Tagged “pip”
CVEs tagged pip, newest first.
4642 CVEsRSS
CVE-2024-45231Low· 3.7Django allows enumeration of user e-mail addresses
Django allows enumeration of user e-mail addresses
CVE-2024-25885Medium· 5.3xhtml2pdf Denial of Service via crafted string
xhtml2pdf Denial of Service via crafted string
CVE-2024-47211Medium· 5.3OpenStack Ironic fails to verify checksums of supplied image_source URLs
OpenStack Ironic fails to verify checksums of supplied image_source URLs
CVE-2024-9277Low· 3.5Inefficient Regular Expression Complexity in langflow
Inefficient Regular Expression Complexity in langflow
CVE-2024-46488Critical· 9.1Heap-based Buffer Overflow in sqlite-vec
Heap-based Buffer Overflow in sqlite-vec
CVE-2024-9014High· 8.6PoCOAuth2 client ID and secret exposed through the web browser
OAuth2 client ID and secret exposed through the web browser
CVE-2024-47226Medium· 5.4A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel …
A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or H…
CVE-2024-45793Medium· 4.8Prevent XSS from Confidant API call
Prevent XSS from Confidant API call
CVE-2024-8375Medium· 6.1Reverb use after free vulnerability
Reverb use after free vulnerability
CVE-2024-45858High· 8.8Guardrails has an arbitrary code execution vulnerability
Guardrails has an arbitrary code execution vulnerability
CVE-2024-45601High· 7.5Mesop has a local file Inclusion via static file serving functionality
Mesop has a local file Inclusion via static file serving functionality
CVE-2024-35515High· 8.8sqlitedict insecure deserialization vulnerability
sqlitedict insecure deserialization vulnerability
CVE-2024-8939Medium· 6.2vLLM Denial of Service via the best_of parameter
vLLM Denial of Service via the best_of parameter
CVE-2024-8768High· 7.5vLLM denial of service vulnerability
vLLM denial of service vulnerability
CVE-2024-45606High· 7.1Sentry improperly authorizes muting of alert rules
Sentry improperly authorizes muting of alert rules
CVE-2024-5998Medium· 5.2LangChain pickle deserialization of untrusted data
LangChain pickle deserialization of untrusted data
CVE-2024-45605Medium· 6.5Sentry improperly authorizes deletion of user issue alert notifications
Sentry improperly authorizes deletion of user issue alert notifications
CVE-2024-8863Low· 3.5Aim Stored XSS through TEXT EXPLORER
Aim Stored XSS through TEXT EXPLORER
CVE-2024-8864Medium· 5.5Composio Code Injection Vulnerability
Composio Code Injection Vulnerability
CVE-2024-8862High· 7.3D-Tale Command Execution Vulnerability
D-Tale Command Execution Vulnerability
CVE-2024-8865Low· 3.5Composio Path Traversal vulnerability
Composio Path Traversal vulnerability
CVE-2024-8775Medium· 5.5A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook
A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without se…
CVE-2024-6587High· 7.5PoCLiteLLM Server-Side Request Forgery (SSRF) vulnerability
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
CVE-2024-27320High· 7.8Refuel Autolab Eval Injection vulnerability
Refuel Autolab Eval Injection vulnerability
CVE-2024-45847High· 8.8MindsDB Eval Injection vulnerability
MindsDB Eval Injection vulnerability
CVE-2024-45857High· 7.8Cleanlab Deserialization of Untrusted Data vulnerability
Cleanlab Deserialization of Untrusted Data vulnerability
CVE-2024-27321High· 7.8Refuel Autolab Eval Injection vulnerability
Refuel Autolab Eval Injection vulnerability
CVE-2024-45856Critical· 9.0MindsDB Cross-site Scripting vulnerability
MindsDB Cross-site Scripting vulnerability
CVE-2024-45595Medium· 6.1D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
CVE-2024-45498High· 8.8Apache Airflow vulnerable to Improper Encoding or Escaping of Output
Apache Airflow vulnerable to Improper Encoding or Escaping of Output