PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-34291Criticallangflow: Langflow CORS misconfiguration enables Account Takeover and RCECVE-2025-66471Highurllib3: urllib3 streaming API improperly handles highly compressed dataCVE-2025-66418Highurllib3: urllib3 allows an unbounded number of links in the decompression chainCVE-2025-65958Highopen-webui: Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/webCVE-2025-63681Lowopen-webui: open-webui is Vulnerable to Incorrect Access ControlCVE-2025-56427Mediumcomposio: ComposioHQ has a directory traversal vulnerabilityCVE-2025-14010Mediumansible: Ansible Community General Collection is vulnerable to exposure of sensitive informationCVE-2025-65896Criticalasyncmy: asyncmy is vulnerable to SQL injection via crafted dict keysCVE-2025-64460MediumDjango: Django is vulnerable to DoS via XML serializer text extractionCVE-2025-13372MediumDjango: Django is vulnerable to SQL injection in column aliasesCVE-2025-66454Mediumarcade-mcp-server: arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker EndpointsCVE-2025-66448Highvllm: vLLM vulnerable to remote code execution via transformers_utils/get_configCVE-2025-66416Highmcp: Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by defaultCVE-2025-65858Lowcalibreweb: Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User CreationCVE-2025-12060Highkeras: Keras Directory Traversal VulnerabilityCVE-2025-66221Mediumwerkzeug: Werkzeug safe_join() allows Windows special device namesCVE-2025-66040Lowspotipy: Spotipy has a XSS vulnerability in its OAuth callback serverCVE-2025-66034Mediumfonttools: fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLibCVE-2025-66423Hightrytond: trytond does not enforce access rights for the route of the HTML editor.CVE-2025-66424Mediumtrytond: trytond does not enforce access rights for data exportCVE-2025-66422Mediumtrytond: trytond allows remote attackers to obtain sensitive trace-back (server setup) informationCVE-2025-66371Mediumpeppol_py: Peppol-py is vulnerable to XXE attacks due to Saxon configurationCVE-2025-13742Lowpretix: pretix has Email Content Injection Through Maliciously Formatted NamesCVE-2025-34351Criticalray: Ray's New Token Authentication is Disabled By DefaultCVE-2025-65681Lowtutor: Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control

Stop the waste.
Protect your environment with Kodem.