PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-12910Mediumllama-index: LlamaIndex Uncontrolled Resource Consumption vulnerabilityCVE-2024-12909Criticalllama-index-packs-finchat: llama-index-packs-finchat SQL Injection vulnerabilityCVE-2024-6483Mediumaim: Aim Relative Path Traversal vulnerabilityCVE-2024-12911Highllama-index: LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure PermissionsGHSA-W466-2WFC-8G58Highopen-webui: Open WebUI has vulnerable dependency on starlette via fastapiCVE-2024-12778Highaim: Aim Uncontrolled Resource Consumption vulnerabilityCVE-2024-12720Mediumtransformers: Transformers Regular Expression Denial of Service (ReDoS) vulnerabilityCVE-2024-12537Highopen-webui: Open WebUI Uncontrolled Resource Consumption vulnerabilityCVE-2024-12376Highfschat: FastChat Server-Side Request Forgery vulnerabilityCVE-2024-12534Highopen-webui: Open WebUI Uncontrolled Resource Consumption vulnerabilityGHSA-564P-RX2Q-4C8VMediumbentoml: BentoML Open Redirect vulnerabilityCVE-2024-12761HighimaginAIry: imaginAIry Denial of Service (DoS) vulnerabilityCVE-2024-12704Highllama-index-core: LlamaIndex Improper Handling of Exceptional Conditions vulnerabilityCVE-2024-12777Mediumaim: Aim vulnerable to Synchronous Access of Remote Resource without TimeoutGHSA-HH3J-9M59-P8VCHighbentoml: BentoML vulnerable to Uncontrolled Resource ConsumptionCVE-2024-12217Mediumgradio: Gradio Path Traversal vulnerabilityCVE-2024-12215Highkedro: Kedro allows Remote Code Execution by Pulling Micro PackagesCVE-2024-12216Highgluoncv: GluonCV Arbitrary File Write via TarSlipCVE-2024-11958Criticalllama-index-retrievers-duckdb-retriever: LlamaIndex Retrievers Integration: DuckDBRetriever SQL InjectionCVE-2024-11602Highfeast: Feast Cross-Origin Resource Sharing vulnerabilityCVE-2024-11603Highfschat: FastChat Server-Side Request Forgery vulnerabilityCVE-2024-11043HighInvokeAI: InvokeAI Uncontrolled Resource Consumption vulnerabilityCVE-2024-11041Criticalvllm: vLLM Deserialization of Untrusted Data vulnerabilityCVE-2024-10908Mediumfschat: FastChat open redirect vulnerabilityCVE-2024-10940Mediumlangchain-core: langchain-core allows unauthorized users to read arbitrary files from the host file system

Stop the waste.
Protect your environment with Kodem.