PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-19702Highmodoboa-dmarc: Modoboa is vulnerable to an XML External Entity Injection (XXE)CVE-2019-19687Highkeystone: OpenStack Keystone Credential LeakageCVE-2019-10195Mediumfreeipa: FreeIPA logs passwords embedded in commands in calls using batchCVE-2019-14856Highansible: Ansible password prompts could expose passwordsCVE-2019-10206Highansible: Ansible password prompts could expose passwordsCVE-2015-5694Mediumdesignate: Designate does not enforce the DNS protocol limit concerning record set sizesCVE-2019-12408Highred-arrow: Missing Initialization of Resource in Apache ArrowCVE-2019-12410Highred-arrow: Missing Initialization of Resource in Apache ArrowCVE-2019-14858Mediumansible: Ansible leaks sensitive information to logs when told not toCVE-2019-17109Highkoji: koji hub allows arbitrary upload destinationsCVE-2019-17134Criticaloctavia: OpenStack Octavia Amphora-Agent not requiring Client-CertificateCVE-2019-14846Highansible: Ansible Uses Plugins That Disclose CredentialsCVE-2019-13628Mediumwolfcrypt: wolfCrypt leaks cryptographic information via timing side channelCVE-2018-21019Highhomeassistant: Home Assistant information disclosure vulnerabilityCVE-2019-16228Highlmdb: py-lmdb Divide by Zero interruptionsCVE-2019-16226Highlmdb: LMDB invalid write CVE-2019-16225Criticallmdb: py-lmdb Invalid write operationCVE-2019-16224Criticallmdb: py-lmdb Invalid write operationCVE-2019-15753Criticalos-vif: OpenStack os-vif Ageing time of 0 disables linuxbridge MAC learningCVE-2019-7617Mediumelastic-apm: Elastic APM agent for Python client CGI proxy redirection flawCVE-2019-14433Highnova: OpenStack Nova Server Resource Faults Leak External Exception DetailsCVE-2019-10141Highironic-inspector: Openstack ironic-inspector has SQL injection vulnerability in node_cacheCVE-2019-14322Highwerkzeug: Pallets Werkzeug vulnerable to Path TraversalCVE-2019-1010259Criticalsalt: SaltStack Salt SQL Injection vulnerability in mysql.user_chpass functionCVE-2019-13594Highsaleor: Mirumee Saleor CSRF Protection Disabled

Stop the waste.
Protect your environment with Kodem.