PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-27835Mediumwger: wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout dataCVE-2026-27888Mediumpypdf: pypdf: Manipulated FlateDecode XFA streams can exhaust RAMCVE-2026-27457Mediumweblate: Weblate: Missing access control for the AddonViewSet API exposes all addon configurationsCVE-2026-27809Mediumpsd-tools: psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gapsCVE-2026-27735Mediummcp-server-git: mcp-server-git : Path traversal in git_add allows staging files outside repository boundariesCVE-2026-27794Mediumlanggraph-checkpoint: LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution CVE-2026-27695Mediumzae-limiter: zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of ServiceCVE-2026-25736Mediumrucio-webui: Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE AttributeCVE-2026-25735Mediumrucio-webui: Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity NameCVE-2026-25734Mediumrucio-webui: Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE MetadataCVE-2026-27696Highchangedetection.io: changedetection.io is Vulnerable to SSRF via Watch URLsCVE-2026-27645Mediumchangedetection.io: changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error ResponseCVE-2026-27641Criticalflask-reuploaded: Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template InjectionCVE-2026-25733Highrucio-webui: Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule FunctionCVE-2026-25138Mediumrucio-webui: Rucio WebUI has Username Enumeration via Login Error MessageCVE-2026-25136Highrucio-webui: Rucio WebUI has a Reflected Cross-site Scripting VulnerabilityCVE-2026-26717Mediumrichie: OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request functionCVE-2026-27628Lowpypdf: pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streamsCVE-2026-27614Criticalbugsink: Bugsink is vulnerable to Stored XSS via Pygments fallback in stacktrace renderingGHSA-MHC9-48GJ-9GP3Mediumfickling: Fickling has safety check bypass via REDUCE+BUILD opcode sequenceGHSA-MXHJ-88FX-4PCVHighfickling: Fickling: OBJ opcode call invisibility bypasses all safety checksCVE-2026-27483Highmindsdb: MindsDB: Path Traversal in /api/files Leading to Remote Code ExecutionCVE-2026-27156Mediumnicegui: NiceGUI vulnerable to XSS via Code Injection during client-side element function executionCVE-2026-27469Mediumisso: Isso affected by Stored XSS via comment website fieldCVE-2026-23984Highapache-superset: Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections

Stop the waste.
Protect your environment with Kodem.