PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2012-5577Highkeyring: Incorrect Default Permissions in keyringCVE-2014-1938Mediumrply: Link Following in rplyCVE-2012-5578Highkeyring: Incorrect Default Permissions in keyringCVE-2013-2167Criticalpython-keystoneclient: Insufficient Verification of Data Authenticity in python-keystoneclientCVE-2014-8650Criticalrequests-kerberos: Improper Authentication in requests-kerberosCVE-2019-12413Mediumapache-superset: Users able to query database metadata in Apache SupersetCVE-2019-12414Mediumapache-superset: Users can view database names in Apache SupersetCVE-2020-1932Mediumapache-superset: Information disclosure in Apache SupersetCVE-2019-14864Mediumansible: Inclusion of Sensitive Information in Log Files and Improper Output Neutralization for Logs in AnsibleCVE-2020-6802Mediumbleach: XSS in Bleach when noscript and raw tag whitelistedCVE-2020-7471Criticaldjango: SQL injection in DjangoCVE-2020-5236Mediumwaitress: Catastrophic backtracking in regex allows Denial of Service in WaitressCVE-2020-5227Mediumfeedgen: Feedgen Vulnerable to XML Denial of Service AttacksCVE-2020-5215Lowtensorflow: Segmentation faultin TensorFlow when converting a Python string to `tf.float16`CVE-2020-5224Mediumdjango-user-sessions: Session key exposure through session list in Django User SessionsCVE-2019-19588Highvalidators: Uncontrolled resource consumption in validators Python packageCVE-2019-19844Criticaldjango: Django Potential account hijack via password reset formCVE-2019-16784HighPyInstaller: Local Privilege Escalation in PyInstallerCVE-2019-16789Mediumwaitress: HTTP Request Smuggling in Waitress: Invalid whitespace characters in headers (Follow-up)GHSA-M5FF-3WJ3-8PH4Highwaitress: HTTP Request Smuggling: Invalid whitespace characters in headers in WaitressCVE-2019-16792Criticalwaitress: HTTP Request Smuggling: Content-Length Sent Twice in WaitressCVE-2019-16786Mediumwaitress: HTTP Request Smuggling: Invalid Transfer-Encoding in WaitressCVE-2019-16785Mediumwaitress: HTTP Request Smuggling: LF vs CRLF handling in WaitressCVE-2014-7143Hightwisted: Python Twisted trustRoot is not respected in HTTP clientCVE-2019-16778Lowtensorflow: Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow

Stop the waste.
Protect your environment with Kodem.