PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2012-3371LowNova: OpenStack Nova Scheduler denial of service through scheduler_hintsCVE-2012-2146HighElixir: Elixir can leak information due to weak use of cryptoCVE-2012-2374Hightornado: Tornado CRLF injection vulnerabilityCVE-2012-3426MediumKeystone: OpenStack Keystone token expiration issuesCVE-2012-3542Highkeystone: OpenStack Keystone Allows Remote User Account CreationCVE-2012-3458Mediumbeaker: Beaker Sensitive Information Disclosure vulnerabilityCVE-2012-3446Mediumapache-libcloud: Apache Libcloud vulnerable to certificate impersonationCVE-2012-4571Highkeyring: Python Keyring does not securely initialize encryption cipherCVE-2012-6080Mediummoin: MoinMoin Directory Traversal vulnerabilityCVE-2012-6495MediumMoin: MoinMoin Multiple vulnerable to directory traversalCVE-2012-6082Mediummoin: MoinMoin Cross-site scripting (XSS) vulnerabilityCVE-2012-5625Mediumnova: OpenStack Nova Information leak in libvirt LVM-backed instancesCVE-2012-0878Highpastescript: Paste Script has improper group memberships permissionsCVE-2012-3442Criticaldjango: Django Allows Redirect via Data URLCVE-2012-3443Highdjango: Django Image Field Vulnerable to Image Decompression BombsCVE-2012-3444HighDjango: Django vulnerable to Improper Restriction of Operations within the Bounds of a Memory BufferCVE-2012-4404Mediummoin: MoinMoin Improper Access ControlCVE-2012-4520Highdjango: Django Allows Arbitrary URL GenerationCVE-2013-1664MediumDjango: XML Entity Expansion (XEE) in DjangoCVE-2013-1665MediumDjango: XML External Entity (XXE) in DjangoCVE-2013-4278Lownova: OpenStack Compute (Nova) Resource limit circumvention in Nova private flavorsCVE-2013-1630Highpyshop: pyshop vulnerable to man-in-the-middle attacks due to using HTTP to retrieve packages from the PyPI repositoryCVE-2013-5942Criticalgraphite-web: graphite-web is vulnerable to Remote Code ExecutionCVE-2013-5093Criticalgraphite-web: graphite-web is vulnerable to Remote Code Execution via renderLocalView function CVE-2013-1633Highsetuptools: Setuptools vulnerable to Man-in-the-middle attacks

Stop the waste.
Protect your environment with Kodem.