PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-26759Criticalclickhouse-driver: Arbitrary code execution in clickhouse-driverCVE-2020-10684Mediumansible: Code Injection, Race Condition, and Execution with Unnecessary Privileges in AnsibleCVE-2020-10685Mediumansible: Exposure of Resource to Wrong Sphere and Insecure Temporary File in AnsibleCVE-2020-1735Mediumansible: Path Traversal in AnsibleCVE-2020-1753Mediumansible: Insertion of Sensitive Information into Log File, Invocation of Process Using Visible Sensitive Information, and Exposure of Sensitive…CVE-2020-1739Lowansible: Exposure of Sensitive Information to an Unauthorized Actor in AnsibleCVE-2021-21423Highprojen: Rebuild-bot workflow may allow unauthorised repository modificationsCVE-2021-21416Lowdjango-registration: Potential sensitive information disclosed in error reportsCVE-2021-25291HighPillow: Out of bounds read in PillowCVE-2021-25292MediumPillow: Regular Expression Denial of Service (ReDoS) in PillowCVE-2021-25290Highpillow: Out-of-bounds Write in PillowCVE-2021-25293HighPillow: Out of bounds read in PillowCVE-2021-25289Criticalpillow: Out of bounds write in PillowCVE-2021-27291HighPygments: Pygments vulnerable to Regular Expression Denial of Service (ReDoS)CVE-2020-28463Highreportlab: Server-side Request Forgery (SSRF) via img tags in reportlabCVE-2021-21333Mediummatrix-synapse: HTML injection in email and account expiry notificationsCVE-2021-21332Mediummatrix-synapse: Cross-site scripting (XSS) vulnerability in the password reset endpointCVE-2020-14343CriticalPyYAML: Improper Input Validation in PyYAMLCVE-2020-13757Highrsa: Python-RSA decryption of ciphertext leads to DoSCVE-2021-21377Mediumomero-web: OMERO webclient does not validate URL redirects on login or switching group.CVE-2021-21376Highomero-web: OMERO.web exposes some unnecessary session information in the pageCVE-2021-28957Mediumlxml: lxml vulnerable to Cross-Site Scripting CVE-2020-25626Mediumdjangorestframework: Cross-site Scripting (XSS) in Django REST FrameworkCVE-2020-35681Highchannels: Django Channels leakage of session identifiers using legacy AsgiHandlerCVE-2020-28493Mediumjinja2: Regular Expression Denial of Service (ReDoS) in Jinja2

Stop the waste.
Protect your environment with Kodem.