PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2017-17554Mediumaubio: Aubio is vulnerable to a NULL pointer dereferenceCVE-2018-1000516Mediumgalaxy-app: Galaxy cross-site scripting (XSS)CVE-2018-14521Highaubio: Aubio is vulnerable to denial of service via aubio_source_avcodec_readframe functionCVE-2017-12614Mediumapache-airflow: Apache Airflow Reflected Cross-site Scripting vulnerability in 404 EndpointCVE-2013-4200HighPlone: Plone Open Redirection vulnerability via next parameterCVE-2013-6480Lowapache-libcloud: Libcloud does not properly scrub data when destroying a DigitalOcean nodeCVE-2014-3225Mediumcobbler: Cobbler Path Traversal vulnerabilityCVE-2016-6186Mediumdjango: Django Cross-site scripting VulnerabilityCVE-2016-7135MediumPlone: Plone vulnerable to filesystem information leakCVE-2016-7136Mediumplone: Plone XSSCVE-2016-7137Mediumplone: Plone Open Redirect VulnerabilityCVE-2016-7139MediumPlone: Plone Cross-site Scripting (XSS) vulnerabilityCVE-2016-7138Mediumplone: Plone XSSCVE-2016-7140MediumPlone: Plone vulnerable to Cross-site ScriptingCVE-2015-3221Mediumneutron: OpenStack Neutron Improper Input Validation vulnerabilityCVE-2018-1000225Mediumcobbler: Cobbler XSS VulnerabilityCVE-2016-5362Highneutron: OpenStack Neutron allows remote attackers to bypass an intended DHCP-spoofing protection mechanismCVE-2015-8914Criticalneutron: OpenStack Neutron allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanismCVE-2016-10075Hightqdm: TDQM Arbitrary Code ExecutionCVE-2016-1866Highsalt: Salt Improper Access ControlCVE-2013-4111Highpython-glanceclient: python-glanceclient vulnerable to SSL server spoofing due to unverified X.509 certificateCVE-2013-2191Highpython-bugzilla: python-bugzilla has improper validation of X.509 certificatesCVE-2013-2161Highswift: OpenStack Swift Unchecked user input in XML responsesCVE-2013-2132Mediumpymongo: Use of NullPointerException Catch to Detect NULL Pointer Dereference in PymongoCVE-2014-3730HighDjango: Django Allows Open Redirects

Stop the waste.
Protect your environment with Kodem.