VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2023-6110Medium· 5.5
1y ago

OpenStack improperly deletes access rules

OpenStack improperly deletes access rules

▾ Sunlitpython-openstackclient · python-openstackclientEPSS 0.49%via OSV
CVE-2021-3988Medium· 6.1
1y ago

Cross-site Scripting (XSS) - DOM in janeczku/calibre-web

Cross-site Scripting (XSS) - DOM in janeczku/calibre-web

▾ Sunlitcalibreweb · calibrewebEPSS 0.36%via OSV
CVE-2021-3986Medium· 4.3
1y ago

Generation of Error Message Containing Sensitive Information in janeczku/calibre-web

Generation of Error Message Containing Sensitive Information in janeczku/calibre-web

▾ Sunlitcalibreweb · calibrewebEPSS 0.37%via OSV
CVE-2021-3987Medium· 5.4
1y ago

Improper Access Control in janeczku/calibre-web

Improper Access Control in janeczku/calibre-web

▾ Sunlitcalibreweb · calibrewebEPSS 0.35%via OSV
CVE-2024-45784High· 7.5
1y ago

Apache Airflow: Sensitive configuration values are not masked in the logs by default

Apache Airflow: Sensitive configuration values are not masked in the logs by default

▾ Twilightairflow · airflowEPSS 1.3%via OSV
CVE-2024-52524Medium
1y ago

ReDoS in giskard's transformation.py (GHSL-2024-324)

ReDoS in giskard's transformation.py (GHSL-2024-324)

▾ Sunlitgiskard · giskardEPSS 0.82%via OSV
CVE-2024-4311Medium· 5.4
1y ago

Missing ratelimit on passwrod resets in zenml

Missing ratelimit on passwrod resets in zenml

▾ Sunlitzenml · zenmlEPSS 0.48%via OSV
CVE-2023-34049Medium· 6.7
1y ago

Salt preflight script could be attacker controlled

Salt preflight script could be attacker controlled

▾ Sunlitsalt · saltEPSS 0.19%via OSV
CVE-2024-11079Medium· 5.5
1y ago

A flaw was found in Ansible-Core

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote da…

▾ Sunlitansible-core · ansible-coreEPSS 0.50%via NVD
CVE-2024-50378Medium· 6.5
1y ago

Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data

Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data

▾ Sunlitapache-airflow · apache-airflowEPSS 1.2%via OSV
CVE-2024-51998High· 8.6
1y ago

changedetection.io path traversal using file URI scheme without supplying hostname

changedetection.io path traversal using file URI scheme without supplying hostname

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.69%via OSV
CVE-2024-9902Medium· 6.3PoC
1y ago

ansible-core Incorrect Authorization vulnerability

ansible-core Incorrect Authorization vulnerability

▾ Twilightansible-core · ansible-coreEPSS 0.26%via OSV
CVE-2024-48061Critical· 9.8PoC
1y ago

Langflow vulnerable to remote code execution

Langflow vulnerable to remote code execution

▾ Abyssallangflow · langflowEPSS 1.5%via OSV
CVE-2024-48052Medium· 6.5
1y ago

gradio Server Side Request Forgery vulnerability

gradio Server Side Request Forgery vulnerability

▾ Sunlitgradio · gradioEPSS 0.47%via OSV
CVE-2024-51734Critical· 9.1
1y ago

Access control vulnerable to user data deletion by anonynmous users

Access control vulnerable to user data deletion by anonynmous users

▾ Midnightaccesscontrol · accesscontrolEPSS 0.43%via OSV
CVE-2024-51483Medium· 6.5PoC
1y ago

changedetection.io Path Traversal

changedetection.io Path Traversal

▾ Twilightchangedetection-io · changedetection-ioEPSS 2.3%via OSV
CVE-2024-8309Medium· 4.9PoC
1y ago

Langchain SQL Injection vulnerability

Langchain SQL Injection vulnerability

▾ Twilightlangchain-community · langchain-communityEPSS 14%via OSV
CVE-2024-49767High· 7.5
1y ago

Werkzeug possible resource exhaustion when parsing file data in forms

Werkzeug possible resource exhaustion when parsing file data in forms

▾ Twilightwerkzeug · werkzeugEPSS 1.1%via OSV
CVE-2024-49766Medium
1y ago

Werkzeug safe_join not safe on Windows

Werkzeug safe_join not safe on Windows

▾ Sunlitwerkzeug · werkzeugEPSS 0.78%via OSV
CVE-2024-49750Medium· 5.5
1y ago

The Snowflake Connector for Python stores sensitive data in logs

The Snowflake Connector for Python stores sensitive data in logs

▾ Sunlitsnowflake-connector-python · snowflake-connector-pythonEPSS 0.20%via OSV
CVE-2024-24826Medium· 5.5
1y ago

Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder

Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder

▾ Sunlitexiv2 · exiv2EPSS 0.24%via OSV
CVE-2024-25112Medium· 5.5
1y ago

Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder

Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder

▾ Sunlitexiv2 · exiv2EPSS 0.22%via OSV
CVE-2024-10073Medium· 5.0
1y ago

Flair allows arbitrary code execution

Flair allows arbitrary code execution

▾ Sunlitflair · flairEPSS 0.61%via OSV
CVE-2024-32651Critical· 10.0PoC
1y ago

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

▾ Abyssalchangedetection-io · changedetection-ioEPSS 84%via OSV
CVE-2024-21272High· 7.5
1y ago

MySQL Connector/Python connector takeover vulnerability

MySQL Connector/Python connector takeover vulnerability

▾ Twilightmysql-connector-python · mysql-connector-pythonEPSS 0.51%via OSV
CVE-2024-47874None· 0.0
1y ago

Starlette Denial of service (DoS) via multipart/form-data

Starlette Denial of service (DoS) via multipart/form-data

▾ Sunlitstarlette · starletteEPSS 0.65%via OSV
CVE-2024-6971Low· 3.4
1y ago

Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py

Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py

▾ Sunlitlollms · lollmsEPSS 0.32%via OSV
GHSA-26jh-r8g2-6fprMedium· 5.3
1y ago

Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list

Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list

▾ Sunlitgradio · gradiovia OSV
CVE-2024-7041Medium· 6.5
1y ago

open-webui Insecure Direct Object Reference (IDOR) vulnerability

open-webui Insecure Direct Object Reference (IDOR) vulnerability

▾ Sunlitopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2024-7038Low· 2.7
1y ago

open-webui allows enumeration of file names and traversal of directories by observing the error messages

open-webui allows enumeration of file names and traversal of directories by observing the error messages

▾ Sunlitopen-webui · open-webuiEPSS 0.34%via OSV
CVEs tagged “pip” — page 103 · VulnSea