PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-5150Mediumdocarray: docarray prototype pollutionCVE-2025-5148Mediuminspiremusic: FunAudioLLM InspireMusic deserialization vulnerabilityCVE-2025-47277Criticalvllm: vLLM Allows Remote Code Execution via PyNcclPipe Communication ServiceCVE-2025-46725Highlangroid: Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_storeCVE-2025-46724Criticallangroid: Langroid has a Code Injection vulnerability in TableChatAgentCVE-2025-47273Highsetuptools: setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File WriteCVE-2025-2099Mediumtransformers: Hugging Face Transformers Regular Expression Denial of ServiceCVE-2025-32962Mediumflask-appbuilder: Flask-AppBuilder open redirect vulnerability using HTTP host injectionCVE-2025-47774Lowvyper: Vyper's `slice()` may elide side-effects when output length is 0CVE-2025-47287Hightornado: Tornado vulnerable to excessive logging caused by malformed multipart form dataCVE-2025-47285Lowvyper: Vyper's `concat()` builtin may elide side-effects for zero-length argumentsCVE-2025-47783Highlabel-studio: label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.CVE-2025-47425Highreflex: Reflex vulnerable to private state fields modificationCVE-2025-47782Highmotioneye: motionEye vulnerable to RCE in add_camera Function Due to unsafe command executionCVE-2025-26864Mediumorg.apache.iotdb:node-commons: Apache IoTDB Discloses Sensitive Information via Log FilesCVE-2024-24780Criticalorg.apache.iotdb:iotdb-core: Apache IoTDB Vulnerable to Remote Code ExecutionCVE-2025-47278Lowflask: Flask uses fallback key instead of current signing keyCVE-2025-27696Mediumapache-superset: Apache Superset Allows Ownership TakeoverCVE-2025-1752Highllama-index: LlamaIndex Vulnerable to Denial of Service (DoS)CVE-2025-44021Lowironic: OpenStack Ironic fails to restrict paths used for file:// image URLsCVE-2025-32873MediumDjango: Django has a denial-of-service possibility in strip_tags()CVE-2025-30165Highvllm: Remote Code Execution Vulnerability in vLLM Multi-Node Cluster ConfigurationCVE-2025-29573MediumMezzanine: Mezzanine CMS Cross-Site Scripting (XSS) vulnerabilityCVE-2025-46726Highlangroid: Langroid Allows XXE Injection via XMLToolMessageCVE-2025-46730Mediummobsf: Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

Stop the waste.
Protect your environment with Kodem.