PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-46608Highglances: Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)CVE-2026-46607Highglances: Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code ExecutionCVE-2026-46606Highglances: Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.pyCVE-2026-46488Criticalmotioneye: motionEye: Authentication possible via password hashCVE-2025-67303Highcomfyui-manager: ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)CVE-2026-32315Mediummotioneye: motionEye's World-Readable Configuration File Exposes Admin Password HashCVE-2026-31978Mediummotioneye: motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview EndpointCVE-2026-21887Highpycti: OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion FeatureCVE-2024-37155Mediumpycti: OpenCTI May Bypass Introspection RestrictionCVE-2026-59153Highaqt: Anki's local HTTP server does not sufficiently validate requestsGHSA-4XGF-CPJX-PC3JMediumpydantic-settings: pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing…GHSA-F4XH-W4CJ-QXQ8Highlangsmith: LangSmith SDK TracingMiddleware: Arbitrary server-side file readGHSA-4CC2-G9W2-FHF6Mediumzeep: Zeep: Server-Side Request Forgery (SSRF)GHSA-CW6H-FFMH-X6VHMediumaqt: Anki: User scripts in iframes have access to the internal Anki APIGHSA-WVRH-2F4M-924VMediumChatterBot: ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainerGHSA-C795-2G9C-J48MHigheveros: EverOS: Path traversal in EverOS /api/v1/memory/add via unvalidated sender_idGHSA-6GQW-JQV7-V88MHighstigmem-node: stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)GHSA-XHV3-Q4XX-349RHighstigmem-node: stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)GHSA-X26H-XMV8-GXF7Highstigmem-node: stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)GHSA-6V7P-G79W-8964Highmsgpack: MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught errorCVE-2026-55447Criticallangflow: Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploitCVE-2026-55446Highlangflow: Langflow: Unauthenticated DoS through multipart form boundary file uploadCVE-2026-55423Mediumlangflow: Langflow: Logout button does not clear sessionCVE-2026-55255Highlangflow: Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's FlowCVE-2026-55206Mediumpy7zr: py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()

Stop the waste.
Protect your environment with Kodem.