VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2024-27763Medium· 5.3
1y ago

XPixelGroup BasicSR Command Injection

XPixelGroup BasicSR Command Injection

▾ Sunlitbasicsr · basicsrEPSS 0.23%via OSV
CVE-2025-1550HighPoC
1y ago

Arbitrary Code Execution via Crafted Keras Config for Model Loading

Arbitrary Code Execution via Crafted Keras Config for Model Loading

▾ Midnightkeras · kerasEPSS 2.6%via OSV
CVE-2025-24986Medium· 6.5
1y ago

Azure PromptFlow remote code execution related to Jinja templates

Azure PromptFlow remote code execution related to Jinja templates

▾ Sunlitpromptflow-tools · promptflow-toolsEPSS 0.53%via OSV
CVE-2025-26699Medium· 5.0
1y ago

Django vulnerable to Allocation of Resources Without Limits or Throttling

Django vulnerable to Allocation of Resources Without Limits or Throttling

▾ Sunlitdjango · djangoEPSS 0.81%via OSV
CVE-2025-1979Medium· 6.4
1y ago

ray vulnerable to Insertion of Sensitive Information into Log File

ray vulnerable to Insertion of Sensitive Information into Log File

▾ Sunlitray · rayEPSS 0.19%via OSV
CVE-2025-27516Medium· 7.3
1y ago

Jinja2 vulnerable to sandbox breakout through attr filter selecting format method

Jinja2 vulnerable to sandbox breakout through attr filter selecting format method

▾ Sunlitjinja2 · jinja2EPSS 0.50%via OSV
CVE-2025-25362Critical· 9.8
1y ago

Spacy-LLM Server-Side Template Injection (SSTI) vulnerability

Spacy-LLM Server-Side Template Injection (SSTI) vulnerability

▾ Midnightspacy-llm · spacy-llmEPSS 0.80%via OSV
CVE-2025-24023Low· 3.7
1y ago

Flask-AppBuilder Observable Response Discrepancy

Flask-AppBuilder Observable Response Discrepancy

▾ Sunlitflask-appbuilder · flask-appbuilderEPSS 0.33%via OSV
CVE-2025-1716Critical· 9.8PoC
1y ago

picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft …

picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and include a malicious pickle file with a non-standard file exte…

▾ Abyssalpicklescan · picklescanEPSS 1.7%via OSV
CVE-2025-1300Medium· 6.1
1y ago

CodeChecker open redirect when URL contains multiple slashes after the product name

CodeChecker open redirect when URL contains multiple slashes after the product name

▾ Sunlitcodechecker · codecheckerEPSS 0.27%via OSV
CVE-2025-27154High
1y ago

Spotipy's cache file, containing spotify auth token, is created with overly broad permissions

Spotipy's cache file, containing spotify auth token, is created with overly broad permissions

▾ Twilightspotipy · spotipyEPSS 0.61%via OSV
CVE-2025-27145Low· 3.6
1y ago

copyparty renders unsanitized filenames as HTML when user uploads empty files

copyparty renders unsanitized filenames as HTML when user uploads empty files

▾ Sunlitcopyparty · copypartyEPSS 0.47%via OSV
CVE-2025-1403High· 8.6
1y ago

Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit

Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit

▾ Twilightqiskit · qiskitEPSS 0.72%via OSV
CVE-2025-26623Medium
1y ago

Exiv2 allows Use After Free

Exiv2 allows Use After Free

▾ Sunlitexiv2 · exiv2EPSS 0.92%via OSV
CVE-2025-25305High· 7.0
1y ago

Home Assistant does not correctly validate SSL for outgoing requests in core and used libs

Home Assistant does not correctly validate SSL for outgoing requests in core and used libs

▾ Twilighthomeassistant · homeassistantEPSS 0.25%via OSV
CVE-2025-25296Medium· 6.1PoC
1y ago

Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint

Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint

▾ Twilightlabel-studio · label-studioEPSS 1.9%via OSV
CVE-2025-25295High
1y ago

Label Studio has a Path Traversal Vulnerability via image Field

Label Studio has a Path Traversal Vulnerability via image Field

▾ Twilightlabel-studio-sdk · label-studio-sdkEPSS 0.76%via OSV
CVE-2025-25297High· 8.6
1y ago

Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint

Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint

▾ Twilightlabel-studio · label-studioEPSS 0.67%via OSV
CVE-2024-12366Critical· 9.8
1y ago

PandasAI interactive prompt function Remote Code Execution (RCE)

PandasAI interactive prompt function Remote Code Execution (RCE)

▾ Midnightpandasai · pandasaiEPSS 1.2%via OSV
CVE-2024-12797Low
1y ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

▾ Sunlitcryptography · cryptographyEPSS 2.5%via OSV
CVE-2025-25183Low· 2.6
1y ago

vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache

vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache

▾ Sunlitvllm · vllmEPSS 0.19%via OSV
CVE-2025-23217High
1y ago

Mitmweb API Authentication Bypass Using Proxy Server

Mitmweb API Authentication Bypass Using Proxy Server

▾ Twilightmitmproxy · mitmproxyEPSS 0.83%via OSV
CVE-2025-24804Medium· 6.5
1y ago

MobSF Partial Denial of Service (DoS)

MobSF Partial Denial of Service (DoS)

▾ Sunlitmobsf · mobsfEPSS 0.46%via OSV
CVE-2025-24803High· 8.1
1y ago

MobSF Stored Cross-Site Scripting (XSS)

MobSF Stored Cross-Site Scripting (XSS)

▾ Twilightmobsf · mobsfEPSS 0.39%via OSV
CVE-2025-24372High· 7.3
1y ago

CKAN has an XSS vector in user uploaded images in group/org and user profiles

CKAN has an XSS vector in user uploaded images in group/org and user profiles

▾ Twilightckan · ckanEPSS 0.46%via OSV
CVE-2025-24805Medium· 6.5
1y ago

MobSF Local Privilege Escalation

MobSF Local Privilege Escalation

▾ Sunlitmobsf · mobsfEPSS 0.36%via OSV
CVE-2025-24795Medium· 4.4
1y ago

snowflake-connector-python vulnerable to insecure cache files permissions

snowflake-connector-python vulnerable to insecure cache files permissions

▾ Sunlitsnowflake-connector-python · snowflake-connector-pythonEPSS 0.14%via OSV
CVE-2025-24794Medium· 6.7
1y ago

snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache

snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache

▾ Sunlitsnowflake-connector-python · snowflake-connector-pythonEPSS 0.25%via OSV
CVE-2025-24793High· 7.0
1y ago

snowflake-connector-python vulnerable to SQL Injection in write_pandas

snowflake-connector-python vulnerable to SQL Injection in write_pandas

▾ Twilightsnowflake-connector-python · snowflake-connector-pythonEPSS 0.31%via OSV
CVE-2025-24357High· 7.5
1y ago

vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

▾ Twilightvllm · vllmEPSS 0.70%via OSV
CVEs tagged “pip” — page 100 · VulnSea