PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-45115HighDjango: Denial-of-service in DjangoCVE-2022-22821Mediumnemo-toolkit: Path Traversal in nemo-toolkitCVE-2021-41499Highpyo: Classic Buffer Overflow in pyoCVE-2021-33430Mediumnumpy: NumPy Buffer Overflow (Disputed)CVE-2021-41500Highcvxopt: Incorrect Comparison in cvxoptCVE-2021-4118Highpytorch-lightning: pytorch-lightning is vulnerable to Deserialization of Untrusted DataCVE-2021-32849Highgerapy: An authenticated user can execute arbitrary command in GerapyCVE-2021-3842Highnltk: NLTK Vulnerable to REDoSCVE-2021-23727Highcelery: OS Command Injection in celeryCVE-2021-4162Mediumarchivy: archivy is vulnerable to Cross-Site Request Forgery (CSRF)CVE-2021-43854Highnltk: Inefficient Regular Expression Complexity in nltk (word_tokenize, sent_tokenize)CVE-2021-43857Criticalgerapy: Gerapy may cause remote code executionCVE-2021-34141Mediumnumpy: Incorrect Comparison in NumPyCVE-2021-41498Highpyo: Pyo Buffer Overflow VulnerabilityCVE-2021-41497Highbounter: bounter Null pointer referenceCVE-2021-43837Mediumvault-cli: vault-cli contains possible RCE when reading user-defined dataCVE-2021-44227Highmailman: Cross Site Request Forgery in mailmanCVE-2021-43818Mediumlxml: lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass throughCVE-2021-44420MediumDjango: Potential bypass of an upstream access control based on URL paths in DjangoCVE-2021-41265HighFlask-AppBuilder: Improper Authentication in Flask-AppBuilderCVE-2021-43811Highsockeye: Code injection via unsafe YAML loadingCVE-2021-37941Highelastic-apm: APM Java Agent Local Privilege EscalationCVE-2021-43781Mediuminvenio-drafts-resources: Permissions not properly checked in Invenio-Drafts-ResourcesCVE-2009-4924Mediumpython-cjson: Cross-site Scripting in python-cjsonCVE-2019-14867Highipa: Code injection in FreeIPA

Stop the waste.
Protect your environment with Kodem.