PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2006-5878Hightrac: Edgewall Trac Cross-site request forgery (CSRF) vulnerabilityCVE-2006-4684Mediumzope2: Zope allows remote attackers to read arbitrary filesCVE-2006-4249MediumPlone: Plone allows a user to masquerade as a groupCVE-2006-4247HighPlone: Plone allows anonymous users to reset any users password through the web via Password Reset ToolCVE-2006-3695Hightrac: Trac reStructuredText breach of privacy and denial of service vulnerabilityCVE-2006-3458LowZope2: Zope allows local users to read arbitrary filesCVE-2006-2458Mediumextractor: Libextractor multiple heap-based buffer overflowsCVE-2006-1711Mediumplone: Plone allows remote users to modify arbitrary portraitsCVE-2006-0847Highcherrypy: CherryPy Directory traversal vulnerabilityCVE-2005-4644Mediumtrac: Trac HTML WikiProcessor cross-site scripting (XSS) vulnerabilityCVE-2005-2875HighPy2Play: Py2Play Unpickles Untrusted ObjectsCVE-2005-1632Highcheetah: Cheetah Path Search Order HijackingCVE-2002-0687Mediumzope: Zope Server vulnerable to DoS via header injectionCVE-2002-0688Highzope: ZCatalog plug-in for Zope allows anonymous users to bypass access restrictionsCVE-2002-0170Highzope: Zope does not properly verify the access for objects with proxy rolesCVE-2000-1211Highzope: Zope does not properly perform security registration for legacy namesCVE-2000-1212Mediumzope: Zope allows attackers to modify raw image and file dataCVE-2000-0725Highzope: Zope does not properly restrict access to the getRoles methodCVE-2000-0062Highzope: Zope DTML implementation Improper AuthenticationCVE-2004-1462HighMoin: MoinMoin Improper Access Control CVE-2004-1463HighMoin: MoinMoin Improper Privilege ManagementCVE-2004-1444MediumRoundup: Roundup Directory traversal vulnerabilityCVE-2004-1177Mediummailman: mailman Cross-site scripting (XSS) vulnerability CVE-2004-0708HighMoin: MoinMoin allows administrative accessCVE-2004-0412Mediummailman: Mailman Sensitive Information Disclosure

Stop the waste.
Protect your environment with Kodem.