PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-1000111Mediumtwisted: Forced Browsing in TwistedCVE-2020-7212Highurllib3: Uncontrolled Resource Consumption in urllib3CVE-2021-26722Mediumoncall: LinkedIn Oncall vulnerable to Cross-Site ScriptingGHSA-JGPV-4H4C-XHW3Mediumpillow: Uncontrolled Resource Consumption in pillowCVE-2020-1733Lowansible: Ansible vulnerable to Exposure of Resource to Wrong Sphere and Insecure Temporary FileCVE-2019-14905Highansible: Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in…CVE-2020-10691Mediumansible: Path Traversal in AnsibleCVE-2019-14904Highansible: OS Command Injection and Improper Input Validation in ansibleCVE-2020-14365Mediumansible: Improper Verification of Cryptographic Signature in ansibleCVE-2020-1746Mediumansible: Exposure of Sensitive Information to an Unauthorized Actor in ansibleCVE-2020-1737Highansible: Path Traversal in AnsibleCVE-2019-20477Criticalpyyaml: Deserialization of Untrusted Data in PyYAMLCVE-2020-17526Highapache-airflow: Incorrect Session Validation in Apache AirflowCVE-2020-17515Mediumapache-airflow: Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944CVE-2020-29651Highpy: py vulnerable to Regular Expression Denial of ServiceCVE-2020-29456Mediumpapermerge: Cross-site scripting in papermergeCVE-2021-20270HighPygments: Infinite Loop in PygmentsCVE-2021-25925Mediumsickrage: Cross-site scripting in SiCKRAGECVE-2021-25926Mediumsickrage: Cross-site scripting in sickrageCVE-2020-17446Criticalasyncpg: Asyncpg Arbitrary Code Execution Via Access to an Uninitialized PointerCVE-2020-28724Mediumwerkzeug: Open Redirect in werkzeugCVE-2021-29421Highpikepdf: Improper Restriction of XML External Entity Reference in pikepdfCVE-2020-27589Highblackduck: Improper Certificate Validation in blackduckCVE-2020-1747Criticalpyyaml: Improper Input Validation in PyYAMLCVE-2020-35678Mediumautobahn: Open Redirect in autobahn

Stop the waste.
Protect your environment with Kodem.