PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2017-17516Highrtv: Reddit Terminal Viewer (RTV) vulnerable to argument injection attacksCVE-2015-1856Mediumswift: OpenStack Swift Unauthorized delete of versioned Swift objectCVE-2015-5162Highcinder: OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource ConsumptionCVE-2015-5223Mediumswift: OpenStack Object Storage (Swift) Sensitive Data ExposureCVE-2016-7401Highdjango: Django CSRF Protection BypassCVE-2016-8638Criticalipsilon: Session Fixation in ipsilonCVE-2017-7400Mediumhorizon: OpenStack Horizon Cross-site Scripting (XSS)CVE-2017-7214Criticalnova: OpenStack Nova logs sensitive context from notification exceptionsCVE-2017-1000469Criticalcobbler: Cobbler vulnerable to arbitrary code executionCVE-2017-1000482MediumProducts.CMFPlone: Products.CMFPlone XSS in profile home_page propertyCVE-2011-4139Highdjango: Django Vulnerable to Cache PoisoningCVE-2011-4138HighDjango: Django Might Allow CSRF Requests via URL VerificationCVE-2012-0805CriticalSQLAlchemy: SQLAlchemy vulnerable to SQL injectionCVE-2017-1000481MediumProducts.CMFPlone: Products.CMFPlone Open Redirect VulnerabilityCVE-2014-1858Highnumpy: Arbitrary file write in NumPyCVE-2016-10516MediumWerkzeug: Pallets Werkzeug cross-site scripting vulnerabilityCVE-2018-7490HighuWSGI: uWSGI Directory Traversal vulnerabilityCVE-2018-1000089Criticaldjango-anymail: django-anymail Includes Sensitive Information in Log FilesCVE-2018-1000167Highsuricata-update: OISF suricata-update unsafely deserializes YAML dataCVE-2014-6633Hightryton: Tryton vulnerable to arbitrary command executionCVE-2018-10657Highmatrix-synapse: Matrix Synapse DoSCVE-2018-12104Mediumknowledge-repo: Airbnb Knowledge Repo XSS In CommentsCVE-2011-4104Criticaldjango-tastypie: Django Tastypie Improper Deserialization of YAML DataCVE-2015-4017Highsalt: Salt vulnerable to Improper Certificate ValidationCVE-2015-3220Hightlslite: tlslite remote denial of service vulnerability

Stop the waste.
Protect your environment with Kodem.