Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2023-6110Medium· 5.5OpenStack improperly deletes access rules
OpenStack improperly deletes access rules
CVE-2021-3988Medium· 6.1Cross-site Scripting (XSS) - DOM in janeczku/calibre-web
Cross-site Scripting (XSS) - DOM in janeczku/calibre-web
CVE-2021-3986Medium· 4.3Generation of Error Message Containing Sensitive Information in janeczku/calibre-web
Generation of Error Message Containing Sensitive Information in janeczku/calibre-web
CVE-2021-3987Medium· 5.4Improper Access Control in janeczku/calibre-web
Improper Access Control in janeczku/calibre-web
CVE-2024-45784High· 7.5Apache Airflow: Sensitive configuration values are not masked in the logs by default
Apache Airflow: Sensitive configuration values are not masked in the logs by default
CVE-2024-52524MediumReDoS in giskard's transformation.py (GHSL-2024-324)
ReDoS in giskard's transformation.py (GHSL-2024-324)
CVE-2024-4311Medium· 5.4Missing ratelimit on passwrod resets in zenml
Missing ratelimit on passwrod resets in zenml
CVE-2023-34049Medium· 6.7Salt preflight script could be attacker controlled
Salt preflight script could be attacker controlled
CVE-2024-11079Medium· 5.5A flaw was found in Ansible-Core
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote da…
CVE-2024-50378Medium· 6.5Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
CVE-2024-51998High· 8.6changedetection.io path traversal using file URI scheme without supplying hostname
changedetection.io path traversal using file URI scheme without supplying hostname
CVE-2024-9902Medium· 6.3PoCansible-core Incorrect Authorization vulnerability
ansible-core Incorrect Authorization vulnerability
CVE-2024-48061Critical· 9.8PoCLangflow vulnerable to remote code execution
Langflow vulnerable to remote code execution
CVE-2024-48052Medium· 6.5gradio Server Side Request Forgery vulnerability
gradio Server Side Request Forgery vulnerability
CVE-2024-51734Critical· 9.1Access control vulnerable to user data deletion by anonynmous users
Access control vulnerable to user data deletion by anonynmous users
CVE-2024-51483Medium· 6.5PoCchangedetection.io Path Traversal
changedetection.io Path Traversal
CVE-2024-8309Medium· 4.9PoCLangchain SQL Injection vulnerability
Langchain SQL Injection vulnerability
CVE-2024-49767High· 7.5Werkzeug possible resource exhaustion when parsing file data in forms
Werkzeug possible resource exhaustion when parsing file data in forms
CVE-2024-49766MediumWerkzeug safe_join not safe on Windows
Werkzeug safe_join not safe on Windows
CVE-2024-49750Medium· 5.5The Snowflake Connector for Python stores sensitive data in logs
The Snowflake Connector for Python stores sensitive data in logs
CVE-2024-24826Medium· 5.5Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder
Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder
CVE-2024-25112Medium· 5.5Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder
Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder
CVE-2024-10073Medium· 5.0Flair allows arbitrary code execution
Flair allows arbitrary code execution
CVE-2024-32651Critical· 10.0PoCchangedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
CVE-2024-21272High· 7.5MySQL Connector/Python connector takeover vulnerability
MySQL Connector/Python connector takeover vulnerability
CVE-2024-47874None· 0.0Starlette Denial of service (DoS) via multipart/form-data
Starlette Denial of service (DoS) via multipart/form-data
CVE-2024-6971Low· 3.4Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py
Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py
GHSA-26jh-r8g2-6fprMedium· 5.3Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
CVE-2024-7041Medium· 6.5open-webui Insecure Direct Object Reference (IDOR) vulnerability
open-webui Insecure Direct Object Reference (IDOR) vulnerability
CVE-2024-7038Low· 2.7open-webui allows enumeration of file names and traversal of directories by observing the error messages
open-webui allows enumeration of file names and traversal of directories by observing the error messages