PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-15751Criticalsalt: SaltStack Salt Remote command execution and incorrect access control when using salt-apiCVE-2018-15750Mediumsalt: SaltStack Salt Directory Traversal vulnerability in salt-apiCVE-2019-2435Highmysql-connector-python: Improper Access Control in MySQL Connector PythonCVE-2019-1000021Highslixmpp: slixmpp Incorrect Access ControlCVE-2017-9111HighOpenEXR: OpenEXR invalid writeCVE-2017-9112MediumOpenEXR: OpenEXR invalid readCVE-2019-3830Mediumceilometer: Ceilometer Prints Sensitive Configuration Data to LogCVE-2018-19787Mediumlxml: Improper Neutralization of Input During Web Page Generation in LXMLCVE-2018-7206Highoauthenticator: JupyterHub OAuthenticator elevation of privilegeCVE-2014-3473Mediumhorizon: Horizon-Orchestration Cross-site scripting (XSS) vulnerability through resource nameCVE-2014-3474Lowhorizon: OpenStack Horizon Cross-site scripting (XSS) vulnerabilityCVE-2014-3594Lowhorizon: OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interfaceCVE-2018-16552HighDjango-CRM: MicroPyramid Django-CRM CSRFCVE-2013-1888Mediumpip: Improper Link Resolution Before File Access in pipCVE-2014-8991Mediumpip: pip lack of randomness in build directoryCVE-2013-1629Highpip: Improper Input Validation in pipCVE-2015-2296Mediumrequests: Python Requests Session FixationCVE-2019-11236Mediumurllib3: Improper Neutralization of CRLF Sequences in urllib3 library for PythonCVE-2013-1909Highqpid-python: Apache Qpid Python client Improper certificate validationCVE-2019-5885Highmatrix-synapse: Matrix Synapse Predictable Secret KeyCVE-2019-10844Criticalnnabla: Sony Neural Network Libraries reliance on untrusted inputs prior to v1.0.10CVE-2018-10875Highansible: Ansible Arbitrary Code ExecutionCVE-2018-16876Highansible: Ansible sensitive information disclosureCVE-2016-4428Mediumhorizon: OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerabilityCVE-2016-4985Highironic: OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor

Stop the waste.
Protect your environment with Kodem.