PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2014-1933MediumPillow: Pillow Temporary file name leakageCVE-2018-21233Hightensorflow: Out-of-bounds read in TensorFlow possibly causing disclosure of the contents of process memory.CVE-2020-11054Lowqutebrowser: Incorrect Provision of Specified Functionality in qutebrowserCVE-2020-11037Mediumwagtail: Potential Observable Timing Discrepancy in WagtailCVE-2019-12398Mediumapache-airflow: XSS in Apache AirflowCVE-2020-5390Highpysaml2: Improper Verification of Cryptographic Signature in PySAML2CVE-2019-1000007Highaioxmpp: Depth counting error in guard() leading to multiple potential security issues in aioxmppCVE-2020-11888Mediummarkdown2: XSS in python-markdown2CVE-2020-11010Mediumtortoise-orm: SQL injection in Tortoise ORMCVE-2020-11001Mediumwagtail: Possible XSS attack in WagtailCVE-2019-19911Highpillow: Uncontrolled Resource Consumption in PillowCVE-2020-5313HighPillow: Out-of-bounds Read in PillowCVE-2019-14859Criticalecdsa: Improper Verification of Cryptographic Signature in Pure-Python ECDSACVE-2020-10108CriticalTwisted: Improper Input Validation in TwistedCVE-2020-10109CriticalTwisted: HTTP Request Smuggling in TwistedCVE-2020-6817Highbleach: regular expression denial-of-service (ReDoS) in BleachGHSA-MR6R-MVW4-736GLowvyper: Vyper interfaces returning integer types less than 256 bits can be manipulated if uint256 is usedCVE-2020-5252Mediumsafety: Malicious package may avoid detection in python auditingCVE-2020-6816Mediumbleach: Bleach vulnerable to mutation XSS via whitelisted math or svg and raw tagCVE-2020-5262Criticaleasybuild-framework: GitHub personal access token leaking into temporary EasyBuild (debug) logsCVE-2020-10571Criticalpsd-tools: Potential buffer overflow in psd-toolsCVE-2020-5240Mediumwagtail-2fa: 2FA bypass through deleting devices in wagtail-2faCVE-2009-5042Criticaldocutils: python-docutils allows insecure usage of temporary filesCVE-2019-18874Highpsutil: Double Free in psutilCVE-2019-10138Highnovajoin: Improper Access Control in novajoin

Stop the waste.
Protect your environment with Kodem.