PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-28972Highsalt: SaltStack Salt Improper Certificate ValidationCVE-2020-35662Highsalt: SaltStack Salt Improper SSL Certificate ValidationCVE-2020-36245HighGramAddict: GramAddict bot uses dependency with reverse tcp backdoorCVE-2020-25340Mediumnfstream: NFStream Local Denial of Service (DoS)CVE-2021-23338Mediumpyqlib: qlib Deserialization of Untrusted Data vulnerabilityCVE-2021-3028Criticalgit-big-picture: git-big-picture Code ExecutionCVE-2020-36191Mediumjupyterhub: Cross-Site Request Forgery in JupyterHubCVE-2020-35459Highcrmsh: ClusterLabs crmsh vulnerable to shell code injectionCVE-2020-22083Criticaljsonpickle: jsonpickle unsafe deserializationCVE-2020-29565Mediumhorizon: OpenStack Horizon Open redirect in workflow formsCVE-2020-27348Mediumsnapcraft: snapcraft Access Restriction BypassCVE-2020-25449Mediumcabot: Cabot Cross Site Scripting (XSS) vulnerability via Address columnCVE-2020-29367Highblosc2: blosc2 heap-based buffer overflowCVE-2020-28975Highscikit-learn: scikit-learn Denial of ServiceCVE-2020-28364Mediumlocust: Locust Stored Cross-site Scripting VulnerabilityCVE-2020-16846Criticalsalt: SaltStack Salt Command Injection in netapi ssh clientCVE-2020-25592Criticalsalt: SaltStack Salt Improper Validation of eauth credentials and tokens in salt-netapiCVE-2020-17490Mediumsalt: SaltStack Salt Allows creating certificates with weak file permissionsCVE-2020-15703Mediumaptdaemon: aptdaemon Information Disclosure via Improper Input Validation in Transaction classCVE-2020-7734Lowcabot: Cabot Cross Site Scripting (XSS) vulnerability via Endpoint columnCVE-2020-8927Mediumcompu-brotli-sys: Integer overflow in the bundled Brotli C libraryCVE-2020-24715Criticalscalyr-agent-2: Scalyr Agent 2 Missing SSL Certificate ValidationCVE-2020-24714Criticalscalyr-agent-2: Scalyr Agent Missing SSL Certificate ValidationCVE-2020-17376Highnova: OpenStack Nova Live migration fails to update persistent domain XMLCVE-2020-15904Highbsdiff4: bsdiff4 out-of-bounds write via patch file

Stop the waste.
Protect your environment with Kodem.