Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2024-4216High· 7.4pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload
pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload
CVE-2024-4215High· 7.4pgAdmin is affected by a multi-factor authentication bypass vulnerability
pgAdmin is affected by a multi-factor authentication bypass vulnerability
CVE-2024-32882Low· 2.7Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`
Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`
CVE-2024-32979High· 7.5nautobot has reflected Cross-site Scripting potential in all object list views
nautobot has reflected Cross-site Scripting potential in all object list views
CVE-2023-46960High· 8.6PyPXE Buffer Overflow vulnerability
PyPXE Buffer Overflow vulnerability
CVE-2023-1000Medium· 6.3dcnnt-py is vulnerable to command injection via Notification Handler
dcnnt-py is vulnerable to command injection via Notification Handler
CVE-2024-33663High· 7.4python-jose algorithm confusion with OpenSSH ECDSA keys
python-jose algorithm confusion with OpenSSH ECDSA keys
CVE-2024-32880Critical· 9.1pyLoad allows upload to arbitrary folder lead to RCE
pyLoad allows upload to arbitrary folder lead to RCE
CVE-2024-32879Medium· 4.9social-auth-app-django affected by Improper Handling of Case Sensitivity
social-auth-app-django affected by Improper Handling of Case Sensitivity
CVE-2024-31208Medium· 6.5Synapse V2 state resolution weakness allows Denial of Service (DoS)
Synapse V2 state resolution weakness allows Denial of Service (DoS)
CVE-2024-28717High· 7.8OpenStack Storlets arbitrary code execution vulnerability
OpenStack Storlets arbitrary code execution vulnerability
CVE-2024-29733Low· 2.7Improper Certificate Validation vulnerability in Apache Airflow FTP Provider
Improper Certificate Validation vulnerability in Apache Airflow FTP Provider
CVE-2024-1681Medium· 5.3flask-cors vulnerable to log injection when the log level is set to debug
flask-cors vulnerable to log injection when the log level is set to debug
CVE-2024-27306Medium· 6.1aiohttp Cross-site Scripting vulnerability on index pages for static file handling
aiohttp Cross-site Scripting vulnerability on index pages for static file handling
CVE-2024-32474High· 7.3Sentry vulnerable to leaking superuser cleartext password in logs
Sentry vulnerable to leaking superuser cleartext password in logs
CVE-2024-31869Medium· 4.3Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
CVE-2024-31580High· 7.5PyTorch heap buffer overflow vulnerability
PyTorch heap buffer overflow vulnerability
CVE-2024-1135High· 8.2Request smuggling leading to endpoint restriction bypass in Gunicorn
Request smuggling leading to endpoint restriction bypass in Gunicorn
CVE-2024-3571Medium· 6.5langchain vulnerable to path traversal
langchain vulnerable to path traversal
CVE-2024-1183Medium· 6.5PoCgradio Server-Side Request Forgery vulnerability
gradio Server-Side Request Forgery vulnerability
CVE-2024-1594High· 7.5mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-1558High· 7.5mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-1561High· 7.5PoCgradio vulnerable to Path Traversal
gradio vulnerable to Path Traversal
CVE-2024-1483High· 7.5PoCmlflow Path Traversal vulnerability
mlflow Path Traversal vulnerability
CVE-2024-1593High· 7.5mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-1560High· 8.1mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-3772Medium· 5.9Pydantic regular expression denial of service
Pydantic regular expression denial of service
CVE-2024-4340High· 7.5sqlparse parsing heavily nested list leads to Denial of Service
sqlparse parsing heavily nested list leads to Denial of Service
CVE-2024-32005High· 8.2NiceGUI allows potential access to local file system
NiceGUI allows potential access to local file system
CVE-2024-28718Medium· 6.3OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack
OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack