PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-21187Criticallibvcs: Command injection in libvcs and vcspullGHSA-32GV-6CF3-WCMQCriticaltwisted: HTTP/2 DoS Attacks: Ping, Reset, and Settings FloodsCVE-2022-25511MediumFreeTAKServer-UI: Path traversal in FreeTAKServer-UICVE-2022-25507MediumFreeTAKServer-UI: Cross-site Scripting in FreeTAKServer-UICVE-2022-25508HighFreeTAKServer: Improper Authentication in FreeTAKServerCVE-2022-25506MediumFreeTAKServer-UI: SQL Injection in FreeTAKServer-UICVE-2022-25512HighFreeTAKServer-UI: Exposure of Sensitive Information to an Unauthorized Actor in FreeTAKServer-UICVE-2022-25510HighFreeTAKServer: Hard coded credentials in FreeTAKServerCVE-2022-0932Mediumsaleor: saleor Missing Authorization vulnerabilityGHSA-4FX9-VC88-Q2XCLowPillow: Infinite loop in PillowCVE-2022-24303HighPillow: Path traversal in PillowCVE-2022-0860Mediumcobbler: Improper Authorization in cobblerCVE-2021-38296Highorg.apache.spark:spark-core: Authentication Bypass by Capture-replay in Apache SparkCVE-2022-26662Hightrytond: XML Entity Expansion in trytond and proteusCVE-2022-26661Mediumtrytond: Improper Restriction of XML External Entity Reference in trytond and proteusCVE-2022-0697Mediumarchivy: Open Redirect in archivyCVE-2022-0766Criticalcalibreweb: Server-Side Request Forgery in calibrewebCVE-2022-0767Criticalcalibreweb: Server-Side Request Forgery in calibrewebCVE-2022-24737Mediumhttpie: Exposure of Sensitive Information to an Unauthorized Actor in httpieCVE-2022-0869Mediumdjango-spirit: Open Redirect in django-spiritCVE-2022-0845Criticalpytorch-lightning: Code Injection in PyTorch LightningCVE-2022-23915HighWeblate: Improper Neutralization of Special Elements used in a Command ('Command Injection') in WeblateCVE-2021-3654Mediumnova: Open Redirect in CPython that affects users of OpenStack NovaCVE-2021-3620Mediumansible: Ansible discloses sensitive information in traceback error messageCVE-2022-21716Hightwisted: Twisted SSH client and server deny of service during SSH handshake.

Stop the waste.
Protect your environment with Kodem.