VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2024-5629Medium· 4.7
2y ago

PyMongo Out-of-bounds Read in the bson module

PyMongo Out-of-bounds Read in the bson module

▾ Sunlitpymongo · pymongoEPSS 0.66%via OSV
CVE-2024-4253Critical· 9.1PoC
2y ago

A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The…

A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing…

▾ Abyssalgradio · gradioEPSS 1.7%via OSV
CVE-2024-37055High· 8.8
2y ago

MLFlow unsafe deserialization

MLFlow unsafe deserialization

▾ Twilightmlflow · mlflowEPSS 0.62%via OSV
CVE-2024-37059High· 8.8
2y ago

MLFlow unsafe deserialization

MLFlow unsafe deserialization

▾ Twilightmlflow · mlflowEPSS 0.62%via OSV
CVE-2024-37065High· 7.8
2y ago

Skops unsafe deserialization

Skops unsafe deserialization

▾ Twilightskops · skopsEPSS 0.24%via OSV
CVE-2024-37061High· 8.8
2y ago

MLFlow improper input validation

MLFlow improper input validation

▾ Twilightmlflow · mlflowEPSS 0.88%via OSV
CVE-2024-37057High· 8.8
2y ago

MLFlow unsafe deserialization

MLFlow unsafe deserialization

▾ Twilightmlflow · mlflowEPSS 0.62%via OSV
CVE-2024-37054High· 8.8PoC
2y ago

MLFlow unsafe deserialization

MLFlow unsafe deserialization

▾ Midnightmlflow · mlflowEPSS 0.70%via OSV
CVE-2024-37062High· 7.8
2y ago

ydata unsafe deserialization

ydata unsafe deserialization

▾ Twilightydata-profiling · ydata-profilingEPSS 0.24%via OSV
CVE-2024-37058High· 8.8
2y ago

MLFlow unsafe deserialization

MLFlow unsafe deserialization

▾ Twilightmlflow · mlflowEPSS 0.62%via OSV
CVE-2024-37060High· 8.8
2y ago

MLFlow unsafe deserialization

MLFlow unsafe deserialization

▾ Twilightmlflow · mlflowEPSS 0.78%via OSV
CVE-2024-37064High· 7.8
2y ago

ydata unsafe deserialization

ydata unsafe deserialization

▾ Twilightydata-profiling · ydata-profilingEPSS 0.24%via OSV
CVE-2024-37056High· 8.8
2y ago

MLFlow unsafe deserialization

MLFlow unsafe deserialization

▾ Twilightmlflow · mlflowEPSS 0.62%via OSV
CVE-2024-37052High· 8.8
2y ago

MLFlow unsafe deserialization

MLFlow unsafe deserialization

▾ Twilightmlflow · mlflowEPSS 0.66%via OSV
CVE-2024-37053High· 8.8
2y ago

MLFlow unsafe deserialization

MLFlow unsafe deserialization

▾ Twilightmlflow · mlflowEPSS 0.62%via OSV
CVE-2024-37063High· 7.8
2y ago

ydata cross-site scripting

ydata cross-site scripting

▾ Twilightydata-profiling · ydata-profilingEPSS 0.32%via OSV
CVE-2024-35228Medium· 5.5
2y ago

Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`

Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`

▾ Sunlitwagtail · wagtailEPSS 0.33%via OSV
CVE-2024-35189Medium· 6.5
2y ago

Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints

Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.58%via OSV
CVE-2024-3924Medium· 4.4
2y ago

code injection vulnerability exists in the huggingface/text-generation-inference repository

code injection vulnerability exists in the huggingface/text-generation-inference repository

▾ Sunlittext-generation · text-generationEPSS 0.32%via OSV
CVE-2024-35196Low· 2.0
2y ago

Slack integration leaks sensitive information in logs

Slack integration leaks sensitive information in logs

▾ Sunlitsentry · sentryEPSS 0.57%via OSV
CVE-2024-4330Medium· 4.0
2y ago

path traversal vulnerability was identified in the parisneo/lollms-webui

path traversal vulnerability was identified in the parisneo/lollms-webui

▾ Sunlitlollms · lollmsEPSS 0.29%via OSV
CVE-2024-34715Low· 2.3
2y ago

Fides Webserver Logs Hosted Database Password Partial Exposure Vulnerability

Fides Webserver Logs Hosted Database Password Partial Exposure Vulnerability

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.27%via OSV
CVE-2024-36105Medium· 5.3
2y ago

dbt allows Binding to an Unrestricted IP Address via socketsocket

dbt allows Binding to an Unrestricted IP Address via socketsocket

▾ Sunlitdbt-core · dbt-coreEPSS 0.71%via OSV
CVE-2024-36110High· 8.2
2y ago

ansibleguy-webui Cross-site Scripting vulnerability

ansibleguy-webui Cross-site Scripting vulnerability

▾ Twilightansibleguy-webui · ansibleguy-webuiEPSS 0.40%via OSV
CVE-2022-4969Medium· 5.3
2y ago

rockhopper Buffer Overflow vulnerability

rockhopper Buffer Overflow vulnerability

▾ Sunlitrockhopper · rockhopperEPSS 0.23%via OSV
CVE-2024-28188Medium· 5.3
2y ago

jupyter-scheduler's endpoint is missing authentication

jupyter-scheduler's endpoint is missing authentication

▾ Sunlitjupyter-scheduler · jupyter-schedulerEPSS 0.33%via OSV
CVE-2024-32969Low· 2.7
2y ago

vantage6 collaboration admins can extend their influence by expanding the collaboration

vantage6 collaboration admins can extend their influence by expanding the collaboration

▾ Sunlitvantage6 · vantage6EPSS 0.32%via OSV
CVE-2024-36039Critical· 9.8PoC
2y ago

PyMySQL SQL Injection vulnerability

PyMySQL SQL Injection vulnerability

▾ Abyssalpymysql · pymysqlEPSS 0.69%via OSV
CVE-2024-35180Medium· 6.1
2y ago

OMERO.web must check that the JSONP callback is a valid function

OMERO.web must check that the JSONP callback is a valid function

▾ Sunlitomero-web · omero-webEPSS 0.29%via OSV
CVE-2024-35061High· 7.3
2y ago

NASA AIT-Core uses unencrypted channels to exchange data over the network

NASA AIT-Core uses unencrypted channels to exchange data over the network

▾ Twilightait-core · ait-coreEPSS 0.55%via OSV
CVEs tagged “pip” — page 109 · VulnSea