PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2014-1934MediumeyeD3: eyeD3 is vulnerable to arbitrary file modification via symlink attackCVE-2014-1839Mediumlogilab-common: Creation of Temporary File With Insecure Permissions in logilab-commonsCVE-2014-1838Highlogilab-common: Improper Link Resolution Before File Access in logilab-commonsCVE-2014-0483MediumDjango: Django data leakage via querystring manipulation in adminCVE-2014-0480Highdjango: Django Incorrectly Validates URLsCVE-2014-0482Mediumdjango: Django Middleware Enables Session HijackingCVE-2014-1830Mediumrequests: Exposure of Sensitive Information to an Unauthorized Actor in RequestsCVE-2014-0157Mediumhorizon: OpenStack Dashboard (aka Horizon) vulnerable to Cross-site ScriptingCVE-2016-3630Highmercurial: Mercurial arbitrary code execution vulnerabilityCVE-2016-3069Highmercurial: Mercurial vulnerable to arbitrary code execution via a crafted name when converting a Git repositoryCVE-2016-3068Highmercurial: Mercurial arbitrary code execution via a crafted git ext:: URL CVE-2015-2316HighDjango: Django Denial-of-service possibility with strip_tagsCVE-2015-2317MediumDjango: Django cross-site scripting (XSS) attack via user-supplied redirect URLsCVE-2014-9601Highpillow: Pillow denial of service via PNG bombCVE-2014-9462Criticalmercurial: Mercurial vulnerable to arbitrary command execution via a crafted repository name in a clone commandCVE-2014-3429Highipython: IPython Notebook vulnerable to improper validation of the origin of websocket requests CVE-2014-3598Highpillow: Pillow is vulnerable to Denial of Service (DOS) in the Jpeg2KImagePluginCVE-2014-3589Highpillow: Pillow denial of service via Crafted Block SizeCVE-2014-4616Mediumsimplejson: simplejson before 2.6.1 vulnerable to array index errorCVE-2014-0481Highdjango: Django denial of service via file upload namingCVE-2015-6938Mediumnotebook: Improper Neutralization of Input During Web Page Generation in Jupyter NotebookCVE-2014-3498Highansible: Ansible Arbitrary Code ExecutionCVE-2013-4259LowAnsible: Ansible uses a socket with predictable filename in /tmpCVE-2013-4260Mediumansible: Ansible Arbitrary File Overwrite VulnerabilityCVE-2012-1585Mediumnova: OpenStack Nova Long server names grow nova-api log files significantly

Stop the waste.
Protect your environment with Kodem.