PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-21241HighFlask-Security-Too: CSRF can expose users authentication tokenCVE-2020-27783Mediumlxml: lxml vulnerable to Cross-site ScriptingCVE-2021-21236HighCairoSVG: Regular Expression Denial of Service in CairoSVGCVE-2020-26275Mediumjupyter-server: Jupyter Server open redirect vulnerabilityCVE-2020-26263Hightlslite-ng: RSA weakness in tslite-ngCVE-2020-17513Mediumapache-airflow: SSRF vulnerability in Apache AirflowCVE-2020-17511Lowapache-airflow: Apache Airflow logs passwords in plaintextCVE-2020-26271Mediumtensorflow: Heap out of bounds access in MakeEdge in TensorFlowCVE-2020-26270Mediumtensorflow: CHECK-fail in LSTM with zero-length input in TensorFlowCVE-2020-26268Mediumtensorflow: Write to immutable memory region in TensorFlowCVE-2020-26267Lowtensorflow: Lack of validation in data format attributes in TensorFlowCVE-2020-26266Mediumtensorflow: Uninitialized memory access in TensorFlowCVE-2020-26257Highmatrix-synapse: Denial of service attack via incorrect parameters in Matrix SynapseCVE-2020-26261Highjupyterhub-systemdspawner: user-readable api tokens in systemd units for JupyterHubCVE-2020-26249Mediumred-dashboard: Remote Code Execution (RCE) Exploit on Cross Site Scripting (XSS) VulnerabilityCVE-2020-26244Highoic: Multiple cryptographic issues in Python oicCVE-2020-29128Highpetl: XXE in petlGHSA-47QG-Q58V-7VRPLowamundsen-frontend: UNEDITABLE_SCHEMAS and UNEDITABLE_TABLE_DESCRIPTION_MATCH_RULES not respected by frontend service backendCVE-2020-26250Highoauthenticator: Base class whitelist configuration ignored in OAuthenticatorCVE-2020-26243Mediumnanopb: Memory leak in NanopbGHSA-74HV-QJJQ-H7G5Lowdatasette-graphql: datasette-graphql leaks details of the schema of private database filesCVE-2020-26890Highmatrix-synapse: Denial of service attack due to invalid JSONGHSA-MJCR-RQJG-RHG3Criticaldatasette-indieauth: Implementation trusts the "me" field returned by the authorization server without verifying itCVE-2020-26232Mediumjupyter-server: Open redirect in Jupyter ServerCVE-2020-26215Lownotebook: Open redirect in Jupyter Notebook

Stop the waste.
Protect your environment with Kodem.