PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2015-5144Highdjango: Django Vulnerable to HTTP Response Splitting AttackCVE-2015-5145HighDjango: Django ReDoS in validators.URLValidatorCVE-2015-4706Mediumipython: Improper Neutralization of Input During Web Page Generation in IPythonCVE-2015-5963MediumDjango: Django denial of service via empty session record creationCVE-2015-7316Mediumplone: Plone Cross-site Scripting VulnerabilityCVE-2015-7315HighProducts.CMFPlone: Plone unauthorized member addition vulnerabilityCVE-2015-7318HighPlone: Plone Header InjectionCVE-2015-5607Highipython: IPython vulnerable to cross site request forgery (CSRF)CVE-2015-7293HighPlone: Plone vulnerable to cross-site request forgeryCVE-2017-5192Highsalt: SaltStack Salt Authentication Bypass when using the local_batch client from salt-apiCVE-2016-9014CriticalDjango: Django DNS Rebinding VulnerabilityCVE-2016-9013CriticalDjango: Django user with hardcoded password created when running tests on OracleCVE-2015-6918Mediumsalt: salt leaks git usernames and passwords to the logCVE-2017-15612Mediummistune: Cross-site Scripting in MistuneCVE-2017-14695Criticalsalt: SaltStack Salt Directory traversal vulnerability in minion id validationCVE-2017-14696Highsalt: SaltStack Salt Denial of Service via a crafted authentication requestCVE-2013-6044MediumDjango: Django cross-site scripting (XSS) vulnerability via is_safe_url function CVE-2017-16762Highsanic: Sanic arbitrary file read and directory traversalCVE-2017-16613Criticalswauth: OpenStack Swauth object/proxy server writing Auth Token to log fileCVE-2017-17054Highaubio: Aubio Divide-By-Zero DoS vulnerability in new_aubio_source_wavread functionCVE-2014-0105Lowpython-keystoneclient: python-keystoneclient vulnerable to context confusion in Keystone auth_token middlewareCVE-2022-30765Criticalcalibreweb: SQL injection in calibrewebCVE-2014-1402HighJinja2: Incorrect Privilege Assignment in Jinja2CVE-2014-3146Mediumlxml: lxml Cross-site Scripting Via Control CharactersCVE-2014-3801Lowopenstack-heat: OpenStack Heat template URL information leakage

Stop the waste.
Protect your environment with Kodem.