PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-3583Highansible: Improper Input Validation and Command Injection in AnsibleCVE-2020-23478Highleo: Regular Expression Denial of Service in Leo EditorCVE-2021-35042CriticalDjango: SQL Injection in DjangoCVE-2021-39229Highapprise: Apprise vulnerable to regex injection with IFTTT PluginCVE-2021-39219Mediumwasmtime: Wrong type for `Linker`-define functions when used across two `Engine`sCVE-2021-39218Mediumwasmtime: Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime CVE-2021-39216Mediumwasmtime: Use after free passing `externref`s to Wasm in WasmtimeCVE-2021-39214Criticalmitmproxy: Lacking Protection against HTTP Request Smuggling in mitmproxyCVE-2021-24040Mediumparlai: Deserialization of Untrusted Data in ParlAICVE-2021-40839Highrencode: Infinite Loop in rencodeCVE-2021-39207Mediumparlai: Deserialization of Untrusted Data in parlaiCVE-2021-32839Highsqlparse: StripComments filter contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service)CVE-2021-23404Highsqlite-web: Cross-Site Request Forgery in sqlite-webCVE-2021-32805MediumFlask-AppBuilder: Flask-AppBuilder Open Redirect vulnerabilityCVE-2021-32838Highflask-restx: Regular Expression Denial of Service in flask-restxCVE-2021-23437Highpillow: Uncontrolled Resource Consumption in pillowCVE-2021-39286Mediumpywb: Cross-site scripting in pywbCVE-2021-39371Highpywps: XML External Entity Injection in PyWPSCVE-2020-19001Criticalsimiki: Command Injection in SimikiCVE-2020-19000Mediumsimiki: Cross Site Scripting (XSS) in SimikiCVE-2021-39163Lowmatrix-synapse: Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.CVE-2021-39164Lowmatrix-synapse: Improper authorisation of members discloses room membership to non-membersCVE-2021-35936Mediumapache-airflow: Missing Authorization in Apache AirflowCVE-2021-23423Mediumbikeshed: Path Traversal in bikshedCVE-2021-23422Highbikeshed: OS Command Injection in bikeshed

Stop the waste.
Protect your environment with Kodem.