PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-41952Mediummatrix-synapse: Uncontrolled Resource Consumption in Matrix SynapseCVE-2022-24798Highirrd: Improper Removal of Sensitive Information Before Storage or Transfer in irrdCVE-2022-25598Highorg.apache.dolphinscheduler:dolphinscheduler: Uncontrolled Resource Consumption in Apache DolphinSchedulerCVE-2022-22941Highsalt: SaltStack Salt Permissions BypassCVE-2022-22935Lowsalt: SaltStack Salt Improper Authentication via Man in the Middle AttackCVE-2022-22934Highsalt: SaltStack Improper Verification of Cryptographic SignatureCVE-2022-22936Highsalt: SaltStack Salt Authentication Bypass by Capture-replayCVE-2022-0315Highhorovod: Use of insecure temporary file in HorovodCVE-2022-24776MediumFlask-AppBuilder: Open Redirect in Flask-AppBuilderCVE-2022-24757Highjupyter-server: Insertion of Sensitive Information into Log File in Jupyter notebookCVE-2022-25568Highmotioneye: MotionEye allows attackers to access sensitive informationCVE-2021-4180Mediumtripleo-heat-templates: Exposure of Sensitive Information to an Unauthorized Actor in OpenStack tripleo-heat-templatesCVE-2022-26184Criticalpoetry: Poetry before v1.1.9 contains Untrusted Search PathCVE-2022-24766Criticalmitmproxy: Insufficient Protection against HTTP Request Smuggling in mitmproxyCVE-2022-24302Highparamiko: Race Condition in ParamikoCVE-2022-21822Highnvflare: Allocation of Resources Without Limits or Throttling in nvflareCVE-2022-24770Highgradio: Improper Neutralization of Formula Elements in a CSV File in Gradio FlaggingCVE-2022-24761Highwaitress: HTTP Request Smuggling in waitressCVE-2021-29607Mediumtensorflow: Incomplete validation in `SparseSparseMinimum`CVE-2021-23556Mediumguake: Command injection in guakeCVE-2021-20180Mediumansible: Insertion of Sensitive Information into Log File in ansibleCVE-2022-0959Mediumpgadmin4: pgAdmin 4 Path Traversal vulnerabilityCVE-2022-27193Mediumcvrf2csaf: XML External Entities Vulnerability in CVRF-CSAF-ConverterCVE-2022-0430Mediumhttpie: Exposure of Sensitive information in httpieCVE-2021-45848Highnicotine-plus: Nicotine+ DoS on Null Character in Download Request

Stop the waste.
Protect your environment with Kodem.