PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2013-4189MediumPlone: Plone Privilege escalation due improper authorizationCVE-2013-4191Mediumplone: Plone is vulnerable to Information Exposure when generating zip archivesCVE-2013-4192Highplone: Plone is vulnerable to email spoofingCVE-2013-4196Mediumplone: Plone is vulnerable to information exposure via the object manager implementation CVE-2013-4199Lowplone: Plone Denial of Service vulnerability via decompressing large zip archivesCVE-2013-4194Mediumplone: Plone is vulnerable to File System Path ExposureCVE-2013-4190Mediumplone: Plone vulnerable to cross-site scriptingCVE-2013-4198MediumPlone: Plone's authenticated users able to alter their password despite of policy definitionCVE-2013-4195Lowplone: Plone Multiple open redirect vulnerabilitiesCVE-2013-4197Highplone: Plone Improper Access Control VulnerabilityCVE-2013-4193Highplone: Plone Unrestricted Filed Manipulation vulnerability via content edit formsCVE-2014-2573Highnova: OpenStack Nova VMWare driver leaks rescued imagesCVE-2013-2209Mediumreviewboard: Review Board Cross-site scripting (XSS) vulnerability in the reviews dropdownCVE-2014-3007Criticalpillow: Pillow command injectionCVE-2014-2260Mediumajenti: Ajenti Cross-site scripting (XSS) vulnerabilityCVE-2013-7110Hightransifex-client: Transifex command-line client has improper certificate validationCVE-2013-2030Mediumpython-keystoneclient: OpenStack Nova uses insecure keystone middleware tmpdir by defaultCVE-2013-2006Lowkeystone: OpenStack Keystone Sensitive information disclosure via log filesCVE-2014-3243MediumSOAPpy: SOAPpy vulnerable to XXE attacksCVE-2014-3242MediumSOAPpy: SOAPpy vulnerable to XML External Entity attacksCVE-2014-0162Mediumglance: OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerabilityCVE-2014-0056Mediumneutron: OpenStack Neutron Improper Authentication vulnerabilityCVE-2014-3995Mediumdjblets: Djblets Cross-site scripting VulnerabilityCVE-2014-3840Mediummayan-edms: Mayan EDMS multiple cross-site scripting (XSS) vulnerabilitiesCVE-2013-4463Lownova: OpenStack Nova denial of service through compressed disk images

Stop the waste.
Protect your environment with Kodem.