PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-48050Highagentscope: AgentScope uses `eval`CVE-2024-48052Mediumgradio: gradio Server Side Request Forgery vulnerabilityCVE-2024-51734MediumAccessControl: Access control vulnerable to user data deletion by anonynmous usersCVE-2024-51483Mediumchangedetection.io: changedetection.io Path TraversalCVE-2024-42835Highlangflow: langflow has vulnerability in PythonCodeTool componentCVE-2024-8309Lowlangchain: Langchain SQL Injection vulnerabilityCVE-2024-6581Mediumlollms: Lollms vulnerable to Cross-site ScriptingCVE-2024-49768Criticalwaitress: Waitress has request processing race condition in HTTP pipelining with invalid first requestCVE-2024-49769Highwaitress: Waitress vulnerable to DoS leading to high CPU usage/resource exhaustionCVE-2024-49771Mediumnet.sf.mpxj:mpxj: MPXJ has a Potential Path Traversal VulnerabilityCVE-2024-47821Highpyload-ng: pyLoad vulnerable to remote code execution by download to /.pyload/scripts using /flashgot APICVE-2024-49767MediumQuart: Werkzeug possible resource exhaustion when parsing file data in formsCVE-2024-49766MediumWerkzeug: Werkzeug safe_join not safe on WindowsCVE-2024-49750Mediumsnowflake-connector-python: The Snowflake Connector for Python stores sensitive data in logsGHSA-3VPC-4P9P-47HCHighcurl-cffi: curl_cffi bundles a version of libcurl affected by High Severity vulnerabilityCVE-2024-10073Mediumflair: Flair allows arbitrary code executionCVE-2024-25112Mediumexiv2: Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoderCVE-2024-24826Mediumexiv2: Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoderCVE-2024-21272Highmysql-connector-python: MySQL Connector/Python connector takeover vulnerabilityCVE-2024-47874Highstarlette: Starlette Denial of service (DoS) via multipart/form-dataCVE-2024-32651Criticalchangedetection.io: changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command ExecutionCVE-2024-48911MediumOpenCanary: OpenCanary Executes Commands From Potentially Writable Config FileCVE-2024-6985Mediumlollms: Lord of Large Language Models (LoLLMs) path traversal vulnerability in the api open_personality_folder endpointCVE-2024-6971Lowlollms: Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.pyGHSA-26JH-R8G2-6FPRLowgradio: Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list

Stop the waste.
Protect your environment with Kodem.