PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2018-1000164Highgunicorn: Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headersCVE-2018-1000159Hightlslite-ng: tlslite-ng off-by-one error on mac checkingCVE-2018-6596Criticaldjango-anymail: Django-Anymail prone to a timing attackCVE-2018-0023Highjsnapy: JSNAPy allows unprivileged local users to alter files under the directoryCVE-2018-9856HighKotti: Kotti CSRF in the local roles implementationCVE-2018-1002150Criticalkoji: Koji hub call does not perform correct access checksCVE-2018-8097Criticaleve: Eve allows execution of arbitrary codeCVE-2018-7750Criticalparamiko: Paramiko not properly checking authentication before processing other requestsCVE-2018-6594Highpycrypto: Pycrypto generates weak key parametersCVE-2018-5773Mediummarkdown2: markdown2 is vulnerable to cross-site scriptingCVE-2016-9190HighPillow: Arbitrary code using "crafted image file" approach affecting PillowCVE-2017-5524MediumPlone: Plone Sandbox EscapeCVE-2018-8768Highnotebook: Jupyter Notebook file bypasses sanitization, executes JavaScript

Stop the waste.
Protect your environment with Kodem.