Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2024-5629Medium· 4.7PyMongo Out-of-bounds Read in the bson module
PyMongo Out-of-bounds Read in the bson module
CVE-2024-4253Critical· 9.1PoCA command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The…
A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing…
CVE-2024-37055High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37059High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37065High· 7.8Skops unsafe deserialization
Skops unsafe deserialization
CVE-2024-37061High· 8.8MLFlow improper input validation
MLFlow improper input validation
CVE-2024-37057High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37054High· 8.8PoCMLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37062High· 7.8ydata unsafe deserialization
ydata unsafe deserialization
CVE-2024-37058High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37060High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37064High· 7.8ydata unsafe deserialization
ydata unsafe deserialization
CVE-2024-37056High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37052High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37053High· 8.8MLFlow unsafe deserialization
MLFlow unsafe deserialization
CVE-2024-37063High· 7.8ydata cross-site scripting
ydata cross-site scripting
CVE-2024-35228Medium· 5.5Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`
Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`
CVE-2024-35189Medium· 6.5Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints
Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints
CVE-2024-3924Medium· 4.4code injection vulnerability exists in the huggingface/text-generation-inference repository
code injection vulnerability exists in the huggingface/text-generation-inference repository
CVE-2024-35196Low· 2.0Slack integration leaks sensitive information in logs
Slack integration leaks sensitive information in logs
CVE-2024-4330Medium· 4.0path traversal vulnerability was identified in the parisneo/lollms-webui
path traversal vulnerability was identified in the parisneo/lollms-webui
CVE-2024-34715Low· 2.3Fides Webserver Logs Hosted Database Password Partial Exposure Vulnerability
Fides Webserver Logs Hosted Database Password Partial Exposure Vulnerability
CVE-2024-36105Medium· 5.3dbt allows Binding to an Unrestricted IP Address via socketsocket
dbt allows Binding to an Unrestricted IP Address via socketsocket
CVE-2024-36110High· 8.2ansibleguy-webui Cross-site Scripting vulnerability
ansibleguy-webui Cross-site Scripting vulnerability
CVE-2022-4969Medium· 5.3rockhopper Buffer Overflow vulnerability
rockhopper Buffer Overflow vulnerability
CVE-2024-28188Medium· 5.3jupyter-scheduler's endpoint is missing authentication
jupyter-scheduler's endpoint is missing authentication
CVE-2024-32969Low· 2.7vantage6 collaboration admins can extend their influence by expanding the collaboration
vantage6 collaboration admins can extend their influence by expanding the collaboration
CVE-2024-36039Critical· 9.8PoCPyMySQL SQL Injection vulnerability
PyMySQL SQL Injection vulnerability
CVE-2024-35180Medium· 6.1OMERO.web must check that the JSONP callback is a valid function
OMERO.web must check that the JSONP callback is a valid function
CVE-2024-35061High· 7.3NASA AIT-Core uses unencrypted channels to exchange data over the network
NASA AIT-Core uses unencrypted channels to exchange data over the network