PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-6051Mediumtransformers: Hugging Face Transformers library has Regular Expression Denial of ServiceCVE-2025-6638Mediumtransformers: Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizerCVE-2025-10193Highmcp-neo4j-cypher: Neo4j Cypher MCP server is vulnerable to DNS rebinding CVE-2025-58065Mediumflask-appbuilder: Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methodsCVE-2025-59036Mediuminfrahub-server: Infrahub: Deleted and expired API tokens can still authenticateCVE-2025-11059Highxml2rfc: xml2rfc is vulnerable to arbitrary file reads through prepped filesCVE-2025-59042Highpyinstaller: PyInstaller has local privilege escalation vulnerabilityCVE-2025-59035Mediumindico: Indico vulnerable to Cross-Site Scripting via LaTeX math codeCVE-2025-59034Mediumindico: Indico may disclose unauthorized user details access via legacy APICVE-2025-10155Criticalpicklescan: Picklescan Bypass is Possible via File Extension MismatchCVE-2025-10156Criticalpicklescan: Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy CheckCVE-2025-10157Criticalpicklescan: Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass ImportsCVE-2025-10164Mediumsglang: SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensorCVE-2025-58757Highmonai: Monai: Unsafe use of Pickle deserialization may lead to RCECVE-2025-58756Highmonai: MONAI: Unsafe torch usage may lead to arbitrary code executionCVE-2025-58755Highmonai: MONAI does not prevent path traversal, potentially leading to arbitrary file writesCVE-2025-58180Highoctoprint: OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File UploadCVE-2025-58753Mediumcopyparty: copyparty: Sharing a single file does not fully restrict access to other files in source folderCVE-2025-57817Highethyca-fides: Fides Webserver API is Vulnerable to OAuth Client Privilege EscalationCVE-2025-57816Mediumethyca-fides: Fides Webserver API Rate Limiting Vulnerability in Proxied EnvironmentsCVE-2025-57815Lowethyca-fides: Fides has a Lack of Brute-Force Protections on Authentication EndpointsCVE-2025-57766Lowethyca-fides: Fides' Admin UI User Password Change Does Not Invalidate Current SessionCVE-2025-57833HighDjango: Django is subject to SQL injection through its column aliasesCVE-2025-58446Mediumxgrammar: xgrammar vulnerable to denial of service by huge enum grammarCVE-2025-58438Criticalinternetarchive: internetarchive Vulnerable to Directory Traversal in File.download()

Stop the waste.
Protect your environment with Kodem.