PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-27154Highspotipy: Spotipy's cache file, containing spotify auth token, is created with overly broad permissionsCVE-2025-27145Lowcopyparty: copyparty renders unsanitized filenames as HTML when user uploads empty filesCVE-2023-25574Criticaljupyterhub-ltiauthenticator: LTI JupyterHub Authenticator does not properly validate JWT SignatureCVE-2025-26623MediumExiv2: Exiv2 allows Use After FreeCVE-2025-27104Lowvyper: Vyper has a double eval in For List IterCVE-2025-27105Lowvyper: AugAssign evaluation order causing OOB write within the object in VyperCVE-2025-26622Lowvyper: Vyper's sqrt doesn't define rounding behaviorCVE-2025-1403Highqiskit: Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in QiskitCVE-2025-25305Highhomeassistant: Home Assistant does not correctly validate SSL for outgoing requests in core and used libsCVE-2025-1057Mediumkeylime: Keylime registrar is vulnerable to Denial-of-Service attack when updated to version 7.12.0CVE-2025-25297Highlabel-studio: Label Studio allows Server-Side Request Forgery in the S3 Storage EndpointCVE-2025-25296Mediumlabel-studio: Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpointCVE-2025-25295Highlabel-studio-sdk: Label Studio has a Path Traversal Vulnerability via image FieldCVE-2024-12797Lowcryptography: Vulnerable OpenSSL included in cryptography wheelsCVE-2024-12366Criticalpandasai: PandasAI interactive prompt function Remote Code Execution (RCE)GHSA-432C-WXPG-M4Q3Mediumxml2rfc: xml2rfc has file inclusion irregularitiesCVE-2025-25183Lowvllm: vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cacheCVE-2025-23217Highmitmproxy: Mitmweb API Authentication Bypass Using Proxy ServerCVE-2025-24805Highmobsf: MobSF Local Privilege EscalationCVE-2025-24804Highmobsf: MobSF Partial Denial of Service (DoS)CVE-2025-24803Highmobsf: MobSF Stored Cross-Site Scripting (XSS)CVE-2025-24372Highckan: CKAN has an XSS vector in user uploaded images in group/org and user profilesCVE-2025-24370Criticaldjango-unicorn: Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication BypassCVE-2025-24793Highsnowflake-connector-python: snowflake-connector-python vulnerable to SQL Injection in write_pandasCVE-2025-24794Mediumsnowflake-connector-python: snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache

Stop the waste.
Protect your environment with Kodem.