PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-51481Mediumdagster: Dagster Local File Inclusion vulnerabilityCVE-2025-54140Highpyload-ng: `pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File WriteCVE-2025-54121Mediumstarlette: Starlette has possible denial-of-service vector when parsing large files in multipart formsCVE-2025-53528Highcadwyn: Cadwyn vulnerable to XSS on the docs pageCVE-2025-7885Lowwebssh: WebSSH Cross-site Scripting vulnerabilityCVE-2025-53890Criticalpyload-ng: pyLoad vulnerable to XSS through insecure CAPTCHA CVE-2025-53643Lowaiohttp: AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sectionsCVE-2025-53640Mediumindico: Indico vulnerability allows attackers to bulk dump user detailsCVE-2025-29606Mediumlibp2p: py-libp2p is vulnerable to DoS attacks through use of large RSA keysCVE-2025-53865Mediumroundup: Roundup is vulnerable to XSS through interactions between URLs and issue tracker templatesCVE-2025-30402Highexecutorch: ExecuTorch vulnerable to Heap-based Buffer Overflow attackCVE-2025-3933Mediumtransformers: Transformers is vulnerable to ReDoS attack through its DonutProcessor classCVE-2025-6211Mediumllama-index: LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class CVE-2025-7346Highpyload-ng: pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packagesCVE-2025-53539Mediumfastapi-guard: fastapi-guard is vulnerable to ReDoS through inefficient regexCVE-2023-51232Mediumdagster: Dagster vulnerable to Path Traversal attack through its /logs endpointCVE-2025-6209Highllama-index-core: LlamaIndex vulnerable to Path Traversal attack through its encode_image functionCVE-2025-6210Mediumllama-index-readers-obsidian: LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploitCVE-2025-5472Mediumllama-index-core: LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsingCVE-2025-6386Highlollms: Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user functionCVE-2025-3777Lowtransformers: Transformers's Improper Input Validation vulnerability can be exploited through username injectionCVE-2025-3264Mediumtransformers: Transformers vulnerable to ReDoS attack through its get_imports() functionCVE-2025-3263Mediumtransformers: Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtrackingCVE-2025-3046Highllama-index-readers-obsidian: LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader classCVE-2025-3225Highllama-index-readers-papers: LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser

Stop the waste.
Protect your environment with Kodem.