PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-9277Mediumlangflow: Inefficient Regular Expression Complexity in langflowCVE-2024-1728Criticalgradio: Gradio allows users to access arbitrary filesCVE-2024-46488Highsqlite-vec: Heap-based Buffer Overflow in sqlite-vecCVE-2024-47082Mediumstrawberry-graphql: Cross-Site Request Forgery (CSRF) in strawberry-graphqlCVE-2024-9014Highpgadmin4: OAuth2 client ID and secret exposed through the web browserCVE-2024-45793Mediumconfidant: Prevent XSS from Confidant API callCVE-2024-8375Mediumdm-reverb: Reverb use after free vulnerabilityCVE-2024-46946Criticallangchain-experimental: LangChain Experimental Eval Injection vulnerabilityCVE-2024-45601Highmesop: Mesop has a local file Inclusion via static file serving functionalityCVE-2024-35515Highsqlitedict: sqlitedict insecure deserialization vulnerabilityCVE-2024-45858Highguardrails-ai: Guardrails has an arbitrary code execution vulnerabilityCVE-2024-8946Mediummicropython-copy: Heap-based Buffer Overflow in MicroPythonCVE-2024-8948Mediummicropython-copy: heap-buffer-overflow in MicroPythonCVE-2024-8947Mediummicropython-copy: Use After Free in MicroPythonCVE-2024-8768Highvllm: vLLM denial of service vulnerabilityCVE-2024-8939Mediumvllm: vLLM Denial of Service via the best_of parameterCVE-2024-45606Highsentry: Sentry improperly authorizes muting of alert rulesCVE-2024-45605Highsentry: Sentry improperly authorizes deletion of user issue alert notificationsCVE-2024-5998Highlangchain-community: LangChain pickle deserialization of untrusted dataCVE-2024-8865Mediumcomposio-core: Composio Path Traversal vulnerabilityCVE-2024-8862Mediumdtale: D-Tale Command Execution VulnerabilityCVE-2024-8864Mediumcomposio-core: Composio Code Injection VulnerabilityCVE-2024-8863Mediumaim: Aim Stored XSS through TEXT EXPLORERCVE-2024-8775Highansible-core: Ansible vulnerable to Insertion of Sensitive Information into Log FileCVE-2024-6587Highlitellm: LiteLLM Server-Side Request Forgery (SSRF) vulnerability

Stop the waste.
Protect your environment with Kodem.