PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-7560Highpyboolector: Boolector use after freeCVE-2018-7749CriticalAsyncSSH: AsyncSSH SSH Server Authentication BypassCVE-2019-7537Criticaldonfig: Donfig Command Injection in collect_yaml methodCVE-2018-16859Mediumansible: Ansible Logs Passwords If PowerShell ScriptBlock is EnabledCVE-2019-9644Mediumjupyter-notebook: Improper Neutralization of Input During Web Page Generation in Jupyter NotebookCVE-2018-14522Highaubio: Aubio is vulnerable to denial of service via aubio_pitch_set_unit functionCVE-2014-8333Mediumnova: OpenStack Nova VMware instance leak potentially leading to compute DoSCVE-2014-1859Highnumpy: Numpy arbitrary file write via symlink attackCVE-2013-2217Mediumsuds: Improper Link Resolution Before File Access in SudsCVE-2017-1000115Highmercurial: Mercurial missing symlink checkCVE-2016-1494Mediumrsa: Python RSA allows attackers to spoof signaturesCVE-2016-10321Criticalweb2py: web2py is vulnerable to password brute-force attackCVE-2016-3954Mediumweb2py: web2py exposure of sensitive informationCVE-2016-3953Criticalweb2py: web2py remote code execution via hardcoded encryption key in session.connect functionCVE-2017-15112Highkeycloak-httpd-client-install: keycloak-httpd-client-install Insecure SecretsCVE-2017-15111Mediumkeycloak-httpd-client-install: keycloak-httpd-client-install symlink attack vulnerabilityCVE-2018-10931Criticalcobbler: Cobbler has Exposed Dangerous Method or FunctionCVE-2017-1000426MediumMapProxy: MapProxy vulnerable to cross-site scripting in demo serviceCVE-2015-6240Highansible: Ansible Sandbox Escape via Symlink AttackCVE-2015-7529Highsosreport: SoSReport Predictable Tmp File NamesCVE-2018-9160Criticalsickrage: SiCKRAGE Discloses Plaintext CredentialsCVE-2018-18482Highpg-query: libpg_query memory leakCVE-2018-16837Highansible: Ansible Leaks Data Passed to ssh-keygenCVE-2018-16515Highmatrix-synapse: Matrix Synapse Improper Signature ValidationCVE-2018-14523Highaubio: Aubio is vulnerable to out of bound read when samplerate > 50kHz

Stop the waste.
Protect your environment with Kodem.