Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2024-6221High· 7.5Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
CVE-2024-42367Medium· 4.8In aiohttp, compressed files as symlinks are not protected from path traversal
In aiohttp, compressed files as symlinks are not protected from path traversal
CVE-2024-41942High· 7.2JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
CVE-2024-6706Medium· 6.1Open WebUI Stored Cross-Site Scripting Vulnerability
Open WebUI Stored Cross-Site Scripting Vulnerability
CVE-2024-7143Medium· 6.7Pulp incorrectly assigns RBAC permissions in tasks that create objects
Pulp incorrectly assigns RBAC permissions in tasks that create objects
CVE-2024-42447Medium· 4.2Apache Airflow Providers FAB Insufficient Session Expiration vulnerability
Apache Airflow Providers FAB Insufficient Session Expiration vulnerability
CVE-2024-7319Medium· 5.0openstack-heat may disclose sensitive information
openstack-heat may disclose sensitive information
CVE-2024-7340High· 8.8PoCWeave server API vulnerable to arbitrary file leak
Weave server API vulnerable to arbitrary file leak
CVE-2024-41950High· 7.5Insecure Jinja2 templates rendered in Haystack Components can lead to RCE
Insecure Jinja2 templates rendered in Haystack Components can lead to RCE
CVE-2024-41955Medium· 5.2PoCMobSF vulnerable to Open Redirect in Login Redirect
MobSF vulnerable to Open Redirect in Login Redirect
CVE-2024-41951Medium· 4.4PheonixAppAPI has visible Encoding Maps
PheonixAppAPI has visible Encoding Maps
CVE-2023-33976High· 7.5TensorFlow has segfault in array_ops.upper_bound
TensorFlow has segfault in array_ops.upper_bound
CVE-2024-6578Medium· 6.1Aim Stored Cross-site Scripting Vulnerability
Aim Stored Cross-site Scripting Vulnerability
CVE-2024-41671High· 8.3twisted.web has disordered HTTP pipeline response
twisted.web has disordered HTTP pipeline response
MAL-2024-12279Critical⚠ ExploitedMalicious code in google-cloud-datacatalog-lineage-producer-client (PyPI)
Malicious code in google-cloud-datacatalog-lineage-producer-client (PyPI)
CVE-2024-40767Medium· 6.5OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
CVE-2024-41656High· 7.1Sentry vulnerable to stored Cross-Site Scripting (XSS)
Sentry vulnerable to stored Cross-Site Scripting (XSS)
CVE-2024-29073Medium· 5.3Anki Latex Incomplete Blocklist Vulnerability
Anki Latex Incomplete Blocklist Vulnerability
CVE-2024-32152Low· 3.1Ankitects Anki LaTeX Blocklist Bypass vulnerability
Ankitects Anki LaTeX Blocklist Bypass vulnerability
CVE-2024-41129Medium· 4.4ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command
ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command
CVE-2024-26020Critical· 9.6Ankitects Anki arbitrary script execution vulnerability
Ankitects Anki arbitrary script execution vulnerability
CVE-2024-6961Medium· 5.9Guardrails AI vulnerable to Improper Restriction of XML External Entity Reference
Guardrails AI vulnerable to Improper Restriction of XML External Entity Reference
CVE-2024-6281High· 7.3LoLLMS vulnerable to Expected Behavior Violation
LoLLMS vulnerable to Expected Behavior Violation
CVE-2024-41124Low· 3.8[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`
[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`
CVE-2024-39123Medium· 5.4PoCCalibre-Web Cross Site Scripting (XSS)
Calibre-Web Cross Site Scripting (XSS)
CVE-2024-35198Critical· 9.8TorchServe vulnerable to bypass of allowed_urls configuration
TorchServe vulnerable to bypass of allowed_urls configuration
CVE-2024-35199High· 8.2TorchServe gRPC Port Exposure
TorchServe gRPC Port Exposure
CVE-2024-40647Low· 2.5Sentry's Python SDK unintentionally exposes environment variables to subprocesses
Sentry's Python SDK unintentionally exposes environment variables to subprocesses
CVE-2024-40637Medium· 4.2dbt has an implicit override for built-in materializations from installed packages
dbt has an implicit override for built-in materializations from installed packages
CVE-2024-39863Medium· 5.4Apache Airflow Potential Cross-site Scripting Vulnerability
Apache Airflow Potential Cross-site Scripting Vulnerability