PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-Q6J3-C4WC-63VWMediumdatasette: CSRF tokens leaked in URL by canned query formCVE-2020-7695Highuvicorn: HTTP response splitting in uvicornCVE-2020-7694Highuvicorn: Log injection in uvicornCVE-2020-10177HighPillow: Out-of-bounds reads in PillowCVE-2020-10379HighPillow: Buffer overflow in PillowCVE-2020-10994HighPillow: Out-of-bounds reads in PillowCVE-2020-11538CriticalPillow: Out-of-bounds read in PillowCVE-2020-15120Mediumihatemoney: Authorization Bypass in I hate moneyCVE-2020-9485Mediumapache-airflow: Stored XSS in Apache AirflowCVE-2020-11982Criticalapache-airflow: Insecure default config of Celery worker in Apache AirflowCVE-2020-11981Criticalapache-airflow: Command injection via Celery broker in Apache AirflowCVE-2020-11978Highapache-airflow: Remote code execution (RCE) in Apache AirflowCVE-2020-11983Mediumapache-airflow: Multiple stored XSS in RBAC Admin screens in Apache AirflowCVE-2020-15110Highjupyterhub-kubespawner: Possible pod name collisions in jupyterhub-kubespawnerCVE-2020-15118Highwagtail: Cross-Site Scripting in WagtailCVE-2020-15105Mediumdjango-two-factor-auth: User passwords are stored in clear text in the Django sessionGHSA-6R3C-8XF3-GGRRMediumdjango-sendfile2: Directory traversal outside of SENDFILE_ROOT in django-sendfile2CVE-2020-4071Mediumdjango-basic-auth-ip-whitelist: Timing attack on django-basic-auth-ip-whitelistCVE-2020-11090Criticalindy-node: Uncontrolled Resource Consumption in Indy NodeCVE-2020-13596MediumDjango: XSS in DjangoCVE-2020-13254HighDjango: Data leakage via cache key collision in DjangoCVE-2020-10594Criticaldrf-jwt: Django Rest Framework jwt allows obtaining new token from notionally invalidated tokenCVE-2019-10682Highdjango-nopassword: django-nopassword stores secrets in cleartext CVE-2020-9402HighDjango: SQL injection in DjangoCVE-2020-11078Mediumhttplib2: CRLF injection in httplib2

Stop the waste.
Protect your environment with Kodem.