VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4642 CVEsRSS

CVE-2024-45231Low· 3.7
1y ago

Django allows enumeration of user e-mail addresses

Django allows enumeration of user e-mail addresses

▾ Sunlitdjango · djangoEPSS 0.79%via OSV
CVE-2024-25885Medium· 5.3
1y ago

xhtml2pdf Denial of Service via crafted string

xhtml2pdf Denial of Service via crafted string

▾ Sunlitxhtml2pdf · xhtml2pdfEPSS 0.64%via OSV
CVE-2024-47211Medium· 5.3
1y ago

OpenStack Ironic fails to verify checksums of supplied image_source URLs

OpenStack Ironic fails to verify checksums of supplied image_source URLs

▾ Sunlitironic · ironicEPSS 0.66%via OSV
CVE-2024-9277Low· 3.5
2y ago

Inefficient Regular Expression Complexity in langflow

Inefficient Regular Expression Complexity in langflow

▾ Sunlitlangflow · langflowEPSS 0.96%via OSV
CVE-2024-46488Critical· 9.1
2y ago

Heap-based Buffer Overflow in sqlite-vec

Heap-based Buffer Overflow in sqlite-vec

▾ Midnightsqlite-vec · sqlite-vecEPSS 0.44%via OSV
CVE-2024-9014High· 8.6PoC
2y ago

OAuth2 client ID and secret exposed through the web browser

OAuth2 client ID and secret exposed through the web browser

▾ Midnightpgadmin4 · pgadmin4EPSS 9.7%via OSV
CVE-2024-47226Medium· 5.4
2y ago

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel …

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or H…

▾ Sunlitpynetbox · pynetboxEPSS 0.31%via OSV
CVE-2024-45793Medium· 4.8
2y ago

Prevent XSS from Confidant API call

Prevent XSS from Confidant API call

▾ Sunlitconfidant · confidantEPSS 0.36%via OSV
CVE-2024-8375Medium· 6.1
2y ago

Reverb use after free vulnerability

Reverb use after free vulnerability

▾ Sunlitdm-reverb · dm-reverbEPSS 0.12%via OSV
CVE-2024-45858High· 8.8
2y ago

Guardrails has an arbitrary code execution vulnerability

Guardrails has an arbitrary code execution vulnerability

▾ Twilightguardrails-ai · guardrails-aiEPSS 0.38%via OSV
CVE-2024-45601High· 7.5
2y ago

Mesop has a local file Inclusion via static file serving functionality

Mesop has a local file Inclusion via static file serving functionality

▾ Twilightmesop · mesopEPSS 0.28%via OSV
CVE-2024-35515High· 8.8
2y ago

sqlitedict insecure deserialization vulnerability

sqlitedict insecure deserialization vulnerability

▾ Twilightsqlitedict · sqlitedictEPSS 0.89%via OSV
CVE-2024-8939Medium· 6.2
2y ago

vLLM Denial of Service via the best_of parameter

vLLM Denial of Service via the best_of parameter

▾ Sunlitvllm · vllmEPSS 0.23%via OSV
CVE-2024-8768High· 7.5
2y ago

vLLM denial of service vulnerability

vLLM denial of service vulnerability

▾ Twilightvllm · vllmEPSS 0.68%via OSV
CVE-2024-45606High· 7.1
2y ago

Sentry improperly authorizes muting of alert rules

Sentry improperly authorizes muting of alert rules

▾ Twilightsentry · sentryEPSS 0.36%via OSV
CVE-2024-5998Medium· 5.2
2y ago

LangChain pickle deserialization of untrusted data

LangChain pickle deserialization of untrusted data

▾ Sunlitlangchain-community · langchain-communityEPSS 0.36%via OSV
CVE-2024-45605Medium· 6.5
2y ago

Sentry improperly authorizes deletion of user issue alert notifications

Sentry improperly authorizes deletion of user issue alert notifications

▾ Sunlitsentry · sentryEPSS 0.39%via OSV
CVE-2024-8863Low· 3.5
2y ago

Aim Stored XSS through TEXT EXPLORER

Aim Stored XSS through TEXT EXPLORER

▾ Sunlitaim · aimEPSS 0.50%via OSV
CVE-2024-8864Medium· 5.5
2y ago

Composio Code Injection Vulnerability

Composio Code Injection Vulnerability

▾ Sunlitcomposio-core · composio-coreEPSS 0.83%via OSV
CVE-2024-8862High· 7.3
2y ago

D-Tale Command Execution Vulnerability

D-Tale Command Execution Vulnerability

▾ Twilightdtale · dtaleEPSS 1.3%via OSV
CVE-2024-8865Low· 3.5
2y ago

Composio Path Traversal vulnerability

Composio Path Traversal vulnerability

▾ Sunlitcomposio-core · composio-coreEPSS 0.87%via OSV
CVE-2024-8775Medium· 5.5
2y ago

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without se…

▾ SunlitRed Hat · ansible-coreEPSS 0.27%via NVD
CVE-2024-6587High· 7.5PoC
2y ago

LiteLLM Server-Side Request Forgery (SSRF) vulnerability

LiteLLM Server-Side Request Forgery (SSRF) vulnerability

▾ Midnightlitellm · litellmEPSS 35%via OSV
CVE-2024-27320High· 7.8
2y ago

Refuel Autolab Eval Injection vulnerability

Refuel Autolab Eval Injection vulnerability

▾ Twilightrefuel-autolabel · refuel-autolabelEPSS 0.35%via OSV
CVE-2024-45847High· 8.8
2y ago

MindsDB Eval Injection vulnerability

MindsDB Eval Injection vulnerability

▾ Twilightmindsdb · mindsdbEPSS 0.85%via OSV
CVE-2024-45857High· 7.8
2y ago

Cleanlab Deserialization of Untrusted Data vulnerability

Cleanlab Deserialization of Untrusted Data vulnerability

▾ Twilightcleanlab · cleanlabEPSS 0.24%via OSV
CVE-2024-27321High· 7.8
2y ago

Refuel Autolab Eval Injection vulnerability

Refuel Autolab Eval Injection vulnerability

▾ Twilightrefuel-autolabel · refuel-autolabelEPSS 0.35%via OSV
CVE-2024-45856Critical· 9.0
2y ago

MindsDB Cross-site Scripting vulnerability

MindsDB Cross-site Scripting vulnerability

▾ Midnightmindsdb · mindsdbEPSS 0.51%via OSV
CVE-2024-45595Medium· 6.1
2y ago

D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder

D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder

▾ Sunlitdtale · dtaleEPSS 0.78%via OSV
CVE-2024-45498High· 8.8
2y ago

Apache Airflow vulnerable to Improper Encoding or Escaping of Output

Apache Airflow vulnerable to Improper Encoding or Escaping of Output

▾ Twilightapache-airflow · apache-airflowEPSS 1.2%via OSV
CVEs tagged “pip” — page 104 · VulnSea