PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2003-0038Mediummailman: Mailman Cross-site scripting (XSS) vulnerability CVE-2021-41945Criticalhttpx: Improper Input Validation in httpxCVE-2022-23942Highpydoris: Apache Doris hardcoded key and IVCVE-2022-24880Mediumflask-session-captcha: Potential Captcha Validate Bypass in flask-session-captchaCVE-2012-6133Mediumroundup: Multiple cross-site scripting (XSS) vulnerabilities in RoundupCVE-2012-2238Hightrytond: trytond Incorrect Authorization vulnerabilityCVE-2012-0051Mediumtahoe-lafs: Tahoe-LAFS fails to ensure integrityCVE-2022-24859MediumPyPDF2: Manipulated inline images can cause Infinite Loop in PyPDF2CVE-2022-24857Highdjango-mfa3: Improper Authentication in django-mfa3GHSA-CF4Q-4CQR-7G7WMediumxml2rfc: SVG with embedded scripts can lead to cross-site scripting attacks in xml2rfcCVE-2022-24845Highvyper: Integer bounds error in VyperCVE-2011-4076Mediumnova: OpenStack Nova Exposure of Sensitive Information to an Unauthorized ActorCVE-2011-4924Mediumzope: Zope XSS VulnerabilityCVE-2011-4952Highcobbler: Cobbler Web Interface Lacks CSRF ProtectionCVE-2011-3147Lownova: Openstack nova qcow format could expose host filesystem informationCVE-2010-4237Mediummercurial: Mercurial Improper Certificate Validation vulnerabilityCVE-2009-3724Mediummarkdown2: Cross-site scripting in markdown2 for pythonCVE-2022-24788Highvyper: Buffer Overflow in vyperCVE-2022-27479Criticalapache-superset: SQL injection in apache-supersetCVE-2022-28346CriticalDjango: SQL Injection in DjangoCVE-2022-28347CriticalDjango: SQL Injection in DjangoCVE-2022-24758Highnotebook: Sensitive Auth & Cookie data stored in Jupyter server logsGHSA-7VRM-3JC8-5WWMHighvyper: Incorrect Comparison in VyperCVE-2022-24801Criticaltwisted: Inconsistent Interpretation of HTTP Requests in twisted.webCVE-2022-27177Criticalconsoleme: Use of Externally-Controlled Format String in consoleme

Stop the waste.
Protect your environment with Kodem.