PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2016-8614Highansible: Ansible apt_key module does not properly verify key fingerprintCVE-2018-10855Highansible: Ansible exposes sensitive data in log files and on the terminalCVE-2016-8628Criticalansible: Ansible fails to properly sanitize fact variables sent from the Ansible controllerCVE-2016-9587Criticalansible: Ansible is vulnerable to an improper input validation in Ansible's handling of data sent from client systemsCVE-2018-17175Mediummarshmallow: In marshmallow library the schema "only" option treats an empty list as implying no "only" optionCVE-2018-1000807Highpyopenssl: PyOpenSSL Use-After-Free vulnerabilityCVE-2018-1000808Highpyopenssl: Pyopenssl Incorrect Memory ManagementCVE-2018-1000805Highparamiko: Paramiko Authentication Bypass vulnerabilityCVE-2018-10895Highqutebrowser: Qutebrowser CSRF VulnerabilityCVE-2018-14574Mediumdjango: Django open redirectCVE-2018-6188Highdjango: Django vulnerable to information leakage in AuthenticationFormCVE-2018-16984Mediumdjango: Django allows unprivileged users to read the password hashes of arbitrary accountsCVE-2018-1000518Highwebsockets: websockets is vulnerable to denial of service by memory exhaustionCVE-2018-1000559Mediumqutebrowser: Qutebrowser XSS VulnerabilityCVE-2018-1000523Hightopydo: Topydo Improper Input Validation vulnerabilityCVE-2018-1000519Highaiohttp-session: aiohttp-session Session Fixation vulnerabilityCVE-2018-13796Mediummailman: Moderate severity vulnerability that affects mailmanCVE-2017-7481Criticalansible: Ansible fails to properly mark lookup-plugin results as unsafeCVE-2018-16407Mediummayan-edms: Moderate severity vulnerability that affects mayan-edmsCVE-2018-16406Mediummayan-edms: Moderate severity vulnerability that affects mayan-edmsCVE-2018-16405Mediummayan-edms: mayan-edms Cross-site Scripting vulnerabilityCVE-2018-15560Highpycryptodome: PyCryptodome integer overflow vulnerabilityCVE-2018-1000656Highflask: Flask is vulnerable to Denial of Service via incorrect encoding of JSON dataCVE-2011-2765Highpyro: Pyro mishandles pid files in temporary directory locations and opening the pid file as rootCVE-2016-8640Criticalpycsw: SQL Injection in pycsw

Stop the waste.
Protect your environment with Kodem.