VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2024-45498High· 8.8
2y ago

Apache Airflow vulnerable to Improper Encoding or Escaping of Output

Apache Airflow vulnerable to Improper Encoding or Escaping of Output

▾ Twilightapache-airflow · apache-airflowEPSS 1.2%via OSV
CVE-2024-45034High· 8.8
2y ago

Apache Airflow vulnerable to Execution with Unnecessary Privileges

Apache Airflow vulnerable to Execution with Unnecessary Privileges

▾ Twilightapache-airflow · apache-airflowEPSS 1.7%via OSV
CVE-2024-45314Low· 3.6
2y ago

Flask-AppBuilder's login form allows browser to cache sensitive fields

Flask-AppBuilder's login form allows browser to cache sensitive fields

▾ Sunlitflask-appbuilder · flask-appbuilderEPSS 0.27%via OSV
CVE-2024-45053Critical· 9.1
2y ago

Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine

Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine

▾ Midnightethyca-fides · ethyca-fidesEPSS 1.3%via OSV
CVE-2024-45052Low
2y ago

Timing-Based Username Enumeration Vulnerability in Fides Webserver Authentication

Timing-Based Username Enumeration Vulnerability in Fides Webserver Authentication

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.56%via OSV
GHSA-h4gh-qq45-vh27Medium
2y ago

pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels

pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels

▾ Sunlitcryptography · cryptographyvia OSV
GHSA-w2pj-9cgh-mq2cHigh· 8.8
2y ago

opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

▾ Twilightopencv-contrib-python-headless · opencv-contrib-python-headlessvia OSV
GHSA-qr4w-53vh-m672High· 8.8
2y ago

opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

▾ Twilightopencv-python · opencv-pythonvia OSV
CVE-2023-26043Medium· 6.5
2y ago

GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection

GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection

▾ Sunlitgeonode · geonodeEPSS 0.84%via OSV
GHSA-jh2j-j4j9-crg3High· 8.8
2y ago

opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

▾ Twilightopencv-python-headless · opencv-python-headlessvia OSV
GHSA-cxjf-x6jp-p7mcHigh· 8.8
2y ago

opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

▾ Twilightopencv-contrib-python · opencv-contrib-pythonvia OSV
CVE-2023-23611Low· 3.7
2y ago

LTI 1.3 Grade Pass Back Implementation has Missing Authorization Vulnerability

LTI 1.3 Grade Pass Back Implementation has Missing Authorization Vulnerability

▾ Sunlitlti-consumer-xblock · lti-consumer-xblockEPSS 0.38%via OSV
CVE-2020-11093High· 7.5
2y ago

Hyperledger Indy's update process of a DID does not check who signs the request

Hyperledger Indy's update process of a DID does not check who signs the request

▾ Twilightindy-node · indy-nodeEPSS 1.2%via OSV
CVE-2020-15100Low· 2.8
2y ago

freewvs vulnerable to denial of service through large files

freewvs vulnerable to denial of service through large files

▾ Sunlitfreewvs · freewvsEPSS 0.34%via OSV
CVE-2020-15101Low· 2.8
2y ago

freewvs's nested directory structure can interrupt scan

freewvs's nested directory structure can interrupt scan

▾ Sunlitfreewvs · freewvsEPSS 0.69%via OSV
CVE-2021-21401High· 7.1PoC
2y ago

nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC

nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC

▾ Midnightnanopb · nanopbEPSS 1.8%via OSV
CVE-2024-43805High· 7.6
2y ago

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

▾ Twilightjupyterlab · jupyterlabEPSS 0.40%via OSV
CVE-2024-42818Medium· 6.1
2y ago

FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function

FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function

▾ Sunlitfastapi-admin · fastapi-adminEPSS 0.29%via OSV
CVE-2024-42816Medium· 6.1
2y ago

FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function

FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function

▾ Sunlitfastapi-admin · fastapi-adminEPSS 0.29%via OSV
CVE-2024-45188Medium· 6.5
2y ago

Mage AI Path Traversal vulnerability

Mage AI Path Traversal vulnerability

▾ Sunlitmage-ai · mage-aiEPSS 0.88%via OSV
CVE-2024-45187High· 7.1
2y ago

Mage AI incorrectly gives privileges to users with deleted accounts

Mage AI incorrectly gives privileges to users with deleted accounts

▾ Twilightmage-ai · mage-aiEPSS 0.50%via OSV
CVE-2024-45189Medium· 6.5
2y ago

Mage AI Path Traversal vulnerability

Mage AI Path Traversal vulnerability

▾ Sunlitmage-ai · mage-aiEPSS 0.88%via OSV
CVE-2024-45190Medium· 6.5
2y ago

Mage AI Path Traversal vulnerability

Mage AI Path Traversal vulnerability

▾ Sunlitmage-ai · mage-aiEPSS 0.86%via OSV
CVE-2024-8072Medium· 5.3
2y ago

Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users

Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users

▾ Sunlitmage-ai · mage-aiEPSS 0.60%via OSV
CVE-2024-41937Medium· 6.1
2y ago

Apache Airflow Cross-site Scripting Vulnerability

Apache Airflow Cross-site Scripting Vulnerability

▾ Sunlitapache-airflow · apache-airflowEPSS 1.7%via OSV
CVE-2024-41675Medium· 6.8
2y ago

CKAN has Cross-site Scripting vector in the Datatables view plugin

CKAN has Cross-site Scripting vector in the Datatables view plugin

▾ Sunlitckan · ckanEPSS 0.40%via OSV
CVE-2024-43371Medium· 4.5
2y ago

Potential access to sensitive URLs via CKAN extensions (SSRF)

Potential access to sensitive URLs via CKAN extensions (SSRF)

▾ Sunlitckan · ckanEPSS 0.37%via OSV
CVE-2024-41674Medium· 5.3
2y ago

CKAN may leak Solr credentials via error message in package_search action

CKAN may leak Solr credentials via error message in package_search action

▾ Sunlitckan · ckanEPSS 0.38%via OSV
CVE-2024-43396Medium· 5.4
2y ago

Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)

Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)

▾ Sunlitkhoj · khojEPSS 0.55%via OSV
CVE-2024-43399High· 8.0
2y ago

Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files

Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files

▾ Twilightmobsf · mobsfEPSS 0.96%via OSV
CVEs tagged “pip” — page 105 · VulnSea