with Kodem.