PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-24795Mediumsnowflake-connector-python: snowflake-connector-python vulnerable to insecure cache files permissionsCVE-2025-24357Highvllm: vllm: Malicious model to RCE by torch.load in hf_model_weights_iteratorGHSA-GVVW-RR8M-FJ76Highuniapi: uniapi version 1.0.7 contained an information harvesting script.CVE-2025-24359Highasteval: ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox EscapeGHSA-VP47-9734-PRJWHighasteval: ASTEVAL Allows Malicious Tampering of Exposed AST Nodes Leads to Sandbox EscapeCVE-2025-22153HighRestrictedPython: try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreterCVE-2024-41672Highduckdb: sniff_csv provides filesystem access even when enable_external_access is disabled in duckdbCVE-2024-53829Highcodechecker: Cross-Site Request Forgery in CodeChecker APICVE-2025-23205Highnbgrader: nbgrader's `frame-ancestors: self` grants all users access to formgraderCVE-2024-50633Mediumindico: Indico Insecure AccessCVE-2025-22146Criticalsentry: Sentry's improper authentication on SAML SSO process allows user impersonationCVE-2024-56374MediumDjango: Django has a potential denial-of-service vulnerability in IPv6 validationCVE-2025-21607Lowvyper: Vyper Does Not Check the Success of Certain Precompile CallsCVE-2025-23042Criticalgradio: Gradio Blocked Path ACL Bypass VulnerabilityCVE-2024-49375Criticalrasa-pro: Rasa Allows Remote Code Execution via Remote Model LoadingCVE-2025-22151Lowstrawberry-graphql: Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolutionCVE-2023-1907Highpgadmin4: pgAdmin has Incorrect Default PermissionsCVE-2024-53995Lowsickchill: GHSL-2024-288: SickChill open redirect in loginCVE-2024-53526Mediumcomposio-claude: Composio Command Execution vulnerabilityCVE-2024-55459Mediumkeras: keras Path Traversal vulnerabilityCVE-2024-45033Lowapache-airflow-providers-fab: Apache Airflow Fab Provider Insufficient Session Expiration vulnerabilityCVE-2025-21618Highnicegui: NiceGUI On Air authentication issueCVE-2024-52294Mediumkhoj: khoj has an IDOR in subscription management allows unauthorized subscription modificationsCVE-2024-39025Highletta: Letta (previously MemGPT) incorrect access control vulnerabilityCVE-2024-56509Highchangedetection.io: changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal

Stop the waste.
Protect your environment with Kodem.