pypi
746,914 packages · pypi.org
High Security Advisories in pypi Clear Filters
High
10 months ago
changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal
pypi
changedetection.io
High
10 months ago
Amazon Redshift Python Connector vulnerable to SQL Injection
pypi
redshift_connector
High
11 months ago
pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
pypi
pyrage
High
11 months ago
Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
pypi
apache-superset
High
11 months ago
Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
pypi
apache-superset
High
11 months ago
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
pypi
matrix-synapse
High
11 months ago
Synapse allows a a malformed invite to break the invitee's `/sync`
pypi
matrix-synapse
High
11 months ago
Synapse allows unsupported content types to lead to memory exhaustion
pypi
matrix-synapse
High
11 months ago
Synapse denial of service through media disk space consumption
pypi
matrix-synapse
High
11 months ago
Denial of service (DoS) via deformation `multipart/form-data` boundary
pypi
python-multipart
High
11 months ago
MLflow's excessive directory permissions allow local privilege escalation
pypi
mlflow
High
11 months ago
virtualenv allows command injection through activation scripts for a virtual environment
pypi
virtualenv
High
12 months ago
Litestar allows unbounded resource consumption (DoS vulnerability)
pypi
starlite, litestar
High
12 months ago
HTML Cleaner allows crafted scripts in special contexts like svg or math to pass through
pypi
lxml-html-clean
High
12 months ago
Apache Airflow: Sensitive configuration values are not masked in the logs by default
pypi
airflow
High
12 months ago
changedetection.io path traversal using file URI scheme without supplying hostname
pypi
changedetection.io
High
about 1 year ago
Waitress vulnerable to DoS leading to high CPU usage/resource exhaustion
pypi
waitress
High
about 1 year ago
pyLoad vulnerable to remote code execution by download to /.pyload/scripts using /flashgot API
pypi
pyload-ng
High
about 1 year ago
curl_cffi bundles a version of libcurl affected by High Severity vulnerability
pypi
curl-cffi
High
about 1 year ago
MySQL Connector/Python connector takeover vulnerability
pypi
mysql-connector-python
High
about 1 year ago
Gradio uses insecure communication between the FRP client and server
pypi
gradio
High
about 1 year ago
Gradio has a race condition in update_root_in_config may redirect user traffic
pypi
gradio
High
about 1 year ago
Gradios's CORS origin validation is not performed when the request has a cookie
pypi
gradio
High
about 1 year ago
RestrictedPython information leakage via `AttributeError.obj` and the `string` module
pypi
RestrictedPython
High
about 1 year ago
Heap-based Buffer Overflow in sqlite-vec
cargo, rubygems, npm, pypi
sqlite-vec
High
about 1 year ago
Mesop has a local file Inclusion via static file serving functionality
pypi
mesop
High
about 1 year ago
Sentry improperly authorizes deletion of user issue alert notifications
pypi
sentry
High
about 1 year ago
Ansible vulnerable to Insertion of Sensitive Information into Log File
pypi
ansible-core
High
about 1 year ago
Apache Airflow vulnerable to Execution with Unnecessary Privileges
pypi
apache-airflow
High
about 1 year ago
Apache Airflow vulnerable to Improper Encoding or Escaping of Output
pypi
apache-airflow
High
about 1 year ago
MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
pypi
mindsdb
High
about 1 year ago
Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine
pypi
ethyca-fides
High
about 1 year ago
opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
pypi
opencv-python
High
about 1 year ago
opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
pypi
opencv-contrib-python
High
about 1 year ago
opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
pypi
opencv-python-headless
High
about 1 year ago
opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
pypi
opencv-contrib-python-headless
High
about 1 year ago
GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection
pypi
GeoNode
High
about 1 year ago
nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC
pypi
nanopb
High
about 1 year ago
Hyperledger Indy's update process of a DID does not check who signs the request
pypi
indy-node
High
about 1 year ago
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
pypi
jupyterlab, notebook
High
about 1 year ago
Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
pypi
mobsf
High
about 1 year ago
Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
pypi
Flask-Cors
High
about 1 year ago
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
pypi
jupyterhub
High
about 1 year ago
Pulp incorrectly assigns RBAC permissions in tasks that create objects
pypi
pulpcore
High
over 1 year ago
Insecure Jinja2 templates rendered in Haystack Components can lead to RCE
pypi
haystack-ai
High
over 1 year ago
TensorFlow has segfault in array_ops.upper_bound
pypi
tensorflow-gpu, tensorflow-cpu, tensorflow
High
over 1 year ago
Guardrails AI vulnerable to Improper Restriction of XML External Entity Reference
pypi
guardrails-ai
High
over 1 year ago
Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
pypi
apache-airflow
Filter by Severity
Filter by Package
tensorflow
122
tensorflow-cpu
114
tensorflow-gpu
111
Django
38
mlflow
30
salt
29
apache-airflow
29
Plone
28
ansible
24
opencv-contrib-python
22
opencv-python
22
matrix-synapse
20
django
20
Pillow
18
pillow
18
rdiffweb
17
gradio
17
open-webui
15
keystone
15
vyper
14
apache-superset
13
mindsdb
13
nova
10
pyload-ng
9
h2o
9
aim
9
litellm
9
neutron
9
lollms
9
cobbler
9
mercurial
9
cryptography
8
plone
8
moin
8
vllm
8
ryu
7
opencv-contrib-python-headless
7
ai.h2o:h2o-core
7
sentry
6
opencv-python-headless
6
aubio
6
kiwitcms
6
ethyca-fides
6
nautobot
6
label-studio
6
mobsf
6
trytond
5
pyftpdlib
5
glance
5
pyspark
5
nltk
5
notebook
5
OctoPrint
5
agentscope
5
paddlepaddle
5
keras
5
pgadmin4
5
waitress
5
zope
5
Zope2
5
pip
4
grpc
4
wagtail
4
scrapy
4
inventree
4
RestrictedPython
4
python-gnupg
4
vantage6
4
urllib3
4
lief
4
transformers
4
Zope
4
tornado
4
calibreweb
4
llama-index
4
swift
4
fschat
4
onnx
4
oauthenticator
4
grpcio
4
skops
4
setuptools
4
numpy
4
esphome
4
langchain-community
3
homeassistant
3
modoboa
3
Moin
3
monai
3
motioneye
3
indy-node
3
cinder
3
sanic
3
ipython
3
yt-dlp
3
Jinja2
3
plone.supermodel
3
dbgpt
3
apache-airflow-providers-apache-spark
3
aws-iot-device-sdk-v2
3
llama-index-core
3
awsiotsdk
3
starlette
3
llamafactory
3
litestar
3
trac
3
PaddlePaddle
3
paramiko
3
langchain
3
flask
3
keyring
3
django-helpdesk
3
protobuf
3
keystonemiddleware
3
changedetection.io
3
langflow
3
software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk
3
pretix
3
authlib
3
plone.app.dexterity
3
plone.app.event
3
plone.app.theming
3
ydata-profiling
3
open-webui
3
gunicorn
3
bottle
2
octoprint
2
koji
2
asteval
2
webargs
2
onionshare-cli
2
pyjwt
2
apache-airflow-providers-apache-hive
2
Weblate
2
langroid
2
websockets
2
sqlparse
2
mailman
2
werkzeug
2
Werkzeug
2
starlite
2
OpenEXR
2
jupyterhub
2
portage
2
aiohttp-session
2
openvpn-monitor
2
httpie
2
langgraph-checkpoint-sqlite
2
pyopenssl
2
FreeTAKServer
2
fastecdsa
2
jupyterlab
2
asyncua
2
tlslite-ng
2
CairoSVG
2
torch
2
jupyter-server
2
org.apache.spark:spark-parent_2.12
2
dtale
2
io.grpc:grpc-protobuf
2
pypqc
2
matrix-sydent
2
mistral
2
kallithea
2
pysaml2
2
tripleo-heat-templates
2
tryton
2
markdown-it-py
2
twisted
2
feedparser
2
pyo
2
typed-ast
2
prefect
2
poetry
2
Flask-AppBuilder
2
untangle
2
keylime
2
pywasm3
2
uvicorn
2
uWSGI
2
flaskcode
2
clearml
2
pytorch-lightning
2
mcp
2
xml2rfc
2
python-keystoneclient
2
guardrails-ai
2
indico
2
reportlab
2
mysql-connector-python
2
Flask-Cors
2
Pygments
2
backend.ai
2
rpyc
2
rsa
2
ecdsa
2
InvokeAI
2
bentoml
2
aiohttp
2
sagemaker
2
Filter by Repository
https://github.com/tensorflow/tensorflow
122
https://github.com/django/django
51
https://github.com/apache/airflow
39
https://github.com/python-pillow/Pillow
35
https://github.com/opencv/opencv
25
https://github.com/ansible/ansible
19
https://github.com/ikus060/rdiffweb
17
https://github.com/gradio-app/gradio
17
https://github.com/plone/Products.CMFPlone
16
https://github.com/mlflow/mlflow
15
https://github.com/openstack/keystone
14
https://github.com/vyperlang/vyper
14
https://github.com/saltstack/salt
13
https://github.com/mindsdb/mindsdb
13
https://github.com/matrix-org/synapse
13
https://github.com/run-llama/llama_index
11
https://github.com/h2oai/h2o-3
9
https://github.com/pyload/pyload
9
https://github.com/openstack/nova
9
https://github.com/PaddlePaddle/Paddle
8
https://github.com/vllm-project/vllm
8
https://github.com/pyca/cryptography
8
https://github.com/MobSF/Mobile-Security-Framework-MobSF
7
https://github.com/faucetsdn/ryu
7
https://github.com/cobbler/cobbler
7
https://github.com/parisneo/lollms
7
https://github.com/langchain-ai/langchain
6
https://github.com/nautobot/nautobot
6
https://github.com/aubio/aubio
6
https://github.com/ethyca/fides
6
https://github.com/pgadmin-org/pgadmin4
6
https://github.com/open-webui/open-webui
6
https://github.com/getsentry/sentry
6
https://github.com/kiwitcms/Kiwi
6
https://github.com/HumanSignal/label-studio
5
https://github.com/openstack/neutron
5
https://github.com/keras-team/keras
5
https://github.com/element-hq/synapse
5
https://github.com/Pylons/waitress
5
https://github.com/zopefoundation/Zope
5
https://github.com/vantage6/vantage6
5
https://github.com/tornadoweb/tornado
4
https://github.com/apache/superset
4
https://github.com/berriai/litellm
4
https://github.com/jupyterhub/oauthenticator
4
https://github.com/lief-project/LIEF
4
https://github.com/OctoPrint/OctoPrint
4
https://github.com/urllib3/urllib3
4
https://github.com/numpy/numpy
4
https://github.com/onnx/onnx
4
https://github.com/wagtail/wagtail
4
https://github.com/BerriAI/litellm
4
https://github.com/nltk/nltk
4
https://github.com/esphome/esphome
4
https://github.com/aimhubio/aim
4
https://github.com/scrapy/scrapy
4
https://github.com/huggingface/transformers
4
https://github.com/zopefoundation/RestrictedPython
4
https://github.com/aws/aws-iot-device-sdk-java-v2
3
https://github.com/pallets/werkzeug
3
https://sourceforge.net/projects/roject
3
https://github.com/GeoNode/geonode
3
https://github.com/grpc/grpc
3
https://github.com/hyperledger/indy-node
3
https://github.com/hiyouga/LLaMA-Factory
3
https://github.com/python/cpython
3
https://github.com/openstack/swift
3
https://github.com/skops-dev/skops
3
https://github.com/langflow-ai/langflow
3
https://github.com/openstack/cinder
3
https://github.com/pyca/pyopenssl
3
https://github.com/pyinstaller/pyinstaller
3
https://github.com/twisted/twisted
3
https://github.com/dgtlmoon/changedetection.io
3
https://github.com/tryton/trytond
3
https://github.com/litestar-org/litestar
3
https://github.com/modelscope/agentscope
3
https://github.com/pypa/setuptools
3
https://github.com/Project-MONAI/MONAI
3
https://github.com/keylime/keylime
3
https://github.com/Kludex/python-multipart
3
https://github.com/inventree/InvenTree
3
https://github.com/pypa/pip
3
https://github.com/home-assistant/core
3
https://github.com/jupyter-server/jupyter_server
3
https://sourceforge.net/projects/sourceforge.net
3
https://github.com/ipython/ipython
3
https://github.com/encode/starlette
3
https://github.com/octoprint/octoprint
3
https://github.com/benoitc/gunicorn
3
https://github.com/giampaolo/pyftpdlib
3
https://github.com/janeczku/calibre-web
3
https://github.com/openstack/glance
3
https://github.com/django-helpdesk/django-helpdesk
3
https://github.com/yt-dlp/yt-dlp
3
https://github.com/pallets/flask
2
https://github.com/geopython/OWSLib
2
https://github.com/protocolbuffers/protobuf
2
https://github.com/jupyterlab/jupyterlab
2
https://github.com/FreeTAKTeam/FreeTakServer
2
https://github.com/tomerfiliba-org/rpyc
2
https://github.com/furlongm/openvpn-monitor
2
https://github.com/python-poetry/poetry
2
https://github.com/jaraco/keyring
2
https://github.com/pygments/pygments
2
https://github.com/indico/indico
2
https://github.com/jupyter/notebook
2
https://github.com/aio-libs/aiohttp
2
https://github.com/aaugustin/websockets
2
https://github.com/refuel-ai/autolabel
2
https://github.com/Netflix/lemur
2
https://github.com/aws/sagemaker-python-sdk
2
https://github.com/qutebrowser/qutebrowser
2
https://github.com/invoke-ai/InvokeAI
2
https://github.com/heartexlabs/label-studio
2
https://github.com/dpgaspar/Flask-AppBuilder
2
https://github.com/authlib/authlib
2
https://github.com/9001/copyparty
2
https://github.com/spotify/luigi
2
https://github.com/zauberzeug/nicegui
2
https://github.com/jpadilla/pyjwt
2
https://github.com/dnkorpushov/ebookmeta
2
https://github.com/langchain-ai/langgraph
2
https://github.com/paramiko/paramiko
2
https://github.com/Kozea/CairoSVG
2
https://github.com/FreeOpcUa/opcua-asyncio
2
https://github.com/onionshare/onionshare
2
https://github.com/mmaitre314/picklescan
2
https://github.com/ietf-tools/xml2rfc
2
https://github.com/WeblateOrg/weblate
2
https://github.com/pretix/pretix
2
https://github.com/bottlepy/bottle
2
https://github.com/admesh/admesh
2
https://github.com/langroid/langroid
2
https://github.com/jupyter/jupyter_core
2
https://github.com/guardrails-ai/guardrails
2
https://github.com/poezio/slixmpp
2
https://github.com/AntonKueltz/fastecdsa
2
https://github.com/TeamSeri0us/pocs
2
https://github.com/aio-libs/aiohttp-session
2
https://gitlab.com/daniele_m/cve-list
2
https://github.com/sanic-org/sanic
2
https://github.com/dlitz/pycrypto
2
https://github.com/stchris/untangle
2
https://github.com/jupyterhub/jupyterhub
2
https://github.com/zenml-io/zenml
2
https://github.com/man-group/dtale
2
https://github.com/wasm3/wasm3
2
https://github.com/marshmallow-code/webargs
2
https://github.com/openstack/mistral
2
https://github.com/pypa/advisory-db
2
https://github.com/sybrenstuvel/python-rsa
2
https://github.com/aws/amazon-redshift-python-driver
2
https://github.com/jhpyle/docassemble
2
https://github.com/belangeo/pyo
2
https://github.com/andialbrecht/sqlparse
2
https://github.com/pytorch/pytorch
2
https://github.com/gitpython-developers/GitPython
2
https://github.com/modoboa/modoboa
2
https://github.com/executablebooks/markdown-it-py
2
https://github.com/Legrandin/pycryptodome
2
https://github.com/snowflakedb/snowflake-connector-python
2
https://github.com/JamesTheAwesomeDude/pypqc
2
https://github.com/corydolphin/flask-cors
2
https://github.com/modelcontextprotocol/python-sdk
2
https://github.com/lmfit/asteval
2
https://github.com/pikepdf/pikepdf
1
https://github.com/QuivrHQ/quivr
1
https://github.com/tlsfuzzer/python-ecdsa
1
https://github.com/OpenIDC/pyoidc
1
https://github.com/aresch/rencode
1
https://github.com/openstack/barbican
1
https://github.com/jlowin/fastmcp
1
https://github.com/FiloSottile/age
1
https://github.com/openstack/ossa
1
https://github.com/kam193/package-campaigns
1
https://github.com/projen/projen
1
https://github.com/Qiskit/qiskit
1
https://github.com/ni/measurementlink-python
1
https://github.com/michael-lazar/rtv
1
https://github.com/scikit-learn/scikit-learn
1
https://github.com/bugsink/bugsink
1
https://bitbucket.org/kang/python-keyring-lib
1
https://github.com/schettino72/sqla_yaml_fixtures
1
https://github.com/matrix-org/matrix-doc
1
https://github.com/python-imaging/Pillow
1
https://github.com/simplegeo/python-oauth2
1
https://github.com/wichert/pyrad
1
https://github.com/Skyvern-AI/skyvern
1
https://github.com/OISF/suricata-update
1
https://github.com/explosion/spacy-llm
1
https://github.com/hwchase17/langchain
1
https://github.com/frappe/frappe
1
https://github.com/AstrBotDevs/AstrBot
1
https://github.com/SAML-Toolkits/python-saml
1
https://github.com/Snawoot/postfix-mta-sts-resolver
1
https://github.com/dirkf/youtube-dl
1
https://github.com/Toblerity/Fiona
1
https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape
1