PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-18705Criticalquokka: Improper Restriction of XML External Entity Reference in QuokkaCVE-2020-18704Criticaldjango-widgy: Unrestricted Upload of File with Dangerous Type in django-widgyCVE-2020-18703Criticalquokka: Improper Restriction of XML External Entity Reference in QuokkaCVE-2020-18702Mediumquokka: Cross Site Scripting (XSS) in QuokkaCVE-2021-39160Highnbgitpuller: Code injection in nbgitpullerCVE-2021-39159Criticalbinderhub: remote code execution via git repo providerCVE-2021-32629Highcranelift-codegen: Memory access due to code generation flaw in Cranelift moduleCVE-2018-20998Criticalarrayfire: Potential memory corruption in arrayfireCVE-2021-37635Hightensorflow: Heap out of bounds access in sparse reduction operationsCVE-2021-37636Mediumtensorflow: Floating point exception in `SparseDenseCwiseDiv`CVE-2021-37637Hightensorflow: Null pointer dereference in `CompressElement`CVE-2021-37638Hightensorflow: Null pointer dereference in `RaggedTensorToTensor`CVE-2021-37639Hightensorflow: Null pointer dereference and heap OOB read in operations restoring tensorsCVE-2021-37640Mediumtensorflow: Integer division by 0 in sparse reshapingCVE-2021-37641Mediumtensorflow: Heap OOB in `RaggedGather`CVE-2021-37642Mediumtensorflow: Division by 0 in `ResourceScatterDiv`CVE-2021-37643Hightensorflow: Null pointer dereference in `MatrixDiagPartOp`CVE-2021-37644Mediumtensorflow: `std::abort` raised from `TensorListReserve`CVE-2021-37645Mediumtensorflow: Integer overflow due to conversion to unsignedCVE-2021-37646Mediumtensorflow: Bad alloc in `StringNGrams` caused by integer conversionCVE-2021-37647Hightensorflow: Null pointer dereference in `SparseTensorSliceDataset`CVE-2021-37648Hightensorflow: Incorrect validation of `SaveV2` inputsCVE-2021-37649Hightensorflow: Null pointer dereference in `UncompressElement`CVE-2021-37650Hightensorflow: Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord`CVE-2021-37651Hightensorflow: Heap buffer overflow in `FractionalAvgPoolGrad`

Stop the waste.
Protect your environment with Kodem.