PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-6WJ5-5PGR-JWQ8Highopen-webui: Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability in api/chat/fileCVE-2024-7765Highh2o: H2O Vulnerable to Denial of Service (DoS) via Large GZIP ParsingCVE-2024-7045Mediumopen-webui: Open WebUI Has Improper Access Control Leading to Arbitrary Prompt ReadCVE-2024-7768Highh2o: H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` EndpointCVE-2024-7053Highopen-webui: Open WebUI Vulnerable to a Session Fixation AttackCVE-2024-7760Highaim: Aim vulnerable to Cross-Site Request ForgeryCVE-2024-7046Mediumopen-webui: Open WebUI Allows Viewing of Admin DetailsCVE-2024-7044Mediumopen-webui: Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File UploadCVE-2024-7033Mediumopen-webui: Open WebUI Allows Arbitrary File Write via the `download_model` EndpointCVE-2024-7039Highopen-webui: Open WebUI Allows Admin Deletion via API EndpointCVE-2024-6866Mediumflask-cors: Flask-CORS vulnerable to Improper Handling of Case SensitivityCVE-2024-6851Highaim: Aim Path Traversal vulnerabilityCVE-2024-6839Mediumflask-cors: Flask-CORS improper regex path matching vulnerabilityCVE-2024-6854Highh2o: H2O Vulnerable to Arbitrary File Overwrite via File ExportCVE-2024-6863Mediumh2o: H2O Vulnerable to Execution of Arbitrary FilesCVE-2024-6829Criticalaim: Aim External Control of File Name or Path vulnerabilityCVE-2024-7036Highopen-webui: Open WebUI Uncontrolled Resource Consumption vulnerabilityCVE-2024-7043Highopen-webui: Open WebUI Allows Arbitrary File Reading and DeletionCVE-2024-7034Mediumopen-webui: Open WebUI Allows Arbitrary File Write via the `/models/upload` EndpointCVE-2024-6825Highlitellm: LiteLLM Vulnerable to Remote Code Execution (RCE)CVE-2024-6844Mediumflask-cors: Flask-CORS allows for inconsistent CORS matchingCVE-2024-6982Highlollms: LoLLMS Code Injection vulnerabilityCVE-2024-6827Highgunicorn: Gunicorn HTTP Request/Response Smuggling vulnerabilityCVE-2024-6577Mediumtorchserve: TorchServe script references S3 bucket without ensuring ownership or confirming accessibilityCVE-2024-6838Mediummlflow: MLflow Uncontrolled Resource Consumption vulnerability

Stop the waste.
Protect your environment with Kodem.