PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-10156Mediumansible: Exposure of Sensitive Information to an Unauthorized Actor in ansibleCVE-2019-13611Highpython-engineio: python-engineio vulnerable to Cross-Site Request Forgery (CSRF) CVE-2018-19800Criticalaubio: aubio Buffer Overflow vulnerabilityCVE-2018-19802Highaubio: Aubio is vulnerable to a NULL pointer dereference in new_aubio_notes functionCVE-2018-19801Highaubio: Aubio is vulnerable to a NULL pointer dereference in new_aubio_filterbankCVE-2019-1010268Criticalladon: Improper Restriction of XML External Entity Reference in ladonCVE-2019-1010142Highscapy: Infinite Loop in scapyCVE-2019-1010083Highflask: Pallets Project Flask is vulnerable to Denial of Service via Unexpected memory usageCVE-2019-1010017Highpython-libnmap: XML Injection in python-libnmapCVE-2019-1020005Mediuminvenio-communities: Cross-site Scripting in invenio-communitiesCVE-2019-1020019Mediuminvenio-previewer: Cross-site Scripting in invenio-previewerCVE-2019-1020003Mediuminvenio-records: Cross-site scripting invenio-recordsCVE-2019-1020006Mediuminvenio-app: Invenio-App vulnerable to host header injection attackCVE-2017-11427Highpython-saml: Python-saml allows manipulation of SAML data without invalidation of cryptographic signatureCVE-2016-6581Highhpack: HPACK Denial of Service vulnerability (HPACK Bomb)CVE-2015-5306Criticalpython-ironic-inspector-client: Injection vulnerability that affects ironic-discoverdCVE-2015-5143Highdjango: Django Denial-of-service by filling session storeCVE-2019-16791Highpostfix-mta-sts-resolver: postfix-mta-sts-resolver Algorithm Downgrade vulnerabilityCVE-2019-12781MediumDjango: Django Incorrect HTTP detection with reverse-proxy connecting via HTTPSCVE-2019-13177Criticaldjango-rest-registration: Improper Verification of Cryptographic Signature in django-rest-registrationCVE-2019-12308MediumDjango: Django Cross-site Scripting in AdminURLFieldWidgetCVE-2019-12387Mediumtwisted: Twisted CRLF InjectionCVE-2019-12761Highpyxdg: Code Injection in PyXDGCVE-2019-12300Criticalbuildbot: Improper Authentication in BuildbotCVE-2018-7577Hightensorflow: Improper Input Validation in Google TensorFlow

Stop the waste.
Protect your environment with Kodem.