PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-38540Criticalapache-airflow: Missing Authentication for Critical Function in Apache AirflowCVE-2021-22004Highsalt: Improper Authentication in SaltStack SaltCVE-2021-40797Highneutron: OpenStack Neutron Denial of Service vulnerabilityCVE-2021-40494Criticallxdui: AdaptiveScale LXDUI Hardcoded JWT Secret KeyCVE-2021-40085Highneutron: OpenStack Neutron vulnerable to authenticated attackers reconfiguring dnsmasq via crafted extra_dhcp_opts valueCVE-2020-19002MediumMezzanine: Mezzanine Cross Site Scripting (XSS) vulnerabilityCVE-2021-38598Highneutron: OpenStack Neutron vulnerable to hardware address impersonationCVE-2020-18699Mediumlin-cms: Lin-CMS-Flask Cross Site Scripting (XSS) vulnerabilityCVE-2020-18698CriticalLin-CMS: Lin-CMS-Flask vulnerable to Improper AuthenticationCVE-2021-38155Highkeystone: OpenStack Keystone allows information disclosure during account lockingCVE-2021-35959Mediumplone: Plone has stored XSS in folder contentsCVE-2021-20267Highneutron: Openstack Neutron has Insufficient Verification of IPv6 addressesCVE-2021-3313Mediumplone: Plone XSS in User Fullname Property and File UploadCVE-2021-32561MediumOctoPrint: OctoPrint API Error Messages vulnerable to XSSCVE-2021-32560Highoctoprint: OctoPrint Incorrect Access ControlCVE-2021-31607Highsalt: Command Injection in SaltStack SaltCVE-2021-25315Highsalt: Saltstack Salt Unauthenticated Arbitrary Code ExecutionCVE-2021-3144Criticalsalt: SaltStack Salt eauth tokens can be used once after expirationCVE-2021-3197Criticalsalt: SaltStack Salt is vulnerable to shell injection via ProxyCommand argumentCVE-2021-3148Criticalsalt: SaltStack Salt command injection in the Salt-API when using the Salt-SSH clientCVE-2021-25284Mediumsalt: SaltStack Salt Cleartext Storage of Sensitive Information via cmdmod CVE-2021-25282Highsalt: SaltStack Salt Directory Traversal vulnerabilityCVE-2021-25283Criticalsalt: SaltStack Salt Server Side Template InjectionCVE-2021-25281Criticalsalt: SaltStack Salt Improper Authentication vulnerabilityCVE-2020-28243Highsalt: SaltStack Salt command injection via a crafted process name

Stop the waste.
Protect your environment with Kodem.