PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-64512Highpdfminer.six: Arbitrary Code Execution in pdfminer.six via Crafted PDF InputCVE-2025-57697MediumAstrBot: AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64CVE-2025-57698HighAstrBot: AstrBot contains a directory traversal vulnerabilityCVE-2025-64496Highopen-webui: Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE EventsCVE-2025-64495Highopen-webui: Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCECVE-2025-64481Lowdatasette: Open redirect endpoint in DatasetteCVE-2025-64439Highlanggraph-checkpoint: LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer CVE-2025-64326Lowweblate: Weblate leaks the IP of project member inviting user to be reviewer in Audit logCVE-2025-64458Highdjango: Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on WindowsCVE-2025-64459Criticaldjango: Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.CVE-2025-58337Mediumdoris-mcp-server: Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" modeCVE-2025-64187Mediumoctoprint: OctoPrint vulnerable to XSS in Action Commands Notification and PromptCVE-2025-64184Highdosage: Dosage vulnerable to a Directory Traversal through crafted HTTP responsesCVE-2025-12695Mediumdspy: DSPy does not properly restrict file readsCVE-2025-60787Highmotioneye: motionEye vulnerable to RCE via unsanitized motion config parameterCVE-2025-64168Highagno: Agno session state overwrites between different sessions/usersCVE-2020-25635Mediumansible: Ansible does not collect garbage after playbook runCVE-2025-63675Mediumcryptidy: cryptidy allows code execution via untrusted data due to pickle.loads CVE-2025-6176Highbrotli: Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementationCVE-2025-50736Lowpdf2zh: Byaidu PDFMathTranslate vulnerable to open redirectCVE-2025-62503Mediumapache-airflow: Apache Airflow's create action can upsert existing Pools/Connections/VariablesCVE-2025-62402Mediumapache-airflow: Apache Airflow `/api/v2/dagReports` executes DAG Python in APICVE-2025-54941Mediumapache-airflow: Apache Airflow has a command injection vulnerability in "example_dag_decorator"CVE-2025-64104Highlanggraph-checkpoint-sqlite: LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStoreGHSA-GRJP-54V3-C442Mediumusd-core: OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability

Stop the waste.
Protect your environment with Kodem.