PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-10903Highcryptography: PyCA Cryptography vulnerable to GCM tag forgeryCVE-2018-14505Criticalmitmproxy: Mitmweb in mitmproxy allows DNS Rebinding attacksCVE-2014-3539Criticalrope: Code injection in ropeCVE-2016-4009Criticalpillow: Pillow Integer overflow in ImagingResampleHorizontalCVE-2016-0775HighPillow: Pillow Buffer overflow in ImagingFliDecodeCVE-2016-2533Highpillow: Pillow buffer overflow in ImagingPcdDecodeCVE-2016-9189Mediumpillow: Pillow Integer overflow in Map.cCVE-2016-0740Mediumpillow: Pillow Buffer overflow in ImagingLibTiffDecodeCVE-2012-2921Highfeedparser: feedparser denial of service vulnerabilityCVE-2011-1949MediumPlone: Plone Cross-site Scripting vulnerabilityCVE-2011-0697MediumDjango: Cross-site scripting in djangoCVE-2011-1950Highplone.app.users: Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accountsCVE-2010-3082MediumDjango: Cross-site scripting in djangoCVE-2011-4136MediumDjango: Session manipulation in DjangoCVE-2012-5503HighPlone: Plone allows remote attackers to read hidden folder contentsCVE-2011-0698CriticalDjango: Directory traversal in DjangoCVE-2011-1157Mediumfeedparser: feedparser Cross-site Scripting vulnerabilityCVE-2012-5489HighZope2: Plone and Zope2 vulnerable to unauthorized access to restricted attributesCVE-2011-2528HighPlone: High severity vulnerability that affects Plone and Zope2CVE-2010-4535Mediumdjango: Improper date handling in DjangoCVE-2012-5486HighZope2: HTTP header injection in Plone and Zope2CVE-2011-1158Mediumfeedparser: feedparser Cross-site Scripting vulnerabilityCVE-2010-4534Highdjango: Improper query string handling in DjangoCVE-2011-4137HighDjango: Denial of service in djangoCVE-2010-1104MediumZope2: Moderate severity vulnerability that affects Zope2

Stop the waste.
Protect your environment with Kodem.