PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-13390Lowcloudtoken: Cloudtoken Insufficiently Protects CredentialsCVE-2018-12423Highmatrix-synapse: Matrix Synapse Authorization ErrorCVE-2018-12291Highmatrix-synapse: Matrix Synapse Security Filtering FlawCVE-2018-10406Highosxcollector: Yelp OSXCollector Improper Certificate ValidationCVE-2018-1000226Criticalcobbler: Cobbler Improper Validation of Security TokensCVE-2017-7893Criticalsalt: SaltStack Salt allows compromised salt-minions to impersonate the salt-masterCVE-2017-5936Highnova-lxd: OpenStack Nova-LXD bypass security restrictionsCVE-2017-5200Highsalt: SaltStack Salt arbitrary command execution in Salt-api via ssh_clientCVE-2017-3590Lowmysql-connector-python: MySQL Connectors Privilege EscalationCVE-2017-18191Highnova: OpenStack Nova Denial of service attack on the compute hostCVE-2017-17051Highnova: OpenStack Nova DoS by rebuilding the same instance with a new image multiple timesCVE-2017-16616Criticalpyanyapi: Unsafe pyyaml load usage in PyAnyAPICVE-2017-16228Criticaldulwich: Dulwich RCE VulnerabilityCVE-2017-16239Mediumnova: OpenStack Nova Filter Scheduler BypassCVE-2017-15914Highborgbackup: Borg Improper Access Control vulnerabilityCVE-2017-14176Highbzr: Bazaar allows remote attackers to execute arbitrary commands via a bzr+ssh URL with initial dash character in hostnameCVE-2017-12852Highnumpy: Numpy missing input validationCVE-2017-12440Highaodh: Openstack Aodh can be used to launder Keystone trustsCVE-2017-12155Mediumtripleo-heat-templates: Openstack tripleo-heat-templates unauthenticated file accessCVE-2017-11610Highsupervisor: Incorrect Default Permissions in SupervisorCVE-2017-11424Highpyjwt: PyJWT vulnerable to key confusion attacksCVE-2017-1000483HighPlone: Plone Unauthorized Access VulnerabilityCVE-2017-1000116Criticalmercurial: Mercurial is vulnerable to shell injection attackCVE-2017-0360Mediumtrytond: Tryton Information Disclosure VulnerabilityCVE-2016-9605Mediumcobbler: Cobbler Arbitrary File Read

Stop the waste.
Protect your environment with Kodem.