PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44844Mediumeml_parser: eml_parser has recursion DoS via nested message/rfc822 attachmentsCVE-2026-44843Highlangchain-core: LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlistsCVE-2026-44566Highopen-webui: Open WebUI Vulnerable to Arbitrary File Upload and Path TraversalCVE-2026-44567Highopen-webui: Open WebUI has Improper Authorization ControlCVE-2026-44549Highopen-webui: Open WebUI has stored XSS in Excel file previewCVE-2026-44568Mediumopen-webui: Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application OrderCVE-2026-44209Highbanks: banks has Critical Remote Code Execution (RCE) via Jinja2 SSTICVE-2026-44200Mediumwagtail: Wagtail has improper permission handling when copying pagesCVE-2026-44201Mediumwagtail: Wagtail has improper restriction handling on Documents and Images APICVE-2026-44199Mediumwagtail: Wagtail has improper permission handling when deleting form submissionsCVE-2026-44198Mediumwagtail: Wagtail has improper permission handling when viewing page historyCVE-2026-44197Mediumwagtail: Wagtail has improper permission handling when comparing revisionsCVE-2026-44560Mediumopen-webui: Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector SearchCVE-2026-44561Mediumopen-webui: Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM ChannelsCVE-2026-44564Mediumopen-webui: Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IOCVE-2026-44563Mediumopen-webui: Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/showCVE-2026-44562Mediumopen-webui: Open WebUI's Model Import Overwrites Any Model Without Ownership CheckCVE-2026-44559Mediumopen-webui: Open WebUI Missing Access Check on Channel Members Endpoint for Standard ChannelsCVE-2026-44557Mediumopen-webui: Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-CollectionCVE-2026-44554Highopen-webui: Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection OverwriteCVE-2026-44558Mediumopen-webui: Open WebUI's Channel Access Grants Bypass filter_allowed_access_grantsCVE-2026-44556Highopen-webui: Open WebUI's responses passthrough endpoint lacks access control authorizationCVE-2026-44555Highopen-webui: Open WebUI's Base Model Routing Bypasses Access Control via Model ChainingCVE-2026-44552Highopen-webui: Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache PoisoningCVE-2026-44553Highopen-webui: Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access

Stop the waste.
Protect your environment with Kodem.