PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2017-1002153Highkoji: Koji blacklisted paths workaroundCVE-2017-1002152Mediumbodhi: Bodhi Cross-site Scripting VulnerabilityCVE-2018-14636Mediumneutron: Openstack Neutron vulnerable to eavesdropping on private trafficCVE-2018-16849Highmistral: openstack-mistral Discloses the presence of arbitrary files within the filesystemCVE-2015-4707Mediumipython: Improper Neutralization of Input During Web Page Generation in IPythonCVE-2015-3171Mediumsosreport: sosreport sensitive information disclosure via weak permissions of the generated archivesCVE-2015-7764Highlemur: Lemur uses static IV per keyCVE-2017-5591Mediumslixmpp: SleekXMPP and Slixmpp Incorrect Implementation of Message Carbons CVE-2017-8342HighRadicale: Radicale is vulnerable to timing oracles and simple bruteforce attacksCVE-2015-1864MediumKallithea: Kallithea cross-site scripting (XSS) vulnerabilityCVE-2015-0260HighRhodeCode: RhodeCode and Kallithea are vulnerable to sensitive information disclosureCVE-2015-0276HighKallithea: Kallithea cross-site request forgery (CSRF) vulnerabilityCVE-2015-5285Highkallithea: Kallithea CRLF injection vulnerabilityCVE-2016-3691Highkallithea: Kallithea Routes CSRF BypassCVE-2015-7546Highkeystone: OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected CredentialsCVE-2015-3646Mediumkeystone: OpenStack Keystone Logs PasswordsCVE-2014-3621Mediumkeystone: OpenStack Identity Keystone Exposure of Sensitive InformationCVE-2014-0204Mediumkeystone: OpenStack Identity Keystone Improper Privilege ManagementCVE-2014-3476Mediumkeystone: OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilegeCVE-2013-2014Mediumkeystone: OpenStack Identity (Keystone) Denial of ServiceCVE-2017-17458Criticalmercurial: Mercurial vulnerable to arbitrary code injectionCVE-2018-1000132Criticalmercurial: Mercurial Incorrect Access Control vulnerabilityCVE-2018-13348Highmercurial: Mercurial Improper Input Validation vulnerabilityCVE-2018-13346Highmercurial: Mercurial Improper Input Validation vulnerabilityCVE-2018-13347Criticalmercurial: Mercurial mishandles integer addition and subtraction

Stop the waste.
Protect your environment with Kodem.