PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2021-4472Mediumpython-mistralclient: OpenStack's Mistral Client has a local file inclusion vulnerabilityCVE-2025-62593Criticalray: Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding AttackCVE-2025-62703Highfugue: Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServerGHSA-J4GV-6X9V-V23GLowomero-web: OMERO.web uses jquery-form library, which may be vulnerable to XSS attackCVE-2025-66019Mediumpypdf: pypdf's LZWDecode streams be manipulated to exhaust RAMCVE-2025-13609Highkeylime: Keylime allows users to register new agents by recycling existing UUIDs when using different TPM devicesCVE-2025-62609Mediummlx: MLX has Wild Pointer Dereference in load_gguf()CVE-2025-62608Mediummlx: MLX has heap-buffer-overflow in load()CVE-2025-62426Mediumvllm: vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`CVE-2025-62372Highvllm: vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputsCVE-2025-62164Highvllm: vLLM deserialization vulnerability leading to DoS and potential RCECVE-2025-65106Highlangchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt TemplatesCVE-2025-60455Criticalmodular: Modular Max Serve has Unsafe Deserialization vulnerabilityCVE-2025-65015Criticaljoserfc: joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token PayloadsCVE-2025-65073Highkeystone: OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.CVE-2025-55449Criticalastrbot: AstrBot is vulnerable to RCE with hard-coded JWT signing keysCVE-2025-12967Highaws_advanced_python_wrapper: AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance CVE-2025-12765Highpgadmin4: pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verificationCVE-2025-12764Highpgadmin4: pgAdmin is affected by an LDAP injection vulnerabilityCVE-2025-12763Mediumpgadmin4: pgAdmin 4 has command injection vulnerability on Windows systemsCVE-2025-12762Criticalpgadmin4: pgAdmin4 vulnerable to Remote Code Execution (RCE) when running in server modeCVE-2025-64509Highbugsink: Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)CVE-2025-64508Highbugsink: Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli inputCVE-2025-62780Lowchangedetection.io: changedetection.io: Stored XSS in Watch update via APICVE-2025-70559Highpdfminer.six: Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc

Stop the waste.
Protect your environment with Kodem.