PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-3568Lowtransformers: Transformers Deserialization of Untrusted Data vulnerabilityCVE-2024-3098Criticalllama-index-core: llama-index-core Prompt Injection vulnerability leading to Arbitrary Code ExecutionCVE-2024-2195Criticalaim: Aim Web API vulnerable to Remote Code ExecutionCVE-2024-2196Highaim: Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operationsCVE-2024-2952Criticallitellm: LiteLLM has Server-Side Template Injection vulnerability in /completions endpointCVE-2024-22423Highyt-dlp: yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)CVE-2024-29905HighDIRAC: DIRAC: Unauthorized users can read proxy contents during generationCVE-2024-28732Highryu: Ryu Infinite Loop vulnerabilityCVE-2024-3116Highpgadmin4: pgAdmin Remote Code Execution (RCE) vulnerabilityCVE-2024-31215Mediummobsf: Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database checkCVE-2024-30265Highvoila: Voilà Local file inclusionCVE-2024-28219Highpillow: Pillow buffer overflow vulnerabilityCVE-2024-30248Highpiccolo-admin: Piccolo Admin's raw SVG loading may lead to complete data compromise from admin pageCVE-2024-29640Highaliyundrive-webdav: aliyundrive-webdav vulnerable to Command InjectionCVE-2024-29888Mediumsaleor: Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery methodCVE-2024-28233Highjupyterhub: Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie TossingCVE-2024-28335CriticalLektor: Lektor does not sanitize database path traversalCVE-2024-2206Highgradio: gradio Server-Side Request Forgery vulnerabilityCVE-2024-29735Mediumapache-airflow: Apache Airflow Improper Preservation of Permissions vulnerabilityCVE-2024-1455Mediumlangchain-core: LangChain's XMLOutputParser vulnerable to XML Entity ExpansionCVE-2024-29199Lownautobot: Unauthenticated views may expose information to anonymous usersCVE-2024-29189Highansys-geometry-core: ansys-geometry-core OS Command Injection vulnerabilityCVE-2024-1603Highpaddlepaddle: PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_fileCVE-2024-29190Highmobsfscan: SSRF Vulnerability on assetlinks_check(act_name, well_knowns)CVE-2024-29019Highesphome: ESPHome vulnerable to Authentication bypass via Cross site request forgery

Stop the waste.
Protect your environment with Kodem.