PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-11042CriticalInvokeAI: InvokeAI Arbitrary File Deletion vulnerabilityCVE-2024-10907Highfschat: FastChat Uncontrolled Resource Consumption vulnerabilityCVE-2024-10912Highfschat: FastChat Denial of Service vulnerabilityCVE-2024-10901Criticaldbgpt: DB-GPT Arbitrary File Write vulnerabilityCVE-2024-10831Criticaldbgpt: DB-GPT Absolute Path Traversal vulnerabilityCVE-2024-10821HighInvokeAI: InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`CVE-2024-10835Criticaldbgpt: DB-GPT is vulnerable to SQL Injection attacks from unauthenticated usersCVE-2024-10830Highdbgpt: DB-GPT Path Traversal vulnerabilityCVE-2024-10713Highhyperlpr3: HyperLPR Denial of Service vulnerabilityCVE-2024-10833Criticaldbgpt: DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/uploadCVE-2024-10829Highdbgpt: DB-GPT Uncontrolled Resource Consumption vulnerabilityCVE-2024-10902Criticaldbgpt: DB-GPT vulnerable to Arbitrary File Upload with Path TraversalCVE-2024-10906Highdbgpt: DB-GPT vulnerable to Cross-Site Request ForgeryCVE-2024-10550Highh2o: H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` EndpointCVE-2024-10648Highgradio: Gradio Vulnerable to Arbitrary File DeletionCVE-2024-10553Criticalh2o: H2O Deserialization of Untrusted Data VulnerabilityCVE-2024-10572Highh2o: H2O Vulnerable to Denial of Service (DoS) and File WriteCVE-2024-10624Highgradio: Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP RequestCVE-2024-10569Highgradio: Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip BombCVE-2024-10549Highh2o: H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` EndpointCVE-2024-10188Highlitellm: LiteLLM Vulnerable to Denial of Service (DoS)CVE-2024-10110Highaim: Aim Vulnerable to Denial of Service (DoS)CVE-2024-10190Criticalhorovod: Horovod Vulnerable to Command InjectionCVE-2025-29783Criticalvllm: vLLM Allows Remote Code Execution via Mooncake IntegrationCVE-2025-29770Mediumvllm: vLLM denial of service via outlines unbounded cache on disk

Stop the waste.
Protect your environment with Kodem.