PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2011-4953Mediumcobbler: Cobbler vulnerable to code injection via unsafe YAML loadingCVE-2012-5500Mediumplone: Plone contains Cross-site Request ForgeryCVE-2012-5508MediumPlone: Exposure of Sensitive Information in PloneCVE-2014-3641Mediumcinder: OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityCVE-2014-3137Highbottle: Bottle does not properly limit content-typesCVE-2015-0838Criticaldulwich: Dulwich Buffer Overflow when handling pack filesCVE-2014-9706Criticaldulwich: Dulwich Arbitrary code execution via commit with directory path starting with .gitCVE-2014-2237Highkeystone: OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backendCVE-2015-0846Highdjango-markupfield: django-markupfield Arbitrary File ReadCVE-2015-4053Lowceph-deploy: ceph-deploy uses world-readable permissions on client.admin keyCVE-2014-3497Mediumswift: OpenStack Swift Cross-site Scriping vulnerabilityCVE-2015-5251Mediumglance: OpenStack Image Service (Glance) allows remote authenticated users to bypass access restrictionsCVE-2014-2828Highkeystone: OpenStack Identity (Keystone) DoS through V3 API authentication chainingCVE-2012-5498Highplone: Plone denial of service via Caching BypassCVE-2015-5217Mediumipsilon: Ipsilon denial of service via a duplicate SP nameCVE-2014-0012MediumJinja2: Insecure Temporary File in Jinja2CVE-2015-5303Hightripleo-heat-templates: OpenStack TripleO Heat templates spoof metadata requestsCVE-2014-6276Mediumroundup: Roundup sensitive data disclosure vulnerabilityCVE-2015-5271Hightripleo-heat-templates: TripleO Heat templates might allow remote attackers to obtain sensitive information from private containersCVE-2015-5240Lowneutron: OpenStack Neutron Race condition vulnerabilityCVE-2014-3994MediumDjblets: Djiblets Cross-site scripting Vulnerability via JSON ObjectsCVE-2014-1829Mediumrequests: Exposure of Sensitive Information to an Unauthorized Actor in RequestsCVE-2014-4301Mediumajenti: Eugene Pankov Ajenti Cross-site scripting VulnerabilitiesCVE-2016-1241Mediumtrytond: Tryton allows users to read the hashed passwordCVE-2016-4972Criticalmurano: OpenStack Murano Code Execution

Stop the waste.
Protect your environment with Kodem.