PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-23980Mediumapache-superset: Apache Superset allows privileged users to conduct error-based SQL InjectionCVE-2026-23982Highapache-superset: Apache Superset Improper Authorization allows low-privileged users to bypass access controls CVE-2026-23969Mediumapache-superset: Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engineCVE-2026-23983Lowapache-superset: Apache Superset allows authenticated users to view sensitive data without explicit permissionsCVE-2025-27555Mediumapache-airflow: Apache Airflow exposes sensitive information in its log filesCVE-2024-56373Highapache-airflow: Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate tableCVE-2026-26331Highyt-dlp: yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` optionCVE-2026-26198Criticalormar: ormar is vulnerable to SQL Injection through aggregate functions min() and max()CVE-2026-2970Lowdatapizza-ai-core: datapizza-ai has unsafe deserialization via pickle.loads() in RedisCacheCVE-2026-2969Lowdatapizza-ai-core: datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template HandlerCVE-2025-65995Mediumapache-airflow: Apache Airflow error reporting may expose full kwargsCVE-2026-2635Criticalmlflow: MLflow Use of Default Password Authentication Bypass VulnerabilityCVE-2026-2033Highmlflow: MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution VulnerabilityCVE-2026-2472Highgoogle-cloud-aiplatform: Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)CVE-2026-2473Highgoogle-cloud-aiplatform: Google Cloud Vertex AI has a a vulnerability involving predictable bucket namingCVE-2026-27482Mediumray: Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)GHSA-83PF-V6QQ-PWMRLowfickling: Fickling has a detection bypass via stdlib network-protocol constructorsCVE-2026-27205Lowflask: Flask session does not add `Vary: Cookie` header when accessed in some waysCVE-2026-27199Mediumwerkzeug: Werkzeug safe_join() allows Windows special device namesCVE-2026-27194Highdtale: D-Tale affected by Remote Code Execution through the /save-column-filter endpointCVE-2026-26030Criticalsemantic-kernel: Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code executionCVE-2026-1669Highkeras: Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight LoadingCVE-2026-27026Mediumpypdf: pypdf possibly has long runtimes for malformed FlateDecode streamsCVE-2026-27025Mediumpypdf: pypdf has possible long runtimes/large memory usage for large /ToUnicode streamsCVE-2026-27024Mediumpypdf: pypdf has a possible infinite loop when processing TreeObject

Stop the waste.
Protect your environment with Kodem.