PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2015-0221Highdjango: Django DoS in django.views.static.serveCVE-2015-0222HighDjango: Django database denial-of-service with ModelMultipleChoiceFieldCVE-2015-0220Mediumdjango: Django Cross-site Scripting VulnerabilityCVE-2015-1852Highkeystonemiddleware: OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacksCVE-2015-3219Mediumhorizon: OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerabilityCVE-2015-5964MediumDjango: Denial-of-service possibility in logout() view by filling session storeCVE-2015-1851Mediumcinder: OpenStack Cinder file disclosure in image convertCVE-2014-9684Highglance: OpenStack Glance Denial of service by creating a large number of imagesCVE-2015-1881Highglance: OpenStack Glance Denial of service by creating a large number of images CVE-2014-0472CriticalDjango: Code Injection in DjangoCVE-2014-0473Highdjango: Django Reuses Cached CSRF TokenCVE-2014-0474Highdjango: Django Vulnerable to MySQL InjectionCVE-2014-1418CriticalDjango: Django Vulnerable to Cache PoisoningCVE-2014-5356Mediumglance: OpenStack Glance improper validation of the image_size_cap configuration optionCVE-2016-9964Highbottle: bottle.py vulnerable to CRLF InjectionCVE-2016-4807Mediumweb2py: Web2py Reflected XSS vulnerabilityCVE-2016-1242Mediumtrytond: Tryton allow authenticated users with certain permissions to read arbitrary files via the name parameterCVE-2016-9015Mediumurllib3: Urllib3 Incorrect Certificate ValidationCVE-2016-4808Mediumweb2py: Web2py Cross-Site Request Forgery vulnerabilityCVE-2016-6580Mediumpriority: priority vulnerable to denial of serviceCVE-2016-7148Mediummoin: MoinMoin Cross-site Scripting (XSS) vulnerabilityCVE-2016-7036Criticalpython-jose: python-jose failure to use a constant time comparison for HMAC keysCVE-2016-7146Mediummoin: MoinMoin Cross-site Scripting (XSS) vulnerabilityCVE-2016-9119Mediummoin: MoinMoin Cross-site Scripting (XSS) vulnerabilityCVE-2016-3176Mediumsalt: Salt Insecure configuration of PAM external authentication service

Stop the waste.
Protect your environment with Kodem.