PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-62379Lowreflex: reflex-dev/reflex has an Open Redirect vulnerabilityCVE-2025-55039Loworg.apache.spark:spark-network-common_2.13: Apache Spark has Inadequate Encryption StrengthCVE-2025-62172Highhomeassistant: Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity NameCVE-2025-7707Highllama-index: llama-index has Insecure Temporary FileCVE-2025-62706Mediumauthlib: Authlib : JWE zip=DEF decompression bomb enables DoSCVE-2025-61912Mediumpython-ldap: python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null TerminationCVE-2025-61911Mediumpython-ldap: python-ldap has sanitization bypass in ldap.filter.escape_filter_charsCVE-2025-61920Highauthlib: Authlib is vulnerable to Denial of Service via Oversized JOSE SegmentsCVE-2025-10283Criticalbbot: BBOT's insufficient sanitization issues in gitdumper.py can lead to RCECVE-2025-10281Mediumbbot: BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserverCVE-2025-10284Criticalbbot: BBOT's various issues in unarchive.py can cause arbitrary file write and RCECVE-2025-61783Mediumsocial-auth-app-django: Python Social Auth - Django has unsafe account association CVE-2025-61773Highpyload-ng: pyLoad CNL and captcha handlers allow Code Injection via unsanitized parametersGHSA-M9MP-6X32-5RHGCriticalscio-pypi: scio is vunerable to Remote Command Execution through PyTorchCVE-2025-61672Mediummatrix-synapse: Synapse's invalid device keys degrade federation functionalityCVE-2025-6242Highvllm: vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` classCVE-2025-61784Highllamafactory: LLaMA Factory's Chat API Contains Critical SSRF and LFI VulnerabilitiesCVE-2025-61620Mediumvllm: vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible ServerCVE-2025-59425Highvllm: vLLM is vulnerable to timing attack at bearer authCVE-2025-61765Mediumpython-socketio: python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server…CVE-2025-59152Highlitestar: Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit EvasionCVE-2025-6985Highlangchain-text-splitters: LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsingCVE-2025-8917Mediumclearml: clearml is vulnerable to Path Traversal through its `safe_extract` functionCVE-2025-8406Mediumzenml: ZenML is vulnerable to Path Traversal through its `PathMaterializer` classCVE-2025-53354Mediumnicegui: NiceGUI has a Reflected XSS

Stop the waste.
Protect your environment with Kodem.