PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-20325Highdefinitions: Code injection in Danijar DefinitionsCVE-2018-1000872Highpykmip: PyKMIP Denial of service vulnerabilityCVE-2018-1000814Highaiohttp-session: aiohttp-session creates non-expiring sessionsCVE-2018-1000843Highluigi: Cross-Site Request Forgery (CSRF) in LuigiCVE-2018-20133Criticalymlref: Code injection in ymlrefCVE-2018-16516Mediumflask-admin: Flask-Admin Cross-site Scripting vulnerabilityCVE-2013-7459Criticalpycrypto: Buffer Overflow in pycryptoCVE-2018-20060Criticalurllib3: Exposure of Sensitive Information to an Unauthorized Actor in urllib3CVE-2018-19443Hightryton: Session Fixation in TrytonCVE-2018-18920Highpy-evm: Py-EVM is vulnerable to arbitrary bytecode injectionCVE-2018-19352Mediumnotebook: Jupyter Notebook XSS via directory nameCVE-2018-19351Mediumnotebook: Jupyter Notebook XSS via untrusted notebooksCVE-2017-12612Highorg.apache.spark:spark-core_2.11: Apache Spark Deserialization of Untrusted Data vulnerabilityCVE-2018-8021Criticalsuperset: Deserialization of Untrusted Data in supersetCVE-2014-1927Highpython-gnupg: python-gnupg's shell_quote function does not properly quote stringsCVE-2013-7323Highpython-gnupg: python-gnupg allows context-dependent attackers to execute arbitrary commands via shell metacharactersCVE-2014-1928Highpython-gnupg: python-gnupg's shell_quote function does not properly escape charactersCVE-2014-1929Criticalpython-gnupg: python-gnupg vulnerable to shell injectionCVE-2015-5159Highkdcproxy: Improper Input Validation in kdcproxyCVE-2018-18074Highrequests: Insufficiently Protected Credentials in RequestsCVE-2018-14572Highconference-scheduler-cli: conference-scheduler-cli Arbitrary Code ExecutionCVE-2015-3908Highansible: Ansible does not verify that the server hostname matches a domain name in certificatesCVE-2016-3096Highansible: Link Following in ansibleCVE-2013-2233Criticalansible: Ansible fails to cache SSH host keysCVE-2016-8647Mediumansible: Improper Input Validation in ansible

Stop the waste.
Protect your environment with Kodem.