PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-1793Criticalllama-index: llama_index vulnerable to SQL InjectionCVE-2025-48432MediumDjango: Django Improper Output Neutralization for Logs vulnerabilityCVE-2025-48994Mediumsignxml: SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attackCVE-2025-48995Mediumsignxml: SignXML's signature verification with HMAC is vulnerable to a timing attackCVE-2025-48957Highastrbot: AstrBot Has Path Traversal Vulnerability in /api/chat/get_fileCVE-2025-30167Highjupyter_core: Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityCVE-2018-25111Mediumdjango-helpdesk: django-helpdesk Allows Sensitive Data ExposureCVE-2025-48912Highapache-superset: Apache Superset: Improper authorization bypass on row level security via SQL InjectionCVE-2025-48889Mediumgradio: Gradio Allows Unauthorized File Copy via Path ManipulationCVE-2025-5321Lowaim: Aim Vulnerable to Sandbox Escape Leading to Remote Code ExecutionCVE-2025-5320Lowgradio: Gradio CORS Origin Validation Bypass VulnerabilityGHSA-94V7-WXJ6-R2Q5Mediummulticast: multicast in source builds from vulnerable setuptools dependencyCVE-2025-48944Mediumvllm: vLLM Tool Schema allows DoS via Malformed pattern and type FieldsCVE-2025-48943Mediumvllm: vLLM allows clients to crash the openai server with invalid regexCVE-2025-48942Mediumvllm: vLLM DOS: Remotely kill vllm over http with invalid JSON schemaCVE-2025-46722Mediumvllm: vLLM has a Weakness in MultiModalHasher Image Hashing ImplementationCVE-2025-46570Lowvllm: Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix CachingGHSA-J828-28RJ-HFHPMediumvllm: vLLM vulnerable to Regular Expression Denial of ServiceCVE-2025-48887Mediumvllm: vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`CVE-2025-5279Highredshift-connector: Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider pluginCVE-2025-1753Highllama-index-cli: LLama-Index CLI OS command injection vulnerabilityCVE-2025-48383Highdjango-select2: Django-Select2 Vulnerable to Widget Instance Secret Cache Key LeakingCVE-2025-5174Mediumpypickle: pypickle unsafe deserialization vulnerabilityCVE-2025-5175Mediumpypickle: pypickle Incorrect Privilege Assignment vulnerabilityCVE-2025-5173Mediumlabel-studio-ml: HumanSignal label-studio-ml-backend Deserialization of Untrusted Data vulnerability

Stop the waste.
Protect your environment with Kodem.