PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2011-4140HighDjango: Django Cross-Site Request Forgery vulnerabilityCVE-2012-6661HighZope2: Plone and Zope2 do not reseed pseudo-random number generatorCVE-2011-0696HighDjango: Cross-site request forgery in DjangoCVE-2012-5507HighZope2: Plone and Zope2 affected by Race ConditionCVE-2011-1948MediumProducts.PasswordResetTool: Cross-site scripting in Products.CMFPlone and Products.PasswordResetToolCVE-2011-4462HighPlone: Plone Denial of Service vulnerabilityCVE-2011-4103Criticaldjango-piston: Django-piston and Django-tastypie do not properly deserialize YAML dataCVE-2011-1156Highfeedparser: feedparser denial of service vulnerabilityCVE-2009-0662MediumProducts.PlonePAS: Moderate severity vulnerability that affects Products.PlonePASCVE-2017-16763Criticalconfire: Unsafe deserialization in confireCVE-2017-1000246Mediumpysaml2: Pysaml2 improperly initializes encryption vectorCVE-2016-10149Highpysaml2: Pysaml2 does not sanitize XML responsesCVE-2017-2810Criticaltablib: Loaded Databook of Tablib prone to python insertion resulting in command executionCVE-2017-0359Criticaldiffoscope: Diffoscope may write to arbitrary locations due to an untrusted archiveCVE-2017-1000433Criticalpysaml2: pysaml2 Improper Authentication vulnerabilityCVE-2017-16618Criticalowlmixin: Unsafe deserialization in owlmixinCVE-2017-16615CriticalMLAlchemy: Unsafe deserialization in MLAlchemyCVE-2017-7235Highcfscrape: cfscrape Improper Input Validation vulnerabilityCVE-2017-6591Mediumdjango-epiceditor: django-epiceditor vulnerable to XSS in form fieldCVE-2017-1000001HighFedMsg: FedMsg not properly completing message validationCVE-2017-9462Highmercurial: Mercurial has Incorrect Permission Assignment for Critical ResourceCVE-2017-1002150Mediumpython-fedora: python-fedora vulnerable to an open redirect resulting in loss of CSRF protectionCVE-2017-16764Criticaldjango_make_app: django_make_app is vulnerable to Code InjectionCVE-2017-2809Highansible-vault: Code injection in ansibleCVE-2017-2592Highoslo.middleware: oslo.middleware Information Disclosure vulnerability

Stop the waste.
Protect your environment with Kodem.