PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-6167Mediumpython-a2a: python-a2a has a path traversal in the create_workflow functionGHSA-5QPG-RH4J-QP35Mediumpycares: pycares has a Use-After-Free VulnerabilityCVE-2025-4565Highprotobuf: protobuf-python has a potential Denial of Service issueCVE-2025-49134Lowweblate: Weblate exposes personal IP address via e-mailCVE-2025-47951Mediumweblate: Weblate lacks rate limiting when verifying second factorCVE-2024-38824Criticalsalt: Salt vulnerable to directory traversal attack in file receiving methodCVE-2025-22242Mediumsalt: Salt's worker process vulnerable to denial of service through file read operationCVE-2025-22238Mediumsalt: Salt vulnerable to directory traversal attack in minion file cache creationCVE-2025-22237Mediumsalt: Salt's on demand pillar functionality vulnerable to arbitrary command injections CVE-2025-22241Mediumsalt: Salt's file contents overwrite the VirtKey classCVE-2025-22240Mediumsalt: Salt allows arbitrary directory creation or file deletionCVE-2025-22239Highsalt: Salt vulnerable to arbitrary event injectionCVE-2024-38825Mediumsalt: Salt's salt.auth.pki module does not properly authenticate callersCVE-2025-22236Highsalt: Salt has minion event bus authorization bypass vulnerabilityCVE-2025-43866Lowvantage6-server: Vantage6 Server JWT secret not cryptographically secureCVE-2025-43863Lowvantage6: vantage6 lacks brute-force protection on change password functionalityCVE-2025-49143Mediumnautobot: Nautobot may allows uploaded media files to be accessible without authenticationCVE-2025-49142Mediumnautobot: Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templatingCVE-2025-48879MediumOctoPrint: OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrintCVE-2025-48067MediumOctoPrint: OctoPrint vulnerable to possible file extraction via upload endpointsCVE-2024-47081Mediumrequests: Requests vulnerable to .netrc credentials leak via malicious URLsCVE-2025-49651Highbackend.ai: Backend.AI Missing Authorization vulnerabilityCVE-2025-49653Highbackend.ai: BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized ActorCVE-2025-49652Criticalbackend.ai: BackendAI Missing Authentication for Critical FunctionCVE-2025-49619Highskyvern: Skyvern has a Jinja runtime leak

Stop the waste.
Protect your environment with Kodem.