PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-9774Mediumpython-sql: python-sql SQL injection vulnerabilityCVE-2024-12745Highredshift_connector: Amazon Redshift Python Connector vulnerable to SQL InjectionCVE-2024-9427Mediumkoji: Koji Cross-site ScriptingCVE-2024-56326Mediumjinja2: Jinja has a sandbox breakout through indirect reference to format methodCVE-2024-56201Mediumjinja2: Jinja has a sandbox breakout through malicious filenamesCVE-2024-56327Highpyrage: pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary executionCVE-2024-56142Mediumpghoard: PGHoard Path Traversal vulnerabilityCVE-2024-55890Mediumdtale: D-Tale allows Remote Code Execution through the Custom Filter InputCVE-2024-21543Highdjoser: djoser Authentication BypassCVE-2024-55633Highapache-superset: Apache Superset: SQLLab Improper readonly query validation allows unauthorized write accessCVE-2024-55587Highpython-libarchive: python-libarchive directory traversalCVE-2024-55655Lowsigstore: sigstore has insufficient validation of integration timestamp during verificationCVE-2024-21542Highluigi: luigi Arbitrary File Write via Archive Extraction (Zip Slip)CVE-2024-46455Mediumunstructured: unstructured XML External Entity (XXE)CVE-2024-53947Lowapache-superset: Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functionsCVE-2024-53949Highapache-superset: Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabledCVE-2024-53948Mediumapache-superset: Apache Superset: Error verbosity exposes metadata in analytics databasesCVE-2024-53908HighDjango: Django SQL injection in HasKey(lhs, rhs) on OracleCVE-2024-53907MediumDjango: Django denial-of-service in django.utils.html.strip_tags()CVE-2024-39163Highpyspider: pyspider Cross-Site Request Forgery (CSRF) via the Flask endpointsCVE-2024-53999Mediummobsf: Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" FunctionalityCVE-2024-53867Mediummatrix-synapse: Synapse Matrix has a partial room state leak via Sliding SyncCVE-2024-53863Highmatrix-synapse: Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decodersCVE-2024-52815Highmatrix-synapse: Synapse allows a a malformed invite to break the invitee's `/sync`CVE-2024-52805Highmatrix-synapse: Synapse allows unsupported content types to lead to memory exhaustion

Stop the waste.
Protect your environment with Kodem.