Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2024-35059Critical· 9.8NASA AIT-Core vulnerable to remote code execution
NASA AIT-Core vulnerable to remote code execution
CVE-2024-35057High· 7.5NASA AIT-Core vulnerable to remote code execution
NASA AIT-Core vulnerable to remote code execution
CVE-2024-35056Critical· 9.8NASA AIT-Core vulnerable to SQL Injection
NASA AIT-Core vulnerable to SQL Injection
CVE-2024-35058High· 7.5NASA AIT-Core vulnerable to remote code execution
NASA AIT-Core vulnerable to remote code execution
CVE-2024-1727Medium· 4.3Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
CVE-2024-34083Medium· 5.4aiosmtpd STARTTLS unencrypted commands injection
aiosmtpd STARTTLS unencrypted commands injection
CVE-2024-35195Medium· 5.6Requests `Session` object does not verify requests after making first request with verify=False
Requests `Session` object does not verify requests after making first request with verify=False
CVE-2024-4264High· 7.2litellm passes untrusted data to `eval` function without sanitization
litellm passes untrusted data to `eval` function without sanitization
CVE-2024-4078Critical· 9.8LoLLMS Command Injection vulnerability
LoLLMS Command Injection vulnerability
CVE-2024-4181High· 8.8RunGptLLM class in LlamaIndex has a command injection
RunGptLLM class in LlamaIndex has a command injection
CVE-2024-34359Critical· 9.6llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata
llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata
CVE-2024-34707High· 7.5Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
CVE-2024-32874Critical· 9.3Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service
Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service
CVE-2024-28148Medium· 4.3Apache Superset Incorrect Authorization vulnerability
Apache Superset Incorrect Authorization vulnerability
CVE-2024-34078HighArbitrary HTML present after sanitization because of unicode normalization
Arbitrary HTML present after sanitization because of unicode normalization
CVE-2024-34064Medium· 5.4PoCJinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
CVE-2024-32982High· 8.2Litestar and Starlite vulnerable to Path Traversal
Litestar and Starlite vulnerable to Path Traversal
CVE-2024-34069High· 7.5PoCWerkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
CVE-2024-34487MediumRyu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34486High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34488High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34484MediumRyu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34483High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34489High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34511Medium· 6.5Gradio's Component Server does not properly consider` _is_server_fn` for functions
Gradio's Component Server does not properly consider` _is_server_fn` for functions
CVE-2024-34072High· 7.8sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data
sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data
CVE-2024-34061Medium· 4.3PoCchangedetection.io Cross-site Scripting vulnerability
changedetection.io Cross-site Scripting vulnerability
CVE-2024-34062Low· 3.9tqdm CLI arguments injection attack
tqdm CLI arguments injection attack
CVE-2024-34073High· 7.8sagemaker-python-sdk Command Injection vulnerability
sagemaker-python-sdk Command Injection vulnerability
CVE-2024-30251High· 7.5aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests