PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-19118HighDjango: Django allows unintended model editingCVE-2019-19275Hightyped-ast: typed-ast Out-of-bounds ReadCVE-2019-19274Hightyped-ast: typed-ast Out-of-bounds ReadCVE-2019-16766Mediumwagtail-2fa: 2FA bypass in Wagtail through new device pathCVE-2019-12417Mediumairflow: Apache Airflow vulnerable to XSS and local file disclosureCVE-2019-17206Criticalrediswrapper: Uncontrolled deserialization of a pickled object in rediswrapper allows attackers to execute arbitrary scriptsCVE-2019-19010Criticallimnoria: Eval injection in Supybot/LimnoriaCVE-2018-21030Mediumnotebook: Cross-site scripting in Jupyter NotebookCVE-2017-18638Highgraphite-web: graphite.composer.views.send_email vulnerable to SSRFCVE-2019-17400Highunoconv: Server-Side Request Forgery in unoconvCVE-2019-16865Highpillow: DOS attack in Pillow when processing specially crafted image filesGHSA-67CX-RHHQ-MFHQHighindico: High severity vulnerability that affects indicoCVE-2019-14853Highecdsa: ecdsa Denial of Service vulnerability in signature verification and signature malleabilityCVE-2019-11457Highdjango-crm: Cross-Site Request Forgery in MicroPyramid Django CRMCVE-2019-10751Highhttpie: Open Redirect in httpieCVE-2019-15486Mediumdjango-js-reverse: Cross-site Scripting in django-js-reverseCVE-2019-14751Highnltk: NLTK Vulnerable To Path TraversalCVE-2018-20858Mediumrecommender-xblock: Cross-site scripting in recommender-xblockCVE-2019-14806Highwerkzeug: Pallets Werkzeug Insufficient EntropyCVE-2019-12855Criticaltwisted: Improper Certificate Validation in TwistedCVE-2019-14234CriticalDjango: SQL Injection in DjangoCVE-2019-10099Highorg.apache.spark:spark-core_2.11: Sensitive data written to disk unencrypted in SparkCVE-2019-14233HighDjango: Django Denial-of-service in strip_tags()CVE-2019-14235HighDjango: Uncontrolled Recursion in DjangoCVE-2019-14232HighDjango: Django Denial-of-service in django.utils.text.Truncator

Stop the waste.
Protect your environment with Kodem.