PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2012-4413Mediumkeystone: OpenStack Keystone does not invalidate existing tokens when granting or revoking rolesCVE-2012-4573Mediumglance: OpenStack Glance arbitrary deletion of non-protected imagesCVE-2012-5482Mediumglance: OpenStack Glance arbitrary deletion of non-protected imagesCVE-2012-5563Highkeystone: OpenStack Keystone Insufficient token expirationCVE-2012-5571MediumKeystone: OpenStack Keystone intended authorization restrictions bypassCVE-2012-5825Mediumtweepy: Tweepy does not verify SSL Certificate CVE-2012-6130Mediumroundup: Roundup Cross-site Scripting (XSS) vulnerabilityCVE-2012-6132Mediumroundup: Roundup Cross-site Scripting (XSS) vulnerabilityCVE-2012-6131Mediumroundup: Roundup Cross-site scripting (XSS) vulnerabilityCVE-2013-1838Highnova: OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp functionCVE-2013-1840Lowglance: OpenStack Glance is vulnerable to Exposure of Sensitive InformationCVE-2013-2059Mediumkeystone: OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user CVE-2013-2100Highportage: Gentoo Portage does not verify X.509 certificates from SSL serversCVE-2013-4249Mediumdjango: Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widgetCVE-2013-7130Highnova: OpenStack Nova Live migration can leak root disk into ephemeral storageCVE-2014-1604LowRPLY: RPLY Predictable Tmpfile Names Allows Cache SpoofingCVE-2014-1624Lowpyxdg: pyxdg Arbitrary File Overwrite via Race ConditionCVE-2014-3563Highsalt: SaltStack Salt Insecure Temporary File CreationCVE-2017-12791Criticalsalt: SaltStack Salt Directory traversal vulnerability in minion id validationCVE-2017-14158Highscrapy: Scrapy denial of service vulnerabilityCVE-2014-7960Mediumswift: OpenStack Swift metadata constraints are not correctly enforcedCVE-2016-2512Mediumdjango: Django XSS VulnerabilityCVE-2016-2513Lowdjango: Django User Enumeration VulnerabilityCVE-2015-5695Highdesignate: Designate mDNS DoS through incorrect handling of large RecordSetsCVE-2013-2013Lowpython-keystoneclient: python-keystoneclient unsecure user password update

Stop the waste.
Protect your environment with Kodem.