PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-45854Highmindsdb: MindsDB Deserialization of Untrusted Data vulnerabilityCVE-2024-45856Mediummindsdb: MindsDB Cross-site Scripting vulnerabilityCVE-2024-45853Highmindsdb: MindsDB Deserialization of Untrusted Data vulnerabilityCVE-2024-45857Highcleanlab: Cleanlab Deserialization of Untrusted Data vulnerabilityCVE-2024-45855Highmindsdb: MindsDB Deserialization of Untrusted Data vulnerabilityCVE-2024-45851Highmindsdb: MindsDB Eval Injection vulnerabilityCVE-2024-45852Highmindsdb: MindsDB Deserialization of Untrusted Data vulnerabilityCVE-2024-45847Highmindsdb: MindsDB Eval Injection vulnerabilityCVE-2024-45850Highmindsdb: MindsDB Eval Injection vulnerabilityCVE-2024-27320Highrefuel-autolabel: Refuel Autolab Eval Injection vulnerabilityCVE-2024-45846Highmindsdb: MindsDB Eval Injection vulnerabilityCVE-2024-27321Highrefuel-autolabel: Refuel Autolab Eval Injection vulnerabilityCVE-2024-45848Highmindsdb: MindsDB Eval Injection vulnerabilityCVE-2024-45849Highmindsdb: MindsDB Eval Injection vulnerabilityGHSA-RJC6-VM4H-85CGMediumaws-sam-cli: Sensitive Information Exposure Through Insecure Logging For Secrets Like Metadata.DockerBuildArgsGHSA-635V-PC42-FR74Mediumsagemaker-training: AWS SageMaker Training Toolkit logs CodeArtifact Authorization tokenCVE-2024-6091Criticalagpt: AutoGPT bypass of the shell commands denylist settingsCVE-2024-45595Mediumdtale: D-Tale vulnerable to Remote Code Execution through the Query input on Chart BuilderCVE-2024-39205Criticalpyload-ng: pyload-ng vulnerable to RCE with js2py sandbox escapeCVE-2024-45034Highapache-airflow: Apache Airflow vulnerable to Execution with Unnecessary PrivilegesCVE-2024-45498Highapache-airflow: Apache Airflow vulnerable to Improper Encoding or Escaping of OutputGHSA-GJ55-2XF9-67RQMediumjupyterlite-core: HTML injection in JupyterLite leading to DOM ClobberingCVE-2024-45758Criticalai.h2o:h2o-core: H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URLCVE-2024-24759Highmindsdb: MindsDB Vulnerable to Bypass of SSRF Protection with DNS RebindingCVE-2024-45314Mediumflask-appbuilder: Flask-AppBuilder's login form allows browser to cache sensitive fields

Stop the waste.
Protect your environment with Kodem.