VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2024-39877High· 8.8
2y ago

Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler

Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler

▾ Twilightapache-airflow · apache-airflowEPSS 1.7%via OSV
CVE-2024-39700Critical· 9.8PoC
2y ago

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` opt…

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension author…

▾ Abyssaljupyterlab · jupyterlabEPSS 1.1%via OSV
CVE-2024-39887Medium· 4.3PoC
2y ago

Apache Superset vulnerable to improper SQL authorization

Apache Superset vulnerable to improper SQL authorization

▾ Twilightapache-superset · apache-supersetEPSS 4.4%via OSV
CVE-2024-6345High· 8.8
2y ago

setuptools vulnerable to Command Injection via package URL

setuptools vulnerable to Command Injection via package URL

▾ Twilightsetuptools · setuptoolsEPSS 1.9%via OSV
CVE-2024-40627Medium· 5.8
2y ago

OpaMiddleware does not filter HTTP OPTIONS requests

OpaMiddleware does not filter HTTP OPTIONS requests

▾ Sunlitfastapi-opa · fastapi-opaEPSS 0.56%via OSV
CVE-2024-39903High· 8.6PoC
2y ago

Local File Inclusion in Solara

Local File Inclusion in Solara

▾ Midnightsolara · solaraEPSS 2.9%via OSV
CVE-2024-39905Medium· 5.3
2y ago

Red-DiscordBot vulnerable to Incorrect Authorization in commands API

Red-DiscordBot vulnerable to Incorrect Authorization in commands API

▾ Sunlitred-discordbot · red-discordbotEPSS 0.41%via OSV
CVE-2024-38875High· 7.5
2y ago

Django vulnerable to Denial of Service

Django vulnerable to Denial of Service

▾ Twilightdjango · djangoEPSS 1.2%via OSV
CVE-2024-39614High· 7.5PoC
2y ago

Django vulnerable to Denial of Service

Django vulnerable to Denial of Service

▾ Midnightdjango · djangoEPSS 29%via OSV
CVE-2024-39330High· 7.5
2y ago

Django Path Traversal vulnerability

Django Path Traversal vulnerability

▾ Twilightdjango · djangoEPSS 1.0%via OSV
CVE-2024-6037Critical· 9.1
2y ago

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the serv…

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resul…

▾ Midnightchuanhuchatgpt · chuanhuchatgptEPSS 11%via OSV
CVE-2024-5569Medium· 6.2
2y ago

zipp Denial of Service vulnerability

zipp Denial of Service vulnerability

▾ Sunlitzipp · zippEPSS 0.24%via OSV
CVE-2024-6227High· 7.5
2y ago

Aim denial of service vulnerability

Aim denial of service vulnerability

▾ Twilightaim · aimEPSS 0.58%via OSV
CVE-2024-39689LowPoC
2y ago

Certifi removes GLOBALTRUST root certificate

Certifi removes GLOBALTRUST root certificate

▾ Twilightcertifi · certifiEPSS 1.0%via OSV
CVE-2024-32498Medium· 6.5
2y ago

OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access

OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access

▾ Sunlitcinder · cinderEPSS 0.83%via OSV
CVE-2024-5753High· 7.5
2y ago

Vanna vulnerable to SQL Injection

Vanna vulnerable to SQL Injection

▾ Twilightvanna · vannaEPSS 0.60%via OSV
CVE-2024-31223Medium· 5.3PoC
2y ago

Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL

Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL

▾ Twilightethyca-fides · ethyca-fidesEPSS 1.1%via OSV
CVE-2024-38537None· 0.0PoC
2y ago

Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js

Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js

▾ Twilightethyca-fides · ethyca-fidesEPSS 1.4%via OSV
CVE-2024-38519High· 7.8
2y ago

yt-dlp File system modification and RCE through improper file-extension sanitization

yt-dlp File system modification and RCE through improper file-extension sanitization

▾ Twilightyt-dlp · yt-dlpEPSS 0.33%via OSV
CVE-2024-39303Medium· 4.4
2y ago

Weblate vulnerable to improper sanitization of project backups

Weblate vulnerable to improper sanitization of project backups

▾ Sunlitweblate · weblateEPSS 0.32%via OSV
CVE-2024-39705High· 7.5
2y ago

ntlk unsafe deserialization vulnerability

ntlk unsafe deserialization vulnerability

▾ Twilightnltk · nltkEPSS 1.3%via OSV
CVE-2024-5980Critical· 9.1
2y ago

pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

▾ Midnightlightning · lightningEPSS 1.3%via OSV
CVE-2024-6090High· 7.5
2y ago

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histo…

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target s…

▾ Twilightchuanhuchatgpt · chuanhuchatgptEPSS 0.86%via OSV
CVE-2024-6038High· 7.5
2y ago

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerabilit…

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-p…

▾ Twilightchuanhuchatgpt · chuanhuchatgptEPSS 0.66%via OSV
CVE-2024-6139High· 7.3
2y ago

lollms vulnerable to dot-dot-slash path traversal in XTTS server

lollms vulnerable to dot-dot-slash path traversal in XTTS server

▾ Twilightlollms · lollmsEPSS 0.52%via OSV
CVE-2024-5710Medium· 5.3
2y ago

litellm vulnerable to improper access control in team management

litellm vulnerable to improper access control in team management

▾ Sunlitlitellm · litellmEPSS 0.41%via OSV
CVE-2024-22231Medium· 5.0
2y ago

Directory creation by malicious user in saltstack

Directory creation by malicious user in saltstack

▾ Sunlitsalt · saltEPSS 0.69%via OSV
CVE-2024-5824High· 7.4
2y ago

lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE

lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE

▾ Twilightlollms · lollmsEPSS 0.45%via OSV
CVE-2024-6085High· 8.6
2y ago

lollms vulnerable to path traversal due to unauthenticated root folder settings change

lollms vulnerable to path traversal due to unauthenticated root folder settings change

▾ Twilightlollms · lollmsEPSS 0.64%via OSV
CVE-2024-5979High· 7.5
2y ago

h2o vulnerable to unexpected POST request shutting down server

h2o vulnerable to unexpected POST request shutting down server

▾ Twilighth2o · h2oEPSS 0.79%via OSV
CVEs tagged “pip” — page 107 · VulnSea