PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-FJ43-3QMQ-673FMediumpicklescan: Picklescan failed to detect to some unsafe global function in Numpy libraryCVE-2025-46417Highpicklescan: Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificateCVE-2025-32013Criticallnbits: LNbits Lightning Network Payment System Vulnerable to Server-Side Request Forgery via LNURL Authentication CallbackCVE-2025-30473Highapache-airflow-providers-common-sql: Apache Airflow Common SQL Provider Vulnerable to SQL InjectionCVE-2025-27520Criticalbentoml: BentoML Allows Remote Code Execution (RCE) via Insecure DeserializationCVE-2025-30370Highjupyterlab-git: jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"CVE-2025-3163Mediumlmdeploy: InternLM LMDeploy code injection vulnerabilityCVE-2025-3162Mediumlmdeploy: LMDeploy Improper Input Validation VulnerabilityCVE-2025-2946Criticalpgadmin4: pgAdmin 4 Vulnerable to Cross-Site Scripting (XSS) via Query Result RenderingCVE-2025-2945Criticalpgadmin4: pgAdmin 4 Vulnerable to Remote Code ExecutionCVE-2025-27556MediumDjango: Django Potential Denial of Service (DoS) on Windows CVE-2025-3048Mediumaws-sam-cli: AWS SAM CLI Path Traversal allows file copy to local cacheCVE-2025-3047Mediumaws-sam-cli: AWS SAM CLI Path Traversal allows file copy to build containerCVE-2025-3001Lowtorch: PyTorch is vulnerable to memory corruption through its torch.lstm_cell functionCVE-2025-31116Mediummobsf: Mobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS RebindingCVE-2025-2999Mediumtorch: PyTorch is vulnerable to memory corruption through its unpack_sequence functionCVE-2025-3000Lowtorch: PyTorch is vulnerable to memory corruption through its torch.jit.script functionCVE-2025-2998Mediumtorch: PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence FunctionCVE-2025-2953Lowtorch: PyTorch susceptible to local Denial of ServiceCVE-2025-30358Highmesop: Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacksCVE-2025-30355Highmatrix-synapse: Synapse vulnerable to federation denial of service via malformed eventsGHSA-785H-76CM-CPMFLowdjango-tomselect: Django TomSelect incomplete escaping of dangerous characters in widget attributesCVE-2025-30217Mediumfrappe: Frappe has possibility of SQL injection due to improper validationsCVE-2025-30214Highfrappe: Frappe vulnerable to information disclosure leading to account takeoverCVE-2025-30213Mediumfrappe: Frappe has Possibility of Remote Code Execution due to improper validation

Stop the waste.
Protect your environment with Kodem.