Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2024-46455Mediumunstructured XML External Entity (XXE)
unstructured XML External Entity (XXE)
CVE-2024-53948Medium· 5.3Apache Superset: Error verbosity exposes metadata in analytics databases
Apache Superset: Error verbosity exposes metadata in analytics databases
CVE-2024-53908Critical· 9.8Django SQL injection in HasKey(lhs, rhs) on Oracle
Django SQL injection in HasKey(lhs, rhs) on Oracle
CVE-2024-53907High· 7.5Django denial-of-service in django.utils.html.strip_tags()
Django denial-of-service in django.utils.html.strip_tags()
CVE-2024-39163High· 8.8pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints
pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints
CVE-2024-53863HighSynapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
CVE-2024-52805HighSynapse allows unsupported content types to lead to memory exhaustion
Synapse allows unsupported content types to lead to memory exhaustion
CVE-2024-52815HighSynapse allows a a malformed invite to break the invitee's `/sync`
Synapse allows a a malformed invite to break the invitee's `/sync`
CVE-2024-53999Medium· 6.1Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality
Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality
CVE-2024-53867Medium· 4.3Synapse Matrix has a partial room state leak via Sliding Sync
Synapse Matrix has a partial room state leak via Sliding Sync
CVE-2024-53848High· 7.1check-jsonschema default caching for remote schemas allows for cache confusion
check-jsonschema default caching for remote schemas allows for cache confusion
CVE-2024-53865High· 8.2Python package "zhmcclient" stores passwords in clear text in its HMC and API logs
Python package "zhmcclient" stores passwords in clear text in its HMC and API logs
CVE-2024-53861Low· 2.2PyJWT Issuer field partial matches allowed
PyJWT Issuer field partial matches allowed
CVE-2024-53981High· 7.5Denial of service (DoS) via deformation `multipart/form-data` boundary
Denial of service (DoS) via deformation `multipart/form-data` boundary
CVE-2024-39162Medium· 6.1pyspider Cross-site Scripting vulnerability
pyspider Cross-site Scripting vulnerability
CVE-2024-52008Medium· 5.7Password Policy Bypass Vulnerability in Fides Webserver User Accept Invite API
Password Policy Bypass Vulnerability in Fides Webserver User Accept Invite API
CVE-2024-53916High· 7.5OpenStack Neutron can use an incorrect ID during policy enforcement
OpenStack Neutron can use an incorrect ID during policy enforcement
CVE-2024-52787Critical· 9.1libre-chat Path Traversal vulnerability
libre-chat Path Traversal vulnerability
CVE-2024-53899High· 8.4virtualenv allows command injection through activation scripts for a virtual environment
virtualenv allows command injection through activation scripts for a virtual environment
CVE-2024-11393High· 8.80dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11392High· 7.50dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11394High· 8.80dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-52804High· 7.5Tornado has an HTTP cookie parsing DoS vulnerability
Tornado has an HTTP cookie parsing DoS vulnerability
CVE-2023-40017High· 7.5GeoNode Server Side Request forgery
GeoNode Server Side Request forgery
CVE-2024-52803High· 7.5LLama Factory Remote OS Command Injection Vulnerability
LLama Factory Remote OS Command Injection Vulnerability
CVE-2024-11406Medium· 6.9django CMS Attributes Field Cross-site Scripting
django CMS Attributes Field Cross-site Scripting
CVE-2024-11404Medium· 5.5Django Filer Unrestricted Upload of File with Dangerous Type
Django Filer Unrestricted Upload of File with Dangerous Type
CVE-2024-52581High· 7.5Litestar allows unbounded resource consumption (DoS vulnerability)
Litestar allows unbounded resource consumption (DoS vulnerability)
CVE-2024-52304Mediumaiohttp allows request smuggling due to incorrect parsing of chunk extensions
aiohttp allows request smuggling due to incorrect parsing of chunk extensions
CVE-2024-52303High· 7.5aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method