PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-10874Highansible: Ansible Improper Input Validation vulnerabilityCVE-2018-16856Highoctavia: Openstack Octavia allows Insertion of Sensitive Information into Log FileCVE-2019-10876Highneutron: OpenStack Neutron overlapping security group rules prevents compute node network configurationCVE-2019-9735Highneutron: OpenStack Neutron's unsupported dport option prevents applying security groupsCVE-2018-14635Highneutron: OpensStack Neutron Denial of Service VulnerabilityCVE-2017-7466Highansible: Ansible Arbitrary Code ExecutionCVE-2017-7549Mediuminstack-undercloud: instack-undercloud vulnerable to symlink attack on tmp filesCVE-2017-7543Mediumneutron: OpenStack Neutron Race Condition vulnerabilityCVE-2017-2673Highkeystone: OpenStack Identity service (keystone) Incorrect AuthorizationCVE-2016-6519Mediummanila-ui: Openstack Manila Persistent XSS in Metadata fieldCVE-2015-5237HighGoogle.Protobuf: protobuf susceptible to buffer overflowCVE-2016-5851Highpython-docx: Improper Restriction of XML External Entity Reference in python-docxCVE-2017-7550Criticalansible: Ansible Insertion of Sensitive Information into Log File vulnerabilityCVE-2018-25033Highadmesh: Out-of-bounds read in admeshCVE-2022-28470Criticalmarcador: Code-execution backdoor in marcadorCVE-2022-30284Criticalpython-libnmap: Argument injection in python-libnmapCVE-2022-1592Highscout-browser: Server-Side Request Forgery in scout-browserCVE-2022-1053Criticalkeylime: Tenant and Verifier might not use the same registrar dataCVE-2013-0335HighNova: OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VMCVE-2013-0305MediumDjango: Django Data leakage via admin history logCVE-2013-0306MediumDjango: Django is vulnerable to Denial of Service attack in formset CVE-2013-0282MediumKeystone: OpenStack Keystone allows context-dependent attackers to bypass access restrictionsCVE-2013-0270Mediumkeystone: OpenStack Keystone Denial of Service vulnerability via a large HTTP requestCVE-2013-0212Mediumglance: OpenStack Glance logs user name and password in cleartext CVE-2013-7489MediumBeaker: Deserialization of Untrusted Data in Beaker

Stop the waste.
Protect your environment with Kodem.