PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-33880Highwebsockets: Observable Timing Discrepancy in aaugustin websockets libraryCVE-2021-33571HighDjango: Django Access Control Bypass possibly leading to SSRF, RFI, and LFI attacks CVE-2021-33203Mediumdjango: Path Traversal in DjangoCVE-2021-32677Highfastapi: Cross-Site Request Forgery (CSRF) in FastAPICVE-2019-20916Highpip: Path Traversal in pipCVE-2020-12690Highkeystone: Insufficient Session Expiration in OpenStack KeystoneCVE-2021-32052MediumDjango: Header injection possible in DjangoCVE-2021-33508MediumPlone: Cross-site scripting in PloneCVE-2021-33512MediumPlone: Cross-site scripting in PloneCVE-2021-33513MediumPlone: Cross-site scripting in PloneCVE-2017-8761Lowswift: Temporary urls leaked via loggingCVE-2021-28677HighPillow: Uncontrolled Resource Consumption in PillowCVE-2021-25288HighPillow: Pillow Out-of-bounds Read vulnerabilityCVE-2021-28678MediumPillow: Insufficient Verification of Data Authenticity in PillowCVE-2021-28675HighPillow: Pillow denial of serviceCVE-2021-25287HighPillow: Out-of-bounds Read in PillowCVE-2021-28676HighPillow: Potential infinite loop in PillowCVE-2021-32674HighZope: Remote Code Execution via traversal in TAL expressionsCVE-2021-32670Mediumdatasette: Reflected cross-site scripting issue in DatasetteCVE-2020-17495Highdjango-celery-results: django-celery-results Stores Sensitive Information In CleartextCVE-2021-31542HighDjango: Path Traversal in DjangoCVE-2020-13388Criticaljw.util: OS Command Injection in jw.utilCVE-2021-26813Highmarkdown2: markdown2 Regular Expression Denial of Service CVE-2021-33038HighHyperKitty: Exposure of sensitive information to an unauthorized actor in HyperKittyCVE-2021-20178Highansible: Insertion of Sensitive Information into Log File in ansible

Stop the waste.
Protect your environment with Kodem.