Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2025-24359High· 8.4ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape
ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape
CVE-2025-22153High· 7.9try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter
try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter
CVE-2025-23205Highnbgrader's `frame-ancestors: self` grants all users access to formgrader
nbgrader's `frame-ancestors: self` grants all users access to formgrader
CVE-2024-50633None· 0.0PoCIndico Insecure Access
Indico Insecure Access
CVE-2025-21607LowVyper Does Not Check the Success of Certain Precompile Calls
Vyper Does Not Check the Success of Certain Precompile Calls
CVE-2024-56374Medium· 5.8Django has a potential denial-of-service vulnerability in IPv6 validation
Django has a potential denial-of-service vulnerability in IPv6 validation
CVE-2023-1907High· 8.0pgAdmin has Incorrect Default Permissions
pgAdmin has Incorrect Default Permissions
CVE-2025-22151Low· 3.7Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
CVE-2024-55459Mediumkeras Path Traversal vulnerability
keras Path Traversal vulnerability
CVE-2024-53526Medium· 6.4Composio Command Execution vulnerability
Composio Command Execution vulnerability
CVE-2024-45033LowApache Airflow Fab Provider Insufficient Session Expiration vulnerability
Apache Airflow Fab Provider Insufficient Session Expiration vulnerability
CVE-2024-53995LowPoCGHSL-2024-288: SickChill open redirect in login
GHSL-2024-288: SickChill open redirect in login
CVE-2025-21618High· 7.5NiceGUI On Air authentication issue
NiceGUI On Air authentication issue
CVE-2024-52294Medium· 4.3khoj has an IDOR in subscription management allows unauthorized subscription modifications
khoj has an IDOR in subscription management allows unauthorized subscription modifications
CVE-2024-9774Medium· 6.5python-sql SQL injection vulnerability
python-sql SQL injection vulnerability
CVE-2024-56509High· 8.6changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal
changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal
CVE-2024-39025High· 7.5Letta (previously MemGPT) incorrect access control vulnerability
Letta (previously MemGPT) incorrect access control vulnerability
CVE-2024-12745High· 8.0Amazon Redshift Python Connector vulnerable to SQL Injection
Amazon Redshift Python Connector vulnerable to SQL Injection
MAL-2025-923NoneMalicious code in fflask (PyPI)
Malicious code in fflask (PyPI)
CVE-2024-9427Medium· 5.4Koji Cross-site Scripting
Koji Cross-site Scripting
CVE-2024-56326High· 7.8Jinja has a sandbox breakout through indirect reference to format method
Jinja has a sandbox breakout through indirect reference to format method
CVE-2024-56201High· 8.8Jinja has a sandbox breakout through malicious filenames
Jinja has a sandbox breakout through malicious filenames
CVE-2024-56327Critical· 9.8pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
CVE-2024-56142Medium· 6.5PGHoard Path Traversal vulnerability
PGHoard Path Traversal vulnerability
CVE-2024-55890MediumPoCD-Tale allows Remote Code Execution through the Custom Filter Input
D-Tale allows Remote Code Execution through the Custom Filter Input
CVE-2024-55633Medium· 6.5Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
CVE-2024-55587High· 8.8PoCpython-libarchive directory traversal
python-libarchive directory traversal
CVE-2024-55655Lowsigstore has insufficient validation of integration timestamp during verification
sigstore has insufficient validation of integration timestamp during verification
CVE-2024-53947Critical· 9.8Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
CVE-2024-53949Medium· 6.5Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled