VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2024-22232High· 7.7
2y ago

Path traversal in saltstack

Path traversal in saltstack

▾ Twilightsalt · saltEPSS 0.84%via OSV
CVE-2024-21520Medium· 6.1PoC
2y ago

Cross-site Scripting in djangorestframework

Cross-site Scripting in djangorestframework

▾ Twilightdjangorestframework · djangorestframeworkEPSS 1.1%via OSV
CVE-2024-38526High· 7.2PoC
2y ago

pdoc embeds link to malicious CDN if math mode is enabled

pdoc embeds link to malicious CDN if math mode is enabled

▾ Midnightpdoc · pdocEPSS 3.8%via OSV
CVE-2024-4460Medium· 4.3
2y ago

Improper line feed handling in zenml

Improper line feed handling in zenml

▾ Sunlitzenml · zenmlvia OSV
CVE-2024-3121Medium· 6.8PoC
2y ago

Remote Code Execution in create_conda_env function in lollms

Remote Code Execution in create_conda_env function in lollms

▾ Twilightlollms · lollmsEPSS 0.45%via OSV
CVE-2024-4940Medium· 5.4PoC
2y ago

Open redirect in gradio

Open redirect in gradio

▾ Twilightgradio · gradioEPSS 1.0%via OSV
CVE-2024-34693Medium· 6.8PoC
2y ago

Apache Superset server arbitrary file read

Apache Superset server arbitrary file read

▾ Twilightapache-superset · apache-supersetEPSS 1.6%via OSV
CVE-2024-28397High· 8.8PoC
2y ago

js2py allows remote code execution

js2py allows remote code execution

▾ Midnightjs2py · js2pyEPSS 4.5%via OSV
CVE-2024-34694High· 8.1
2y ago

LNbits improperly handles potential network and payment failures when using Eclair backend

LNbits improperly handles potential network and payment failures when using Eclair backend

▾ Twilightlnbits · lnbitsEPSS 0.60%via OSV
CVE-2024-37891Medium· 4.4
2y ago

urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects

urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects

▾ Sunliturllib3 · urllib3EPSS 1.1%via OSV
CVE-2024-25142Low
2y ago

Apache Airflow does not return the "Cache-Control" header for dynamic content

Apache Airflow does not return the "Cache-Control" header for dynamic content

▾ Sunlitapache-airflow · apache-airflowEPSS 0.32%via OSV
CVE-2024-37300High· 8.1
2y ago

Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0

Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0

▾ Twilightoauthenticator · oauthenticatorEPSS 0.40%via OSV
CVE-2024-37301High· 7.2
2y ago

document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection

document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection

▾ Twilightdocument-merge-service · document-merge-serviceEPSS 1.0%via OSV
CVE-2024-35255Medium· 5.5
2y ago

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

▾ Sunlitazure-identity · azure-identityEPSS 0.83%via OSV
CVE-2024-4680Low· 3.9
2y ago

zenml-io/zenml does not expire the session after password reset

zenml-io/zenml does not expire the session after password reset

▾ Sunlitzenml · zenmlEPSS 0.41%via OSV
CVE-2024-37388Critical· 9.1
2y ago

ebookmeta XML External Entity vulnerability

ebookmeta XML External Entity vulnerability

▾ Midnightebookmeta · ebookmetaEPSS 0.54%via OSV
GHSA-w235-7p84-xx57Medium· 6.5
2y ago

Tornado has a CRLF injection in CurlAsyncHTTPClient headers

Tornado has a CRLF injection in CurlAsyncHTTPClient headers

▾ Sunlittornado · tornadovia OSV
CVE-2024-5206Medium· 5.3
2y ago

scikit-learn sensitive data leakage vulnerability

scikit-learn sensitive data leakage vulnerability

▾ Sunlitscikit-learn · scikit-learnEPSS 0.19%via OSV
CVE-2024-35178High· 7.5
2y ago

Jupyter server on Windows discloses Windows user password hash

Jupyter server on Windows discloses Windows user password hash

▾ Twilightjupyter-server · jupyter-serverEPSS 0.70%via OSV
CVE-2024-5452Critical· 9.8PoC
2y ago

Remote code execution in pytorch lightning

Remote code execution in pytorch lightning

▾ Abyssallightning · lightningEPSS 27%via OSV
GHSA-753j-mpmx-qq6gMedium· 5.3
2y ago

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado

▾ Sunlittornado · tornadovia OSV
CVE-2024-2965Medium· 4.2
2y ago

Denial of service in langchain-community

Denial of service in langchain-community

▾ Sunlitlangchain-community · langchain-communityEPSS 0.30%via OSV
CVE-2024-5550Medium· 5.3
2y ago

Arbitrary system path lookup in h20

Arbitrary system path lookup in h20

▾ Sunlith2o · h2oEPSS 0.83%via OSV
CVE-2024-3095Medium· 4.8
2y ago

Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever

Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever

▾ Sunlitlangchain-community · langchain-communityEPSS 0.69%via OSV
CVE-2024-5225Medium· 6.4
2y ago

SQL injection in litellm

SQL injection in litellm

▾ Sunlitlitellm · litellmEPSS 0.43%via OSV
CVE-2024-4325High· 8.6PoC
2y ago

Server-Side Request Forgery in gradio

Server-Side Request Forgery in gradio

▾ Midnightgradio · gradioEPSS 37%via OSV
CVE-2024-4890Medium· 4.9PoC
2y ago

SQL injection in litellm

SQL injection in litellm

▾ Twilightlitellm · litellmEPSS 0.56%via OSV
CVE-2024-3099Medium· 5.4
2y ago

Undefined Behavior in mlflow

Undefined Behavior in mlflow

▾ Sunlitmlflow · mlflowEPSS 0.44%via OSV
CVE-2024-4888Medium· 6.5
2y ago

Arbitrary file deletion in litellm

Arbitrary file deletion in litellm

▾ Sunlitlitellm · litellmEPSS 0.62%via OSV
CVE-2024-3429Critical· 9.8
2y ago

LoLLMS Path Traversal vulnerability

LoLLMS Path Traversal vulnerability

▾ Midnightlollms · lollmsEPSS 28%via OSV
CVEs tagged “pip” — page 108 · VulnSea