PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-41226Mediumtensorflow: Heap OOB in `SparseBinCount`CVE-2021-41227Mediumtensorflow: Arbitrary memory read in `ImmutableConst`CVE-2021-41228Mediumtensorflow: Code injection in `saved_model_cli`CVE-2021-39182Highenrocrypt: Improper hashing in enrocryptGHSA-9WX7-JRVC-28MMHighstarkbank-ecdsa: Signature verification vulnerability in Stark Bank ecdsa librariesCVE-2021-41134Mediumnbdime: Stored XSS in Jupyter nbdimeCVE-2021-41247Mediumjupyterhub: incomplete JupyterHub logout with simultaneous JupyterLab sessionsCVE-2020-5312CriticalPillow: PCX P mode buffer overflow in PillowCVE-2020-10378HighPillow: Out-of-bounds read in PillowCVE-2020-5310Criticalpillow: Integer overflow in PillowCVE-2021-3840Highantilles-tools: Antilles Dependency Confusion VulnerabilityCVE-2024-21910Mediumtinymce: Cross-site scripting vulnerability in TinyMCE pluginsCVE-2020-26705Higheasy-xml: XML External Entity vulnerability in Easy-XMLCVE-2021-41194Criticaljupyterhub-firstuseauthenticator: Improper Access Control in jupyterhub-firstuseauthenticatorGHSA-V988-828W-XVF2Highrucio-webui: Authentication Bypass Using an Alternate Path or Channel and Authentication Bypass by Primary Weakness in rucio-webuiCVE-2021-41146Highqutebrowser: Arbitrary command execution on Windows via qutebrowserurl: URL handlerCVE-2021-41127Highrasa: Maliciously Crafted Model Archive Can Lead To Arbitrary File WriteCVE-2021-42771Highbabel: Directory Traversal in BabelCVE-2021-42576Highpybluemonday: Policies not properly enforced in bluemondayCVE-2021-41131Mediumtuf: Client metadata path-traversalCVE-2021-41078Criticalnameko: Nameko Arbitrary code execution due to YAML deserializationCVE-2021-41132Criticalomero-web: Inconsistent input sanitisation leads to XSS vectorsCVE-2020-19003Mediumgateone: Verification check bypass in Gate OneCVE-2018-5268Mediumopencv-python: Out-of-bounds Write in OpenCV.CVE-2019-5064Highopencv-python: Out-of-bounds Write in OpenCV

Stop the waste.
Protect your environment with Kodem.