PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2013-4185Mediumnova: OpenStack Nova Denial of Service in network source security groupsCVE-2011-4596Mediumnova: OpenStack Nova Multiple directory traversal vulnerabilitiesCVE-2014-3517Mediumnova: OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityCVE-2012-4456Highkeystone: OpenStack Keystone Improper Authentication vulnerabilityCVE-2012-4457MediumKeystone: OpenStack Keystone Token authorization for a user in a disabled tenant is allowedCVE-2013-2256Mediumnova: OpenStack Compute (Nova) allows remote authenticated users to obtain sensitive informationCVE-2013-4202Mediumcinder: OpenStack Cinder Denial of Service using XML entities CVE-2014-3608Mediumnova: OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of serviceCVE-2015-8749Mediumnova: OpenStack Nova Potential Xen connection password leak via StorageErrorCVE-2014-3708Mediumnova: OpenStack Compute (Nova) Denial of Service vulnerabilityCVE-2015-3280Mediumnova: OpenStack Compute (nova) allows remote authenticated users to cause a denial of serviceCVE-2013-7048Lownova: OpenStack Nova live snapshots use an insecure local directoryCVE-2015-3241Mediumnova: OpenStack Nova instance migration process does not stop when instance is deletedCVE-2013-6437Mediumnova: OpenStack Nova DoS through ephemeral disk backing filesCVE-2015-7713Mediumnova: OpenStack Compute (Nova) allows remote attackers to bypass intended restrictionCVE-2015-0259Mediumnova: OpenStack Compute (Nova) has Insufficient Verification of Data AuthenticityCVE-2014-7231Lowoslo.utils: OpenStack Oslo utility sensitive information exposure via log filesCVE-2016-2140Mediumnova: OpenStack Nova host data access through resize/migrationCVE-2018-18548Mediumajenti: Ajenti Cross-site Scripting Via FilenameCVE-2013-2037Mediumhttplib2: httplib2 incorrectly checks SSL certificateCVE-2018-17983Highmercurial: Mercurial Out-of-bounds Read vulnerabilityCVE-2015-3206Criticalkerberos: python-kerberos vulnerable to KDC spoofing attacksCVE-2015-0861Mediumtrytond: trytond arbitrary fields write via a sequence of recordsCVE-2015-1195Mediumglance: OpenStack Glance v2 API unrestricted path traversal through filesystem:// schemeCVE-2019-7313Mediumbuildbot: Buildbot CRLF Injection

Stop the waste.
Protect your environment with Kodem.