Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2024-27763Medium· 5.3XPixelGroup BasicSR Command Injection
XPixelGroup BasicSR Command Injection
CVE-2025-1550HighPoCArbitrary Code Execution via Crafted Keras Config for Model Loading
Arbitrary Code Execution via Crafted Keras Config for Model Loading
CVE-2025-24986Medium· 6.5Azure PromptFlow remote code execution related to Jinja templates
Azure PromptFlow remote code execution related to Jinja templates
CVE-2025-26699Medium· 5.0Django vulnerable to Allocation of Resources Without Limits or Throttling
Django vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2025-1979Medium· 6.4ray vulnerable to Insertion of Sensitive Information into Log File
ray vulnerable to Insertion of Sensitive Information into Log File
CVE-2025-27516Medium· 7.3Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
CVE-2025-25362Critical· 9.8Spacy-LLM Server-Side Template Injection (SSTI) vulnerability
Spacy-LLM Server-Side Template Injection (SSTI) vulnerability
CVE-2025-24023Low· 3.7Flask-AppBuilder Observable Response Discrepancy
Flask-AppBuilder Observable Response Discrepancy
CVE-2025-1716Critical· 9.8PoCpicklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft …
picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and include a malicious pickle file with a non-standard file exte…
CVE-2025-1300Medium· 6.1CodeChecker open redirect when URL contains multiple slashes after the product name
CodeChecker open redirect when URL contains multiple slashes after the product name
CVE-2025-27154HighSpotipy's cache file, containing spotify auth token, is created with overly broad permissions
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
CVE-2025-27145Low· 3.6copyparty renders unsanitized filenames as HTML when user uploads empty files
copyparty renders unsanitized filenames as HTML when user uploads empty files
CVE-2025-1403High· 8.6Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
CVE-2025-26623MediumExiv2 allows Use After Free
Exiv2 allows Use After Free
CVE-2025-25305High· 7.0Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
CVE-2025-25296Medium· 6.1PoCLabel Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
CVE-2025-25295HighLabel Studio has a Path Traversal Vulnerability via image Field
Label Studio has a Path Traversal Vulnerability via image Field
CVE-2025-25297High· 8.6Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
CVE-2024-12366Critical· 9.8PandasAI interactive prompt function Remote Code Execution (RCE)
PandasAI interactive prompt function Remote Code Execution (RCE)
CVE-2024-12797LowVulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2025-25183Low· 2.6vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
CVE-2025-23217HighMitmweb API Authentication Bypass Using Proxy Server
Mitmweb API Authentication Bypass Using Proxy Server
CVE-2025-24804Medium· 6.5MobSF Partial Denial of Service (DoS)
MobSF Partial Denial of Service (DoS)
CVE-2025-24803High· 8.1MobSF Stored Cross-Site Scripting (XSS)
MobSF Stored Cross-Site Scripting (XSS)
CVE-2025-24372High· 7.3CKAN has an XSS vector in user uploaded images in group/org and user profiles
CKAN has an XSS vector in user uploaded images in group/org and user profiles
CVE-2025-24805Medium· 6.5MobSF Local Privilege Escalation
MobSF Local Privilege Escalation
CVE-2025-24795Medium· 4.4snowflake-connector-python vulnerable to insecure cache files permissions
snowflake-connector-python vulnerable to insecure cache files permissions
CVE-2025-24794Medium· 6.7snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache
snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache
CVE-2025-24793High· 7.0snowflake-connector-python vulnerable to SQL Injection in write_pandas
snowflake-connector-python vulnerable to SQL Injection in write_pandas
CVE-2025-24357High· 7.5vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator