PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-52303Mediumaiohttp: aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed methodCVE-2024-47533Criticalcobbler: cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changesCVE-2024-11319Mediumdjango-cms: django CMS Cross-Site Scripting (XSS)CVE-2023-6110Mediumpython-openstackclient: OpenStack improperly deletes access rulesCVE-2021-3988Mediumcalibreweb: Cross-site Scripting (XSS) - DOM in janeczku/calibre-webCVE-2021-3987Mediumcalibreweb: Improper Access Control in janeczku/calibre-webCVE-2021-3986Mediumcalibreweb: Generation of Error Message Containing Sensitive Information in janeczku/calibre-webCVE-2024-45784Highairflow: Apache Airflow: Sensitive configuration values are not masked in the logs by defaultCVE-2024-52524Mediumgiskard: ReDoS in giskard's transformation.py (GHSL-2024-324)CVE-2024-4311Mediumzenml: Missing ratelimit on passwrod resets in zenmlCVE-2023-34049Mediumsalt: Salt preflight script could be attacker controlledCVE-2024-43598Highlightgbm: LightGBM Remote Code Execution VulnerabilityCVE-2024-11079Lowansible-core: Ansible-Core vulnerable to content protections bypassCVE-2024-27530Highpywasm3: pywasm3 contains a Use-After-Free in ForEachModuleCVE-2024-27528Highpywasm3: pywasm3 has an Invalid Memory Read, Leading to DoS and Potential Code ExecutionCVE-2024-27529Mediumgithub.com/shareup/wasm-interpreter-apple: wasm3 uncontrolled memory allocation vulnerabilityCVE-2024-50378Lowapache-airflow: Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent DataCVE-2024-51998Highchangedetection.io: changedetection.io path traversal using file URI scheme without supplying hostnameCVE-2024-51751Mediumgradio: Gradio vulnerable to arbitrary file read with File and UploadButton componentsCVE-2024-10082Criticalcodechecker: codechecker authentication method confusion vulnerability allows logging in as the built-in root user from an external serviceCVE-2024-10081Criticalcodechecker: codechecker vulnerable to authentication bypass when using specifically crafted URLsCVE-2024-9902Mediumansible-core: ansible-core Incorrect Authorization vulnerabilityCVE-2024-51493MediumOctoPrint: OctoPrint has API key access in settings without reauthenticationCVE-2024-49377MediumOctoPrint: OctoPrint Vulnerable to Reflected XSS in Jinja2 TemplatesCVE-2024-48061Mediumlangflow: Langflow vulnerable to remote code execution

Stop the waste.
Protect your environment with Kodem.