PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2019-9710Highwebargs: Webargs mishandles concurrent JSON parsingCVE-2018-20244Mediumapache-airflow: Apache Airflow vulnerable to Stored XSSCVE-2019-6975HighDjango: Uncontrolled Memory Consumption in DjangoCVE-2017-18361Highcolander: Pylons Colander Denial of Service vulnerabilityCVE-2018-11760Mediumpyspark: Pyspark User Impersonation VulnerabilityCVE-2019-6802Mediumpypiserver: CRLF Injection in pypiserverCVE-2018-20245Highapache-airflow: Improper Certificate Validation in Apache AirflowCVE-2017-17835Highapache-airflow: Cross-Site Request Forgery (CSRF) in Apache AirflowCVE-2017-17836Criticalapache-airflow: Apache Airflow vulnerable to XSSCVE-2017-15720Highapache-airflow: Improper Input Validation in Apache Airflow resulting in Remote Code ExecutionCVE-2017-1002157Criticalmodulemd: modulemd uses an unsafe function for processing externally provided dataCVE-2019-3498HighDjango: Improper Input Validation in DjangoCVE-2018-1000809HighprivacyIDEA: privacyIDEA Improper Input Validation vulnerabilityCVE-2017-12794MediumDjango: Django vulnerable to XSS on 500 pagesCVE-2017-7233MediumDjango: Django open redirect and possible XSS attack via user-supplied numeric redirect URLsCVE-2017-7234Mediumdjango: Django open redirectCVE-2018-7536MediumDjango: Django denial-of-service possibility in urlize and urlizetrunc template filtersCVE-2018-7537Lowdjango: Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filtersCVE-2017-0906Criticalrecurly: Recurly vulnerable to SSRFCVE-2017-16876Mediummistune: mistune Cross-site scripting (XSS) vulnerabilityCVE-2017-1000484Mediumplone: Plone Open RedirectCVE-2018-7753Criticalbleach: Bleach URI Scheme Restriction BypassCVE-2017-5934Mediummoin: Moderate severity vulnerability that affects moinCVE-2017-18342CriticalPyYAML: PyYAML insecurely deserializes YAML strings leading to arbitrary code executionCVE-2019-3575Highsqla-yaml-fixtures: sqla-yaml-fixtures is vulnerable to Code Injection

Stop the waste.
Protect your environment with Kodem.