Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2024-39877High· 8.8Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
CVE-2024-39700Critical· 9.8PoCJupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` opt…
JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension author…
CVE-2024-39887Medium· 4.3PoCApache Superset vulnerable to improper SQL authorization
Apache Superset vulnerable to improper SQL authorization
CVE-2024-6345High· 8.8setuptools vulnerable to Command Injection via package URL
setuptools vulnerable to Command Injection via package URL
CVE-2024-40627Medium· 5.8OpaMiddleware does not filter HTTP OPTIONS requests
OpaMiddleware does not filter HTTP OPTIONS requests
CVE-2024-39903High· 8.6PoCLocal File Inclusion in Solara
Local File Inclusion in Solara
CVE-2024-39905Medium· 5.3Red-DiscordBot vulnerable to Incorrect Authorization in commands API
Red-DiscordBot vulnerable to Incorrect Authorization in commands API
CVE-2024-38875High· 7.5Django vulnerable to Denial of Service
Django vulnerable to Denial of Service
CVE-2024-39614High· 7.5PoCDjango vulnerable to Denial of Service
Django vulnerable to Denial of Service
CVE-2024-39330High· 7.5Django Path Traversal vulnerability
Django Path Traversal vulnerability
CVE-2024-6037Critical· 9.1A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the serv…
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resul…
CVE-2024-5569Medium· 6.2zipp Denial of Service vulnerability
zipp Denial of Service vulnerability
CVE-2024-6227High· 7.5Aim denial of service vulnerability
Aim denial of service vulnerability
CVE-2024-39689LowPoCCertifi removes GLOBALTRUST root certificate
Certifi removes GLOBALTRUST root certificate
CVE-2024-32498Medium· 6.5OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
CVE-2024-5753High· 7.5Vanna vulnerable to SQL Injection
Vanna vulnerable to SQL Injection
CVE-2024-31223Medium· 5.3PoCInformation Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
CVE-2024-38537None· 0.0PoCInclusion of Untrusted polyfill.io Code Vulnerability in fides.js
Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js
CVE-2024-38519High· 7.8yt-dlp File system modification and RCE through improper file-extension sanitization
yt-dlp File system modification and RCE through improper file-extension sanitization
CVE-2024-39303Medium· 4.4Weblate vulnerable to improper sanitization of project backups
Weblate vulnerable to improper sanitization of project backups
CVE-2024-39705High· 7.5ntlk unsafe deserialization vulnerability
ntlk unsafe deserialization vulnerability
CVE-2024-5980Critical· 9.1pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
CVE-2024-6090High· 7.5A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histo…
A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target s…
CVE-2024-6038High· 7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerabilit…
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-p…
CVE-2024-6139High· 7.3lollms vulnerable to dot-dot-slash path traversal in XTTS server
lollms vulnerable to dot-dot-slash path traversal in XTTS server
CVE-2024-5710Medium· 5.3litellm vulnerable to improper access control in team management
litellm vulnerable to improper access control in team management
CVE-2024-22231Medium· 5.0Directory creation by malicious user in saltstack
Directory creation by malicious user in saltstack
CVE-2024-5824High· 7.4lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE
lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE
CVE-2024-6085High· 8.6lollms vulnerable to path traversal due to unauthenticated root folder settings change
lollms vulnerable to path traversal due to unauthenticated root folder settings change
CVE-2024-5979High· 7.5h2o vulnerable to unexpected POST request shutting down server
h2o vulnerable to unexpected POST request shutting down server