Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2024-22232High· 7.7Path traversal in saltstack
Path traversal in saltstack
CVE-2024-21520Medium· 6.1PoCCross-site Scripting in djangorestframework
Cross-site Scripting in djangorestframework
CVE-2024-38526High· 7.2PoCpdoc embeds link to malicious CDN if math mode is enabled
pdoc embeds link to malicious CDN if math mode is enabled
CVE-2024-4460Medium· 4.3Improper line feed handling in zenml
Improper line feed handling in zenml
CVE-2024-3121Medium· 6.8PoCRemote Code Execution in create_conda_env function in lollms
Remote Code Execution in create_conda_env function in lollms
CVE-2024-4940Medium· 5.4PoCOpen redirect in gradio
Open redirect in gradio
CVE-2024-34693Medium· 6.8PoCApache Superset server arbitrary file read
Apache Superset server arbitrary file read
CVE-2024-28397High· 8.8PoCjs2py allows remote code execution
js2py allows remote code execution
CVE-2024-34694High· 8.1LNbits improperly handles potential network and payment failures when using Eclair backend
LNbits improperly handles potential network and payment failures when using Eclair backend
CVE-2024-37891Medium· 4.4urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
CVE-2024-25142LowApache Airflow does not return the "Cache-Control" header for dynamic content
Apache Airflow does not return the "Cache-Control" header for dynamic content
CVE-2024-37300High· 8.1Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0
CVE-2024-37301High· 7.2document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
CVE-2024-35255Medium· 5.5Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
CVE-2024-4680Low· 3.9zenml-io/zenml does not expire the session after password reset
zenml-io/zenml does not expire the session after password reset
CVE-2024-37388Critical· 9.1ebookmeta XML External Entity vulnerability
ebookmeta XML External Entity vulnerability
GHSA-w235-7p84-xx57Medium· 6.5Tornado has a CRLF injection in CurlAsyncHTTPClient headers
Tornado has a CRLF injection in CurlAsyncHTTPClient headers
CVE-2024-5206Medium· 5.3scikit-learn sensitive data leakage vulnerability
scikit-learn sensitive data leakage vulnerability
CVE-2024-35178High· 7.5Jupyter server on Windows discloses Windows user password hash
Jupyter server on Windows discloses Windows user password hash
CVE-2024-5452Critical· 9.8PoCRemote code execution in pytorch lightning
Remote code execution in pytorch lightning
GHSA-753j-mpmx-qq6gMedium· 5.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado
CVE-2024-2965Medium· 4.2Denial of service in langchain-community
Denial of service in langchain-community
CVE-2024-5550Medium· 5.3Arbitrary system path lookup in h20
Arbitrary system path lookup in h20
CVE-2024-3095Medium· 4.8Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever
Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever
CVE-2024-5225Medium· 6.4SQL injection in litellm
SQL injection in litellm
CVE-2024-4325High· 8.6PoCServer-Side Request Forgery in gradio
Server-Side Request Forgery in gradio
CVE-2024-4890Medium· 4.9PoCSQL injection in litellm
SQL injection in litellm
CVE-2024-3099Medium· 5.4Undefined Behavior in mlflow
Undefined Behavior in mlflow
CVE-2024-4888Medium· 6.5Arbitrary file deletion in litellm
Arbitrary file deletion in litellm
CVE-2024-3429Critical· 9.8LoLLMS Path Traversal vulnerability
LoLLMS Path Traversal vulnerability