VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2024-46455Medium
1y ago

unstructured XML External Entity (XXE)

unstructured XML External Entity (XXE)

▾ Sunlitunstructured · unstructuredEPSS 0.57%via OSV
CVE-2024-53948Medium· 5.3
1y ago

Apache Superset: Error verbosity exposes metadata in analytics databases

Apache Superset: Error verbosity exposes metadata in analytics databases

▾ Sunlitapache-superset · apache-supersetEPSS 0.85%via OSV
CVE-2024-53908Critical· 9.8
1y ago

Django SQL injection in HasKey(lhs, rhs) on Oracle

Django SQL injection in HasKey(lhs, rhs) on Oracle

▾ Midnightdjango · djangoEPSS 1.4%via OSV
CVE-2024-53907High· 7.5
1y ago

Django denial-of-service in django.utils.html.strip_tags()

Django denial-of-service in django.utils.html.strip_tags()

▾ Twilightdjango · djangoEPSS 1.4%via OSV
CVE-2024-39163High· 8.8
1y ago

pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints

pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints

▾ Twilightpyspider · pyspiderEPSS 0.23%via OSV
CVE-2024-53863High
1y ago

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

▾ Twilightmatrix-synapse · matrix-synapseEPSS 0.61%via OSV
CVE-2024-52805High
1y ago

Synapse allows unsupported content types to lead to memory exhaustion

Synapse allows unsupported content types to lead to memory exhaustion

▾ Twilightmatrix-synapse · matrix-synapseEPSS 0.74%via OSV
CVE-2024-52815High
1y ago

Synapse allows a a malformed invite to break the invitee's `/sync`

Synapse allows a a malformed invite to break the invitee's `/sync`

▾ Twilightmatrix-synapse · matrix-synapseEPSS 0.57%via OSV
CVE-2024-53999Medium· 6.1
1y ago

Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality

Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality

▾ Sunlitmobsf · mobsfEPSS 0.52%via OSV
CVE-2024-53867Medium· 4.3
1y ago

Synapse Matrix has a partial room state leak via Sliding Sync

Synapse Matrix has a partial room state leak via Sliding Sync

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.44%via OSV
CVE-2024-53848High· 7.1
1y ago

check-jsonschema default caching for remote schemas allows for cache confusion

check-jsonschema default caching for remote schemas allows for cache confusion

▾ Twilightcheck-jsonschema · check-jsonschemaEPSS 0.14%via OSV
CVE-2024-53865High· 8.2
1y ago

Python package "zhmcclient" stores passwords in clear text in its HMC and API logs

Python package "zhmcclient" stores passwords in clear text in its HMC and API logs

▾ Twilightzhmcclient · zhmcclientEPSS 0.14%via OSV
CVE-2024-53861Low· 2.2
1y ago

PyJWT Issuer field partial matches allowed

PyJWT Issuer field partial matches allowed

▾ Sunlitpyjwt · pyjwtEPSS 0.83%via OSV
CVE-2024-53981High· 7.5
1y ago

Denial of service (DoS) via deformation `multipart/form-data` boundary

Denial of service (DoS) via deformation `multipart/form-data` boundary

▾ Twilightpython-multipart · python-multipartEPSS 0.64%via OSV
CVE-2024-39162Medium· 6.1
1y ago

pyspider Cross-site Scripting vulnerability

pyspider Cross-site Scripting vulnerability

▾ Sunlitpyspider · pyspiderEPSS 0.41%via OSV
CVE-2024-52008Medium· 5.7
1y ago

Password Policy Bypass Vulnerability in Fides Webserver User Accept Invite API

Password Policy Bypass Vulnerability in Fides Webserver User Accept Invite API

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.56%via OSV
CVE-2024-53916High· 7.5
1y ago

OpenStack Neutron can use an incorrect ID during policy enforcement

OpenStack Neutron can use an incorrect ID during policy enforcement

▾ Twilightneutron · neutronEPSS 0.71%via OSV
CVE-2024-52787Critical· 9.1
1y ago

libre-chat Path Traversal vulnerability

libre-chat Path Traversal vulnerability

▾ Midnightlibre-chat · libre-chatEPSS 0.77%via OSV
CVE-2024-53899High· 8.4
1y ago

virtualenv allows command injection through activation scripts for a virtual environment

virtualenv allows command injection through activation scripts for a virtual environment

▾ Twilightvirtualenv · virtualenvEPSS 1.6%via OSV
CVE-2024-11393High· 8.80dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 3.1%via OSV
CVE-2024-11392High· 7.50dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 7.3%via OSV
CVE-2024-11394High· 8.80dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 2.6%via OSV
CVE-2024-52804High· 7.5
1y ago

Tornado has an HTTP cookie parsing DoS vulnerability

Tornado has an HTTP cookie parsing DoS vulnerability

▾ Twilighttornado · tornadoEPSS 1.0%via OSV
CVE-2023-40017High· 7.5
1y ago

GeoNode Server Side Request forgery

GeoNode Server Side Request forgery

▾ Twilightgeonode · geonodeEPSS 0.76%via OSV
CVE-2024-52803High· 7.5
1y ago

LLama Factory Remote OS Command Injection Vulnerability

LLama Factory Remote OS Command Injection Vulnerability

▾ Twilightllamafactory · llamafactoryEPSS 2.3%via OSV
CVE-2024-11406Medium· 6.9
1y ago

django CMS Attributes Field Cross-site Scripting

django CMS Attributes Field Cross-site Scripting

▾ Sunlitdjangocms-attributes-field · djangocms-attributes-fieldEPSS 0.47%via OSV
CVE-2024-11404Medium· 5.5
1y ago

Django Filer Unrestricted Upload of File with Dangerous Type

Django Filer Unrestricted Upload of File with Dangerous Type

▾ Sunlitdjango-filer · django-filerEPSS 0.36%via OSV
CVE-2024-52581High· 7.5
1y ago

Litestar allows unbounded resource consumption (DoS vulnerability)

Litestar allows unbounded resource consumption (DoS vulnerability)

▾ Twilightlitestar · litestarEPSS 0.79%via OSV
CVE-2024-52304Medium
1y ago

aiohttp allows request smuggling due to incorrect parsing of chunk extensions

aiohttp allows request smuggling due to incorrect parsing of chunk extensions

▾ Sunlitaiohttp · aiohttpEPSS 0.56%via OSV
CVE-2024-52303High· 7.5
1y ago

aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method

aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method

▾ Twilightaiohttp · aiohttpEPSS 0.59%via OSV
CVEs tagged “pip” — page 102 · VulnSea