PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-8537Criticalagentscope: AgentScope path traversal vulnerabilityCVE-2024-8502Criticalagentscope: AgentScope Deserialization VulnerabilityCVE-2024-8769Criticalaim: Aim path traversal in LockManager.release_locksCVE-2024-8551Criticalagentscope: AgentScope path traversal vulnerability in save-workflowCVE-2024-8616Highh2o: H2O Vulnerable to Arbitrary File OverwriteCVE-2024-8556Mediumagentscope: AgentScope stored cross-site scripting (XSS) vulnerabilityCVE-2024-8487Highagentscope: AgentScope Cross-Origin Resource Sharing (CORS) vulnerabilityCVE-2024-8524Highagentscope: AgentScope directory traversal vulnerability in /read-examplesCVE-2024-8501Highagentscope: AgentScope arbitrary file download vulnerability in rpc_agent_clientCVE-2024-8438Highagentscope: AgentScope Path Traversal in /api/fileCVE-2024-8183Highprefect: Prefect CORS (Cross-Origin Resource Sharing) misconfigurationCVE-2024-8060Highopen-webui: Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptionsCVE-2024-8053Highopen-webui: Open WebUI lacks authentication for the `api/v1/utils/pdf` endpointCVE-2024-8061Highaim: Aim allows denial of service due to no timeouts for some tracking server endpointsCVE-2024-8238Mediumaim: Aim Improper Access ControlCVE-2024-7983Highopen-webui: Open WebUI denial of service through endpoint for converting markdownCVE-2024-7990Highopen-webui: Open WebUI stored cross-site scripting (XSS) vulnerabilityCVE-2024-8020Highpytorch-lightning: PyTorch Lightning denial of service vulnerabilityCVE-2024-8021Mediumgradio: Gradio Vulnerable to Open RedirectCVE-2024-8062Highh2o: H2O Vulnerable to Denial of Service (DoS) via `HEAD` RequestCVE-2024-7035Mediumopen-webui: Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)CVE-2024-7776Highonnx: Open Neural Network Exchange (ONNX) Path Traversal VulnerabilityCVE-2024-7806Highopen-webui: Open WebUI Cross-Site Request Forgery (CSRF) VulnerabilityCVE-2024-8019Criticalpytorch-lightning: PyTorch Lightning path traversal vulnerabilityCVE-2024-7959Highopen-webui: Open WebUI has SSRF in /openai/models

Stop the waste.
Protect your environment with Kodem.