PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-MFJM-VH54-3F96Mediumscrapy: Scrapy cookie-setting is not restricted based on the public suffix listCVE-2022-0577Mediumscrapy: Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapyCVE-2021-45229Mediumapache-airflow: Apache Airflow Cross-site Scripting VulnerabilityCVE-2022-24288Highapache-airflow: OS Command injection in Apache AirflowCVE-2022-24710MediumWeblate: Cross-site Scripting in WeblateCVE-2022-23653Mediumb2: B2 Command Line Tool TOCTOU application key disclosure CVE-2022-23651Mediumb2sdk: b2-sdk-python TOCTOU application key disclosure CVE-2022-0736Highmlflow: Insecure Temporary File in mlflowCVE-2021-45083Highcobbler: Incorrect Default Permissions in CobblerCVE-2021-45082Highcobbler: Command Injection in CobblerCVE-2022-0637Mediumpollbot: open redirect in pollbotGHSA-7P79-6X2V-5H88Highsanic: Server crash if running Python 3.10 w/ Sanic 20.12GHSA-RPX7-33J2-XX9XLownemo_toolkit: Arbitrary file deletion in NeMo ASR webappCVE-2019-3902Mediummercurial: Mercurial Path Traversal/Link Following vulnerabilityCVE-2020-9480Criticalorg.apache.spark:spark-parent_2.11: Improper Authentication in Apache SparkCVE-2022-23583Mediumtensorflow: `CHECK`-failures in binary ops in TensorflowCVE-2022-23582Mediumtensorflow: `CHECK`-failures in `TensorByteSize` in TensorflowCVE-2022-23579Mediumtensorflow: `CHECK`-failures during Grappler's `SafeToRemoveIdentity` in TensorflowCVE-2022-23578Mediumtensorflow: Memory leak in TensorflowCVE-2022-23575Hightensorflow: Integer overflow in TensorflowCVE-2022-23576Hightensorflow: Integer overflow in TensorflowCVE-2022-23577Hightensorflow: Null-dereference in TensorflowCVE-2022-21735Hightensorflow: Division by zero in TensorflowCVE-2022-21734Hightensorflow: `CHECK`-failures in TensorflowCVE-2022-21733Mediumtensorflow: Memory exhaustion in Tensorflow

Stop the waste.
Protect your environment with Kodem.