VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2024-6221High· 7.5
2y ago

Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default

Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default

▾ Twilightflask-cors · flask-corsEPSS 0.72%via OSV
CVE-2024-42367Medium· 4.8
2y ago

In aiohttp, compressed files as symlinks are not protected from path traversal

In aiohttp, compressed files as symlinks are not protected from path traversal

▾ Sunlitaiohttp · aiohttpEPSS 0.65%via OSV
CVE-2024-41942High· 7.2
2y ago

JupyterHub has a privilege escalation vulnerability with the `admin:users` scope

JupyterHub has a privilege escalation vulnerability with the `admin:users` scope

▾ Twilightjupyterhub · jupyterhubEPSS 0.59%via OSV
CVE-2024-6706Medium· 6.1
2y ago

Open WebUI Stored Cross-Site Scripting Vulnerability

Open WebUI Stored Cross-Site Scripting Vulnerability

▾ Sunlitopen-webui · open-webuiEPSS 0.66%via OSV
CVE-2024-7143Medium· 6.7
2y ago

Pulp incorrectly assigns RBAC permissions in tasks that create objects

Pulp incorrectly assigns RBAC permissions in tasks that create objects

▾ Sunlitpulpcore · pulpcoreEPSS 0.61%via OSV
CVE-2024-42447Medium· 4.2
2y ago

Apache Airflow Providers FAB Insufficient Session Expiration vulnerability

Apache Airflow Providers FAB Insufficient Session Expiration vulnerability

▾ Sunlitapache-airflow-providers-fab · apache-airflow-providers-fabEPSS 0.93%via OSV
CVE-2024-7319Medium· 5.0
2y ago

openstack-heat may disclose sensitive information

openstack-heat may disclose sensitive information

▾ Sunlitopenstack-heat · openstack-heatEPSS 0.39%via OSV
CVE-2024-7340High· 8.8PoC
2y ago

Weave server API vulnerable to arbitrary file leak

Weave server API vulnerable to arbitrary file leak

▾ Midnightweave · weaveEPSS 5.0%via OSV
CVE-2024-41950High· 7.5
2y ago

Insecure Jinja2 templates rendered in Haystack Components can lead to RCE

Insecure Jinja2 templates rendered in Haystack Components can lead to RCE

▾ Twilighthaystack-ai · haystack-aiEPSS 1.2%via OSV
CVE-2024-41955Medium· 5.2PoC
2y ago

MobSF vulnerable to Open Redirect in Login Redirect

MobSF vulnerable to Open Redirect in Login Redirect

▾ Twilightmobsf · mobsfEPSS 1.0%via OSV
CVE-2024-41951Medium· 4.4
2y ago

PheonixAppAPI has visible Encoding Maps

PheonixAppAPI has visible Encoding Maps

▾ Sunlitpheonixappapi · pheonixappapiEPSS 0.17%via OSV
CVE-2023-33976High· 7.5
2y ago

TensorFlow has segfault in array_ops.upper_bound

TensorFlow has segfault in array_ops.upper_bound

▾ Twilighttensorflow · tensorflowEPSS 0.43%via OSV
CVE-2024-6578Medium· 6.1
2y ago

Aim Stored Cross-site Scripting Vulnerability

Aim Stored Cross-site Scripting Vulnerability

▾ Sunlitaim · aimEPSS 0.29%via OSV
CVE-2024-41671High· 8.3
2y ago

twisted.web has disordered HTTP pipeline response

twisted.web has disordered HTTP pipeline response

▾ Twilighttwisted · twistedEPSS 0.86%via OSV
MAL-2024-12279Critical⚠ Exploited
2y ago

Malicious code in google-cloud-datacatalog-lineage-producer-client (PyPI)

Malicious code in google-cloud-datacatalog-lineage-producer-client (PyPI)

▾ Abyssalgoogle-cloud-datacatalog-lineage-producer-client · google-cloud-datacatalog-lineage-producer-clientvia OSV
CVE-2024-40767Medium· 6.5
2y ago

OpenStack Nova vulnerable to unauthorized access to potentially sensitive data

OpenStack Nova vulnerable to unauthorized access to potentially sensitive data

▾ Sunlitnova · novaEPSS 0.94%via OSV
CVE-2024-41656High· 7.1
2y ago

Sentry vulnerable to stored Cross-Site Scripting (XSS)

Sentry vulnerable to stored Cross-Site Scripting (XSS)

▾ Twilightsentry · sentryEPSS 0.47%via OSV
CVE-2024-29073Medium· 5.3
2y ago

Anki Latex Incomplete Blocklist Vulnerability

Anki Latex Incomplete Blocklist Vulnerability

▾ Sunlitanki · ankiEPSS 12%via OSV
CVE-2024-32152Low· 3.1
2y ago

Ankitects Anki LaTeX Blocklist Bypass vulnerability

Ankitects Anki LaTeX Blocklist Bypass vulnerability

▾ Sunlitanki · ankiEPSS 13%via OSV
CVE-2024-41129Medium· 4.4
2y ago

ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command

ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command

▾ Sunlitops · opsEPSS 0.20%via OSV
CVE-2024-26020Critical· 9.6
2y ago

Ankitects Anki arbitrary script execution vulnerability

Ankitects Anki arbitrary script execution vulnerability

▾ Midnightanki · ankiEPSS 15%via OSV
CVE-2024-6961Medium· 5.9
2y ago

Guardrails AI vulnerable to Improper Restriction of XML External Entity Reference

Guardrails AI vulnerable to Improper Restriction of XML External Entity Reference

▾ Sunlitguardrails-ai · guardrails-aiEPSS 0.41%via OSV
CVE-2024-6281High· 7.3
2y ago

LoLLMS vulnerable to Expected Behavior Violation

LoLLMS vulnerable to Expected Behavior Violation

▾ Twilightlollms · lollmsEPSS 0.27%via OSV
CVE-2024-41124Low· 3.8
2y ago

[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`

[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`

▾ Sunlitpuncia · punciaEPSS 0.27%via OSV
CVE-2024-39123Medium· 5.4PoC
2y ago

Calibre-Web Cross Site Scripting (XSS)

Calibre-Web Cross Site Scripting (XSS)

▾ Twilightcalibreweb · calibrewebEPSS 23%via OSV
CVE-2024-35198Critical· 9.8
2y ago

TorchServe vulnerable to bypass of allowed_urls configuration

TorchServe vulnerable to bypass of allowed_urls configuration

▾ Midnighttorchserve · torchserveEPSS 0.80%via OSV
CVE-2024-35199High· 8.2
2y ago

TorchServe gRPC Port Exposure

TorchServe gRPC Port Exposure

▾ Twilighttorchserve · torchserveEPSS 0.64%via OSV
CVE-2024-40647Low· 2.5
2y ago

Sentry's Python SDK unintentionally exposes environment variables to subprocesses

Sentry's Python SDK unintentionally exposes environment variables to subprocesses

▾ Sunlitsentry-sdk · sentry-sdkEPSS 0.20%via OSV
CVE-2024-40637Medium· 4.2
2y ago

dbt has an implicit override for built-in materializations from installed packages

dbt has an implicit override for built-in materializations from installed packages

▾ Sunlitdbt-core · dbt-coreEPSS 0.37%via OSV
CVE-2024-39863Medium· 5.4
2y ago

Apache Airflow Potential Cross-site Scripting Vulnerability

Apache Airflow Potential Cross-site Scripting Vulnerability

▾ Sunlitapache-airflow · apache-airflowEPSS 1.00%via OSV
CVEs tagged “pip” — page 106 · VulnSea