VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2025-24359High· 8.4
1y ago

ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape

ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape

▾ Twilightasteval · astevalEPSS 0.28%via OSV
CVE-2025-22153High· 7.9
1y ago

try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter

try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter

▾ Twilightrestrictedpython · restrictedpythonEPSS 0.40%via OSV
CVE-2025-23205High
1y ago

nbgrader's `frame-ancestors: self` grants all users access to formgrader

nbgrader's `frame-ancestors: self` grants all users access to formgrader

▾ Twilightnbgrader · nbgraderEPSS 0.47%via OSV
CVE-2024-50633None· 0.0PoC
1y ago

Indico Insecure Access

Indico Insecure Access

▾ Twilightindico · indicoEPSS 0.63%via OSV
CVE-2025-21607Low
1y ago

Vyper Does Not Check the Success of Certain Precompile Calls

Vyper Does Not Check the Success of Certain Precompile Calls

▾ Sunlitvyper · vyperEPSS 0.65%via OSV
CVE-2024-56374Medium· 5.8
1y ago

Django has a potential denial-of-service vulnerability in IPv6 validation

Django has a potential denial-of-service vulnerability in IPv6 validation

▾ Sunlitdjango · djangoEPSS 1.9%via OSV
CVE-2023-1907High· 8.0
1y ago

pgAdmin has Incorrect Default Permissions

pgAdmin has Incorrect Default Permissions

▾ Twilightpgadmin4 · pgadmin4EPSS 0.45%via OSV
CVE-2025-22151Low· 3.7
1y ago

Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution

Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution

▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.38%via OSV
CVE-2024-55459Medium
1y ago

keras Path Traversal vulnerability

keras Path Traversal vulnerability

▾ Sunlitkeras · kerasEPSS 0.23%via OSV
CVE-2024-53526Medium· 6.4
1y ago

Composio Command Execution vulnerability

Composio Command Execution vulnerability

▾ Sunlitcomposio-claude · composio-claudeEPSS 0.59%via OSV
CVE-2024-45033Low
1y ago

Apache Airflow Fab Provider Insufficient Session Expiration vulnerability

Apache Airflow Fab Provider Insufficient Session Expiration vulnerability

▾ Sunlitapache-airflow-providers-fab · apache-airflow-providers-fabEPSS 0.95%via OSV
CVE-2024-53995LowPoC
1y ago

GHSL-2024-288: SickChill open redirect in login

GHSL-2024-288: SickChill open redirect in login

▾ Twilightsickchill · sickchillEPSS 0.97%via OSV
CVE-2025-21618High· 7.5
1y ago

NiceGUI On Air authentication issue

NiceGUI On Air authentication issue

▾ Twilightnicegui · niceguiEPSS 0.38%via OSV
CVE-2024-52294Medium· 4.3
1y ago

khoj has an IDOR in subscription management allows unauthorized subscription modifications

khoj has an IDOR in subscription management allows unauthorized subscription modifications

▾ Sunlitkhoj · khojEPSS 0.38%via OSV
CVE-2024-9774Medium· 6.5
1y ago

python-sql SQL injection vulnerability

python-sql SQL injection vulnerability

▾ Sunlitpython-sql · python-sqlEPSS 0.70%via OSV
CVE-2024-56509High· 8.6
1y ago

changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal

changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.70%via OSV
CVE-2024-39025High· 7.5
1y ago

Letta (previously MemGPT) incorrect access control vulnerability

Letta (previously MemGPT) incorrect access control vulnerability

▾ Twilightletta · lettaEPSS 0.40%via OSV
CVE-2024-12745High· 8.0
1y ago

Amazon Redshift Python Connector vulnerable to SQL Injection

Amazon Redshift Python Connector vulnerable to SQL Injection

▾ Twilightredshift-connector · redshift-connectorEPSS 0.53%via OSV
MAL-2025-923None
1y ago

Malicious code in fflask (PyPI)

Malicious code in fflask (PyPI)

▾ Sunlitfflask · fflaskvia OSV
CVE-2024-9427Medium· 5.4
1y ago

Koji Cross-site Scripting

Koji Cross-site Scripting

▾ Sunlitkoji · kojiEPSS 0.30%via OSV
CVE-2024-56326High· 7.8
1y ago

Jinja has a sandbox breakout through indirect reference to format method

Jinja has a sandbox breakout through indirect reference to format method

▾ Twilightjinja2 · jinja2EPSS 0.52%via OSV
CVE-2024-56201High· 8.8
1y ago

Jinja has a sandbox breakout through malicious filenames

Jinja has a sandbox breakout through malicious filenames

▾ Twilightjinja2 · jinja2EPSS 0.31%via OSV
CVE-2024-56327Critical· 9.8
1y ago

pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

▾ Midnightpyrage · pyrageEPSS 0.50%via OSV
CVE-2024-56142Medium· 6.5
1y ago

PGHoard Path Traversal vulnerability

PGHoard Path Traversal vulnerability

▾ Sunlitpghoard · pghoardEPSS 0.41%via OSV
CVE-2024-55890MediumPoC
1y ago

D-Tale allows Remote Code Execution through the Custom Filter Input

D-Tale allows Remote Code Execution through the Custom Filter Input

▾ Twilightdtale · dtaleEPSS 2.4%via OSV
CVE-2024-55633Medium· 6.5
1y ago

Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access

Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access

▾ Sunlitapache-superset · apache-supersetEPSS 2.8%via OSV
CVE-2024-55587High· 8.8PoC
1y ago

python-libarchive directory traversal

python-libarchive directory traversal

▾ Midnightpython-libarchive · python-libarchiveEPSS 2.1%via OSV
CVE-2024-55655Low
1y ago

sigstore has insufficient validation of integration timestamp during verification

sigstore has insufficient validation of integration timestamp during verification

▾ Sunlitsigstore · sigstoreEPSS 0.25%via OSV
CVE-2024-53947Critical· 9.8
1y ago

Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions

Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions

▾ Midnightapache-superset · apache-supersetEPSS 0.84%via OSV
CVE-2024-53949Medium· 6.5
1y ago

Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled

Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled

▾ Sunlitapache-superset · apache-supersetEPSS 0.72%via OSV
CVEs tagged “pip” — page 101 · VulnSea