PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-28468Criticalpwntools: pwntools Server-Side Template Injection (SSTI) vulnerabilityCVE-2021-29434Highwagtail: Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fieldsGHSA-22WC-C9WJ-6Q2VMediumvyper: VVE-2021-0001: Memory corruption using function calls within arraysGHSA-375M-5FVV-XQ23Lowvyper: VVE-2021-0002: Incorrect `returndatasize` when using simple forwarder proxies deployed prior to EIP-1167 adoptionCVE-2021-29432Mediummatrix-sydent: Malicious users could abuse Sydent to control the content of invitation emailsCVE-2021-29431Mediummatrix-sydent: SSRF in Sydent due to missing validation of hostnamesCVE-2021-29430Highmatrix-sydent: Sydent vulnerable to denial of service attack via memory exhaustionCVE-2021-29433Mediummatrix-sydent: Sydent DoS (via resource exhaustion) due to improper input validationCVE-2021-30459Highdjango-debug-toolbar: SQL Injection via in django-debug-toolbarCVE-2021-21392Highmatrix-synapse: Open redirect via transitional IPv6 addresses on dual-stack networksCVE-2021-21394Mediummatrix-synapse: Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpointsCVE-2021-21393Mediummatrix-synapse: Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpointsGHSA-63RQ-P8FP-524QMediumsopel-modules.weather: Potential API key leakCVE-2021-21431Highsopel-plugins.channelmgnt: Improper Input Validation in sopel-plugins.channelmgntCVE-2021-28658MediumDjango: Directory Traversal in DjangoGHSA-FXQ4-R6MR-9X64LowFlask-Security-Too: CSRF Vuln can expose user's QRcodeCVE-2021-30185Highindico: Indico Tampering with links (e.g. password reset) in sent emailsCVE-2020-1740Mediumansible: Exposure of Sensitive Information to an Unauthorized Actor and Insecure Temporary File in AnsibleCVE-2020-28736HighPlone: Improper Restriction of XML External Entity Reference in PloneCVE-2020-28735HighPlone: SSRF attacks via tracebacks in PloneCVE-2020-28734HighPlone: Improper Restriction of XML External Entity Reference in PloneCVE-2020-7965Highwebargs: Cross-Site Request Forgery in WebargsCVE-2021-26559Highapache-airflow: Improper Access Control in Apache AirflowCVE-2020-28473Mediumbottle: bottle HTTP Request smugglingCVE-2021-3116Highproxy.py: Logic error in authentication in proxy.py

Stop the waste.
Protect your environment with Kodem.