PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-24157Highnemo-toolkit: NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loadingCVE-2026-24159Highnemo-toolkit: NVIDIA NeMo Framework contains a vulnerability leading to Remote Code ExecutionCVE-2026-33545Mediummobsf: MobSF has SQL Injection in its SQLite Database Viewer UtilsGHSA-5VP3-3CG6-2RQ3Highjusthtml: JustHTML is vulnerable to XSS via code fence breakout in <pre> contentCVE-2026-33430Highbriefcase: Briefcase: Windows MSI Installer Privilege Escalation via Insecure Directory Permissions CVE-2026-33046Highindico: Indico discloses local files resulting in Remote Code Execution through LaTeX injection CVE-2026-26209Highcbor2: cbor2 has a Denial of Service via Uncontrolled Recursion in cbor2.loadsCVE-2026-4539LowPygments: Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID MatchingCVE-2026-4506Lowmindsql: MindSQL is vulnerable to Code Injection through its ask_db functionCVE-2026-33509Highpyload-ng: pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script ConfigurationCVE-2026-33497Highlangflow: langflow: /profile_pictures/{folder_name}/{file_name} endpoint file readingCVE-2026-33484Highlangflow: langflow has Unauthenticated IDOR on Image DownloadsCVE-2026-32711Highpydicom: pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set rootCVE-2026-33332Mediumnicegui: NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustionCVE-2026-3029MediumPyMuPDF: PyMuPDF has a path traversal in _main_.pyGHSA-2MHW-8QCG-GR96Highskia-python: skia-python vendors vulnerable libfreetype because of pinned cibuildwheel versionCVE-2026-33314Mediumpyload-ng: Improper Authentication and Origin Validation Error in pyload-ngCVE-2026-33310Highintake: Intake has a Command Injection via shell() Expansion in Parameter DefaultsCVE-2026-33309Criticallangflow: Langflow has an Arbitrary File Write (RCE) via v2 APICVE-2026-32889Mediumtinytag: Denial of service via non-terminating SYLT frame parsing loop in tinytagCVE-2026-27953Highormar: ormar Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model ConstructorCVE-2026-33236Highnltk: NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File OverwriteCVE-2026-33231Highnltk: Unauthenticated remote shutdown in nltk.app.wordnet_appCVE-2025-15031Highmlflow: Arbitrary file write via tar traversal in mlflowCVE-2026-33230Mediumnltk: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk

Stop the waste.
Protect your environment with Kodem.