PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2013-1445Highpycrypto: PyCrypto does not properly reseed PRNG before allowing accessCVE-2013-4155Mediumswift: OpenStack Swift allows authenticated users to cause a denial of serviceCVE-2013-4183Mediumcinder: OpenStack Cinder LVMVolumeDriver does not zero deleted snapshotsCVE-2013-4179Mediumnova: OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attackCVE-2013-4294Mediumkeystone: OpenStack Identity (Keystone) allows remote attackers to bypass intended access restrictions via revoked PKI tokenCVE-2013-6617Highsalt: SaltStack Privilege Escalation vulnerabilityCVE-2013-4439Highsalt: Minion identity not validated in saltstackCVE-2013-4497Mediumnova: OpenStack Compute Nova Improper Access ControlCVE-2013-4436Highsalt: SaltStack MITM SSH attack in salt-sshCVE-2013-4437Highsalt: SaltStack insecurely uses /tmpCVE-2013-4435Highsalt: Salt has insufficient argument validation in several modulesCVE-2013-4510Hightrytond: Tryton Directory Traversal vulnerabilityCVE-2013-1865Mediumkeystone: OpenStack Keystone Improper Authentication vulnerabilityCVE-2013-4315Highdjango: Django Directory Traversal via ssi template tagCVE-2013-4314HighpyOpenSSL: PyOpenSSL Mishandles NUL Byte In Certificate Subject Alternative NameCVE-2012-6081Mediummoin: MoinMoin Multiple unrestricted file upload vulnerabilitiesCVE-2013-2096Mediumnova: OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 imageCVE-2013-2104Highpython-keystoneclient: python-keystoneclient missing expiration check in PKI token validation CVE-2013-1443HighDjango: Django Denial of Service Vulnerability in the authentication framework CVE-2013-6396Criticalpython-swiftclient: Python Swift client is vulnerable to Missing SSL Certificate CheckCVE-2013-4477Lowkeystone: OpenStack Identity Keystone Privilege Escalation vulnerabilityCVE-2014-1948Mediumglance: OpenStack Glance sensitive information disclosure via logsCVE-2013-6419Mediumnova: OpenStack Nova Router metadata queries are not restricted by tenantCVE-2014-0006Highswift: OpenStack Swift Discloses Secret URLs to Timing AttackCVE-2013-4188Mediumplone: Plone Authenticated Denial of Service vulnerability

Stop the waste.
Protect your environment with Kodem.