PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-48956Highvllm: vllm API endpoints vulnerable to Denial of Service AttacksCVE-2025-55214Mediumcopier: Copier's safe template has filesystem write access outside destination pathCVE-2025-55201Highcopier: Copier's safe template has arbitrary filesystem read/write accessCVE-2025-55675Mediumapache-superset: Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to accessCVE-2025-55672Mediumapache-superset: Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerabilityCVE-2025-55673Mediumapache-superset: Apache Superset data query improperly discloses database schema information to low-privileged guest userCVE-2025-55674Mediumapache-superset: Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functionsCVE-2025-55197Mediumpypdf: PyPDF's Manipulated FlateDecode streams can exhaust RAMCVE-2025-54791Mediumomero-web: OMERO.web displays unecessary user information when requesting password resetCVE-2025-8747Highkeras: Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionalityCVE-2025-71325Highpicklescan: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypassCVE-2025-55156Highpyload-ng: PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameterGHSA-674P-XV2X-RF3GLowlitestar: Litestar has potential log injection in exception loggingCVE-2025-55149Mediumtiny-scientist: TinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)CVE-2025-54952Mediumexecutorch: ExecuTorch integer overflow vulnerability leads to code executionCVE-2025-30404Criticalexecutorch: ExecuTorch integer overflow vulnerabilityCVE-2025-54949Criticalexecutorch: ExecuTorch heap buffer overflow vulnerabilityCVE-2025-54950Criticalexecutorch: ExecuTorch out-of-bounds access vulnerabilityCVE-2025-30405Criticalexecutorch: ExecuTorch integer overflow vulnerabilityCVE-2025-54951Criticalexecutorch: ExecuTorch vulnerable to Heap-based Buffer OverflowCVE-2025-54368Mediumuv: uv allows ZIP payload obfuscation through parsing differentialsCVE-2025-54886Highskops: SKOPS Card.get_model happily allows arbitrary code executionCVE-2025-5197Mediumtransformers: Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerabilityCVE-2025-54802Criticalpyload-ng: pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)CVE-2025-54796Highcopyparty: copyparty allows Regex Denial of Service (ReDoS) in the upload listing

Stop the waste.
Protect your environment with Kodem.