PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-10055Hightensorflow: Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlowCVE-2019-9635Hightensorflow: NULL Pointer Dereference in Google TensorFlowCVE-2018-7575Criticaltensorflow: Integer Overflow or Wraparound in Google TensorFlowCVE-2019-11358Mediumjquery-rails: XSS in jQuery as used in Drupal, Backdrop CMS, and other productsCVE-2018-8825Hightensorflow: Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlowCVE-2018-7576Hightensorflow: Null pointer dereference in TensorFlow leads to exploitationCVE-2015-1326Highpython-dbusmock: Improper Input Validation in python-dbusmockCVE-2019-11324Highurllib3: Improper Certificate Validation in urllib3CVE-2019-0229Highapache-airflow: Apache Airflow vulnerable to CSRF AttacksCVE-2019-7164CriticalSQLAlchemy: SQLAlchemy vulnerable to SQL Injection via order_by parameterCVE-2019-7548CriticalSQLAlchemy: SQLAlchemy is vulnerable to SQL Injection via group_by parameter CVE-2019-3828Lowansible: Ansible Path Traversal vulnerabilityCVE-2019-0216Mediumapache-airflow: Apache Airflow vulnerable to Stored XSSCVE-2019-10868Hightrytond: Tryton Improper Access ControlCVE-2019-10906HighJinja2: Jinja2 sandbox escape via string formattingCVE-2016-10745HighJinja2: Jinja2 sandbox escape vulnerabilityCVE-2019-10856Mediumnotebook: Jupyter Notebook open redirect vulnerabilityCVE-2019-10904Mediumroundup: Moderate severity vulnerability that affects roundupCVE-2018-12680HighCoAPthon: CoAPthon DoS due to ExceptionsCVE-2018-12679HighCoAPthon3: CoAPthon3 vulnerable to Deserialization of Untrusted DataCVE-2019-10255Mediumnotebook: Open Redirect vulnerability in jupyterhub and notebookCVE-2019-5729Criticalsplunk-sdk: splunk-sdk does not properly verify untrusted TLS server certificatesCVE-2019-6690Highpython-gnupg: Improper Input Validation python-gnupgCVE-2019-7539Criticalipycache: ipycache is vulnerable to Code InjectionCVE-2018-1334Mediumorg.apache.spark:spark-core_2.10: Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark

Stop the waste.
Protect your environment with Kodem.