Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2024-45498High· 8.8Apache Airflow vulnerable to Improper Encoding or Escaping of Output
Apache Airflow vulnerable to Improper Encoding or Escaping of Output
CVE-2024-45034High· 8.8Apache Airflow vulnerable to Execution with Unnecessary Privileges
Apache Airflow vulnerable to Execution with Unnecessary Privileges
CVE-2024-45314Low· 3.6Flask-AppBuilder's login form allows browser to cache sensitive fields
Flask-AppBuilder's login form allows browser to cache sensitive fields
CVE-2024-45053Critical· 9.1Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine
Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine
CVE-2024-45052LowTiming-Based Username Enumeration Vulnerability in Fides Webserver Authentication
Timing-Based Username Enumeration Vulnerability in Fides Webserver Authentication
GHSA-h4gh-qq45-vh27Mediumpyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
GHSA-w2pj-9cgh-mq2cHigh· 8.8opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
GHSA-qr4w-53vh-m672High· 8.8opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
CVE-2023-26043Medium· 6.5GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection
GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection
GHSA-jh2j-j4j9-crg3High· 8.8opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
GHSA-cxjf-x6jp-p7mcHigh· 8.8opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
CVE-2023-23611Low· 3.7LTI 1.3 Grade Pass Back Implementation has Missing Authorization Vulnerability
LTI 1.3 Grade Pass Back Implementation has Missing Authorization Vulnerability
CVE-2020-11093High· 7.5Hyperledger Indy's update process of a DID does not check who signs the request
Hyperledger Indy's update process of a DID does not check who signs the request
CVE-2020-15100Low· 2.8freewvs vulnerable to denial of service through large files
freewvs vulnerable to denial of service through large files
CVE-2020-15101Low· 2.8freewvs's nested directory structure can interrupt scan
freewvs's nested directory structure can interrupt scan
CVE-2021-21401High· 7.1PoCnanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC
nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC
CVE-2024-43805High· 7.6HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
CVE-2024-42818Medium· 6.1FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function
FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function
CVE-2024-42816Medium· 6.1FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function
FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function
CVE-2024-45188Medium· 6.5Mage AI Path Traversal vulnerability
Mage AI Path Traversal vulnerability
CVE-2024-45187High· 7.1Mage AI incorrectly gives privileges to users with deleted accounts
Mage AI incorrectly gives privileges to users with deleted accounts
CVE-2024-45189Medium· 6.5Mage AI Path Traversal vulnerability
Mage AI Path Traversal vulnerability
CVE-2024-45190Medium· 6.5Mage AI Path Traversal vulnerability
Mage AI Path Traversal vulnerability
CVE-2024-8072Medium· 5.3Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
CVE-2024-41937Medium· 6.1Apache Airflow Cross-site Scripting Vulnerability
Apache Airflow Cross-site Scripting Vulnerability
CVE-2024-41675Medium· 6.8CKAN has Cross-site Scripting vector in the Datatables view plugin
CKAN has Cross-site Scripting vector in the Datatables view plugin
CVE-2024-43371Medium· 4.5Potential access to sensitive URLs via CKAN extensions (SSRF)
Potential access to sensitive URLs via CKAN extensions (SSRF)
CVE-2024-41674Medium· 5.3CKAN may leak Solr credentials via error message in package_search action
CKAN may leak Solr credentials via error message in package_search action
CVE-2024-43396Medium· 5.4Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)
Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)
CVE-2024-43399High· 8.0Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files