PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2017-12597Highopencv-python: Out-of-bounds Write in OpenCVCVE-2016-1517Mediumopencv-python: Improper Input Validation in OpenCVCVE-2016-1516Highopencv-python: Double Free in OpenCVCVE-2021-40978Highmkdocs: Directory traversal in mkdocsCVE-2021-42053Mediumdjango-unicorn: Cross-site scripting in Unicorn frameworkCVE-2021-42134Mediumdjango-unicorn: Cross-site Scripting in django-unicornCVE-2019-10217Highansible: Exposure of Sensitive Information to an Unauthorized Actor in ansibleCVE-2013-2166Criticalpython-keystoneclient: Inadequate Encryption Strength in python-keystoneclientCVE-2013-1895Highpy-bcrypt: Improper Restriction of Excessive Authentication Attempts in py-bcryptCVE-2020-12607Highfastecdsa: Improper Verification of Cryptographic Signature in fastecdsaCVE-2020-8897Highcom.amazonaws:aws-encryption-sdk-java: Security issues in AWS KMS and AWS Encryption SDKs: in-band protocol negotiation and robustnessCVE-2021-41121Highvyper: Memory corruption when returning a literal struct with a private call inside of itCVE-2021-41124Highscrapy-splash: Splash authentication credentials potentially leaked to target websites CVE-2021-41122Mediumvyper: missing clamps for decimal args in external functionsCVE-2021-28125Mediumsuperset: Open Redirect in Apache SupersetCVE-2021-41125MediumScrapy: Scrapy HTTP authentication credentials potentially leaked to target websites CVE-2021-34552Criticalpillow: Buffer Overflow in PillowCVE-2021-22557Mediumslo-generator: Code Injection in SLO GeneratorCVE-2021-40325Highcobbler: Cobbler before 3.3.0 allows authorization bypass for modification of settings.CVE-2021-40323Highcobbler: Cobbler before 3.3.0 allows log poisoningCVE-2021-40324Highcobbler: Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.CVE-2021-25963Mediumshuup: Cross-site Scripting in shuupCVE-2021-25962Highshuup: CSV injection in shuupCVE-2021-3828Highnltk: NLTK Vulnerable to REDoSCVE-2021-41104Highesphome: Basic auth bypass in esphome

Stop the waste.
Protect your environment with Kodem.