VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4537 CVEsRSS

MAL-2026-16346Critical⚠ Exploited
today

Malicious code in rrs (PyPI)

Malicious code in rrs (PyPI)

Abyssalrrs · rrsvia OSV
CVE-2026-55074High· 8.2
today

Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec

Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and r…

Twilightchofstede · ansible_jailexecvia NVD
CVE-2026-55071High· 8.4PoC
today

MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design

MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command stri…

MidnightSepineTam · mcp-for-statavia NVD
MAL-2026-16298Critical⚠ Exploited
2d ago

Malicious code in urc (PyPI)

Malicious code in urc (PyPI)

Abyssalurc · urcvia OSV
MAL-2026-16296Critical⚠ Exploited
3d ago

Malicious code in py-venv-doctor (PyPI)

Malicious code in py-venv-doctor (PyPI)

Abyssalpy-venv-doctor · py-venv-doctorvia OSV
CVE-2026-59163Critical· 9.1PoC
3d ago

Mnemosyne is a memory layer for artificial intelligence agents

Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with…

Abyssalmnemosyne-memory · mnemosyne-memoryEPSS 0.25%via NVD
CVE-2025-66455Critical· 9.8
3d ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize m…

MidnightInternLM · lmdeployEPSS 0.70%via NVD
GHSA-39wr-7q6h-cf68High· 7.5
3d ago

LMDeploy has an SSRF bypass

LMDeploy has an SSRF bypass

Twilightlmdeploy · lmdeployvia OSV
CVE-2026-33625High· 8.8
3d ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitra…

TwilightInternLM · lmdeployEPSS 0.24%via NVD
CVE-2026-64847Medium· 6.8
3d ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains,…

Sunlitagronholm · anyioEPSS 0.12%via NVD
CVE-2026-63374Critical
3d ago

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

Midnightanyio · anyiovia OSV
CVE-2026-63349High· 7.0
3d ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_proce…

Twilightanyio · anyioEPSS 0.11%via NVD
MAL-2026-16275Critical⚠ Exploited
4d ago

Malicious code in requests-triwes (PyPI)

Malicious code in requests-triwes (PyPI)

Abyssalrequests-triwes · requests-triwesvia OSV
MAL-2026-16274Critical⚠ Exploited
4d ago

Malicious code in requests-auroras (PyPI)

Malicious code in requests-auroras (PyPI)

Abyssalrequests-auroras · requests-aurorasvia OSV
MAL-2026-16269Critical⚠ Exploited
4d ago

Malicious code in requests-asetwe (PyPI)

Malicious code in requests-asetwe (PyPI)

Abyssalrequests-asetwe · requests-asetwevia OSV
MAL-2026-16268Critical⚠ Exploited
4d ago

Malicious code in index-forum (PyPI)

Malicious code in index-forum (PyPI)

Abyssalindex-forum · index-forumvia OSV
MAL-2026-16267Critical⚠ Exploited
4d ago

Malicious code in pyjstat-smooth (PyPI)

Malicious code in pyjstat-smooth (PyPI)

Abyssalpyjstat-smooth · pyjstat-smoothvia OSV
MAL-2026-16264Critical⚠ Exploited
4d ago

Malicious code in aiosendletter (PyPI)

Malicious code in aiosendletter (PyPI)

Abyssalaiosendletter · aiosendlettervia OSV
GHSA-xjw9-38cr-6372High
4d ago

djust: A template binding inherits a context safety grant it never earned (XSS)

djust: A template binding inherits a context safety grant it never earned (XSS)

Twilightdjust · djustvia OSV
GHSA-9395-2g46-rj3fHigh
4d ago

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

Twilightdjust · djustvia OSV
CVE-2026-86049High· 7.1
4d ago

Jupyter Server is the backend for Jupyter web applications

Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for t…

Twilightjupyter-server · jupyter_serverEPSS 0.24%via NVD
CVE-2026-86000Medium· 5.3PoC
4d ago

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and V…

Twilightfacelessuser · soupsieveEPSS 0.44%via NVD
CVE-2026-85999Medium· 5.3
4d ago

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used …

Sunlitfacelessuser · soupsieveEPSS 0.35%via NVD
MAL-2026-16250Critical⚠ Exploited
4d ago

Malicious code in marketing-mcp (PyPI)

Malicious code in marketing-mcp (PyPI)

Abyssalmarketing-mcp · marketing-mcpvia OSV
CVE-2026-85078Medium· 6.5
4d ago

Sanic is an opensource python web server/framework

Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer.…

Sunlitsanic-org · sanicEPSS 0.30%via NVD
CVE-2026-54446High· 8.1PoC
4d ago

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-ne…

MidnightLabs64 · NetLicensing-MCPEPSS 0.47%via NVD
CVE-2026-49292Low· 0.0
4d ago

Kiwi TCMS is an open source test management system

Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migra…

Sunlitkiwitcms · KiwiEPSS 0.26%via NVD
MAL-2026-16242Critical⚠ Exploited
5d ago

Malicious code in trongappy (PyPI)

Malicious code in trongappy (PyPI)

Abyssaltrongappy · trongappyvia OSV
MAL-2026-16241Critical⚠ Exploited
5d ago

Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)

Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)

Abyssalrak-lab-yoav-orca-zrktd2cp5hjmo4x7 · rak-lab-yoav-orca-zrktd2cp5hjmo4x7via OSV
MAL-2026-16240Critical⚠ Exploited
5d ago

Malicious code in praetorian-mind-rce-test-2026 (PyPI)

Malicious code in praetorian-mind-rce-test-2026 (PyPI)

Abyssalpraetorian-mind-rce-test-2026 · praetorian-mind-rce-test-2026via OSV
CVEs tagged “pip” · VulnSea