PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-37303Mediummatrix-synapse: Synapse's unauthenticated writes to the media repository allow planting of problematic contentCVE-2024-37302Highmatrix-synapse: Synapse denial of service through media disk space consumptionCVE-2024-53981Highpython-multipart: Denial of service (DoS) via deformation `multipart/form-data` boundaryCVE-2024-53865Mediumzhmcclient: Python package "zhmcclient" stores passwords in clear text in its HMC and API logsCVE-2024-53861LowPyJWT: PyJWT Issuer field partial matches allowedCVE-2024-53848Mediumcheck-jsonschema: check-jsonschema default caching for remote schemas allows for cache confusionCVE-2024-39162Mediumpyspider: pyspider Cross-site Scripting vulnerabilityCVE-2024-52008Lowethyca-fides: Password Policy Bypass Vulnerability in Fides Webserver User Accept Invite APIGHSA-486G-47CC-8WXFHighaiocpa: aiocpa contains credential harvesting codeCVE-2024-52787Mediumlibre-chat: libre-chat Path Traversal vulnerabilityCVE-2024-27134Highmlflow: MLflow's excessive directory permissions allow local privilege escalationCVE-2024-53916Mediumneutron: OpenStack Neutron can use an incorrect ID during policy enforcementCVE-2024-53899Highvirtualenv: virtualenv allows command injection through activation scripts for a virtual environmentCVE-2024-11392Hightransformers: Deserialization of Untrusted Data in Hugging Face TransformersCVE-2024-11393Hightransformers: Deserialization of Untrusted Data in Hugging Face TransformersCVE-2024-11394Hightransformers: Deserialization of Untrusted Data in Hugging Face TransformersCVE-2024-53253Mediumsentry: Sentry improper error handling leaks Application Integration Client SecretCVE-2024-52804Hightornado: Tornado has an HTTP cookie parsing DoS vulnerabilityCVE-2023-40017Highgeonode: GeoNode Server Side Request forgeryCVE-2024-52803Highllamafactory: LLama Factory Remote OS Command Injection VulnerabilityCVE-2024-52581Highlitestar: Litestar allows unbounded resource consumption (DoS vulnerability) CVE-2024-11404Mediumdjango-filer: Django Filer Unrestricted Upload of File with Dangerous TypeCVE-2024-11406Mediumdjangocms-attributes-field: django CMS Attributes Field Cross-site ScriptingCVE-2024-52595Highlxml-html-clean: HTML Cleaner allows crafted scripts in special contexts like svg or math to pass throughCVE-2024-52304Mediumaiohttp: aiohttp allows request smuggling due to incorrect parsing of chunk extensions

Stop the waste.
Protect your environment with Kodem.