PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2013-4346Highoauth2: SimpleGeo python-oauth2 does not check the nonce allowing replay attacksCVE-2013-4347Mediumoauth2: SimpleGeo python-oauth2 vulnerable to the use of Insufficiently Random Values to generate noncesCVE-2013-6444Mediumpywbem: PyWBEM TOCTOU vulnerability in certificate validationCVE-2013-6418Highpywbem: PyWBEM TOCTOU vulnerability in certificate validationCVE-2014-7144Highkeystonemiddleware: OpenStack keystonemiddleware does not verify certificateCVE-2015-5286Mediumglance: OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of serviceCVE-2015-5163Highglance: OpenStack Image Service (Glance) allows remote authenticated users to read arbitrary fileCVE-2016-0757Mediumglance: OpenStack Image Service (Glance) vulnerable to Improper Access ControlCVE-2016-1505CriticalRadicale: Radicale is vulnerable to directory traversal on Windows Filesystem Storage Backend componentCVE-2016-2048Highdjango: Django Access Restrictions Bypass CVE-2016-4911Mediumkeystone: OpenStack Identity Keystone Improper Access Control CVE-2016-5363Highneutron: OpenStack Neutron Intended MAC-spoofing protection mechanism bypassCVE-2016-6298Mediumjwcrypto: jwcrypto lacks the Random Filling protection mechanismCVE-2015-2241Mediumdjango: Django Cross-site Scripting VulnerabilityCVE-2015-3010Lowceph-deploy: ceph-deploy allows local users to obtain sensitive information by reading the fileCVE-2016-0737Highswift: OpenStack Object Storage (Swift) allows remote attackers to cause a denial of serviceCVE-2015-3982MediumDjango: Django allows user sessions hijacking via an empty string in the session keyCVE-2015-8748MediumRadicale: Radicale regex metacharacters injection in the user nameCVE-2015-8747CriticalRadicale: Radicale vulnerable to arbitrary file read or writeCVE-2016-0738Highswift: OpenStack Object Storage (Swift) allows remote attackers to cause a denial of serviceCVE-2014-9623Mediumglance: OpenStack Glance Bypass the storage quota and Denial of service CVE-2015-5301Mediumipsilon: Ipsilon denial of service by deleting a SAML2 Service Provider (SP)CVE-2015-7337Criticalnotebook: Improper Input Validation in Jupyter NotebookCVE-2015-8213Mediumdjango: Django settings leak in date template filterCVE-2015-0219Mediumdjango: Django WSGI Header Spoofing Vulnerability

Stop the waste.
Protect your environment with Kodem.