VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2024-4216High· 7.4
2y ago

pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload

pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload

▾ Twilightpgadmin4 · pgadmin4EPSS 0.46%via OSV
CVE-2024-4215High· 7.4
2y ago

pgAdmin is affected by a multi-factor authentication bypass vulnerability

pgAdmin is affected by a multi-factor authentication bypass vulnerability

▾ Twilightpgadmin4 · pgadmin4EPSS 0.63%via OSV
CVE-2024-32882Low· 2.7
2y ago

Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`

Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`

▾ Sunlitwagtail · wagtailEPSS 0.48%via OSV
CVE-2024-32979High· 7.5
2y ago

nautobot has reflected Cross-site Scripting potential in all object list views

nautobot has reflected Cross-site Scripting potential in all object list views

▾ Twilightnautobot · nautobotEPSS 0.49%via OSV
CVE-2023-46960High· 8.6
2y ago

PyPXE Buffer Overflow vulnerability

PyPXE Buffer Overflow vulnerability

▾ Twilightpypxe · pypxeEPSS 0.54%via OSV
CVE-2023-1000Medium· 6.3
2y ago

dcnnt-py is vulnerable to command injection via Notification Handler

dcnnt-py is vulnerable to command injection via Notification Handler

▾ Sunlitdcnnt · dcnntEPSS 1.3%via OSV
CVE-2024-33663High· 7.4
2y ago

python-jose algorithm confusion with OpenSSH ECDSA keys

python-jose algorithm confusion with OpenSSH ECDSA keys

▾ Twilightpython-jose · python-joseEPSS 0.31%via OSV
CVE-2024-32880Critical· 9.1
2y ago

pyLoad allows upload to arbitrary folder lead to RCE

pyLoad allows upload to arbitrary folder lead to RCE

▾ Midnightpyload-ng · pyload-ngEPSS 1.4%via OSV
CVE-2024-32879Medium· 4.9
2y ago

social-auth-app-django affected by Improper Handling of Case Sensitivity

social-auth-app-django affected by Improper Handling of Case Sensitivity

▾ Sunlitsocial-auth-app-django · social-auth-app-djangoEPSS 0.58%via OSV
CVE-2024-31208Medium· 6.5
2y ago

Synapse V2 state resolution weakness allows Denial of Service (DoS)

Synapse V2 state resolution weakness allows Denial of Service (DoS)

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.5%via OSV
CVE-2024-28717High· 7.8
2y ago

OpenStack Storlets arbitrary code execution vulnerability

OpenStack Storlets arbitrary code execution vulnerability

▾ Twilightstorlets · storletsEPSS 0.89%via OSV
CVE-2024-29733Low· 2.7
2y ago

Improper Certificate Validation vulnerability in Apache Airflow FTP Provider

Improper Certificate Validation vulnerability in Apache Airflow FTP Provider

▾ Sunlitapache-airflow-providers-ftp · apache-airflow-providers-ftpEPSS 0.63%via OSV
CVE-2024-1681Medium· 5.3
2y ago

flask-cors vulnerable to log injection when the log level is set to debug

flask-cors vulnerable to log injection when the log level is set to debug

▾ Sunlitflask-cors · flask-corsEPSS 0.58%via OSV
CVE-2024-27306Medium· 6.1
2y ago

aiohttp Cross-site Scripting vulnerability on index pages for static file handling

aiohttp Cross-site Scripting vulnerability on index pages for static file handling

▾ Sunlitaiohttp · aiohttpEPSS 0.67%via OSV
CVE-2024-32474High· 7.3
2y ago

Sentry vulnerable to leaking superuser cleartext password in logs

Sentry vulnerable to leaking superuser cleartext password in logs

▾ Twilightsentry · sentryEPSS 0.43%via OSV
CVE-2024-31869Medium· 4.3
2y ago

Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used

Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used

▾ Sunlitapache-airflow · apache-airflowEPSS 1.1%via OSV
CVE-2024-31580High· 7.5
2y ago

PyTorch heap buffer overflow vulnerability

PyTorch heap buffer overflow vulnerability

▾ Twilighttorch · torchEPSS 0.22%via OSV
CVE-2024-1135High· 8.2
2y ago

Request smuggling leading to endpoint restriction bypass in Gunicorn

Request smuggling leading to endpoint restriction bypass in Gunicorn

▾ Twilightgunicorn · gunicornEPSS 3.0%via OSV
CVE-2024-3571Medium· 6.5
2y ago

langchain vulnerable to path traversal

langchain vulnerable to path traversal

▾ Sunlitlangchain · langchainEPSS 1.9%via OSV
CVE-2024-1183Medium· 6.5PoC
2y ago

gradio Server-Side Request Forgery vulnerability

gradio Server-Side Request Forgery vulnerability

▾ Twilightgradio · gradioEPSS 1.8%via OSV
CVE-2024-1594High· 7.5
2y ago

mlflow vulnerable to Path Traversal

mlflow vulnerable to Path Traversal

▾ Twilightmlflow · mlflowEPSS 0.71%via OSV
CVE-2024-1558High· 7.5
2y ago

mlflow vulnerable to Path Traversal

mlflow vulnerable to Path Traversal

▾ Twilightmlflow · mlflowEPSS 0.86%via OSV
CVE-2024-1561High· 7.5PoC
2y ago

gradio vulnerable to Path Traversal

gradio vulnerable to Path Traversal

▾ Midnightgradio · gradioEPSS 9.3%via OSV
CVE-2024-1483High· 7.5PoC
2y ago

mlflow Path Traversal vulnerability

mlflow Path Traversal vulnerability

▾ Midnightmlflow · mlflowEPSS 2.7%via OSV
CVE-2024-1593High· 7.5
2y ago

mlflow vulnerable to Path Traversal

mlflow vulnerable to Path Traversal

▾ Twilightmlflow · mlflowEPSS 0.70%via OSV
CVE-2024-1560High· 8.1
2y ago

mlflow vulnerable to Path Traversal

mlflow vulnerable to Path Traversal

▾ Twilightmlflow · mlflowEPSS 0.86%via OSV
CVE-2024-3772Medium· 5.9
2y ago

Pydantic regular expression denial of service

Pydantic regular expression denial of service

▾ Sunlitpydantic · pydanticEPSS 0.96%via OSV
CVE-2024-4340High· 7.5
2y ago

sqlparse parsing heavily nested list leads to Denial of Service

sqlparse parsing heavily nested list leads to Denial of Service

▾ Twilightsqlparse · sqlparseEPSS 3.2%via OSV
CVE-2024-32005High· 8.2
2y ago

NiceGUI allows potential access to local file system

NiceGUI allows potential access to local file system

▾ Twilightnicegui · niceguiEPSS 0.76%via OSV
CVE-2024-28718Medium· 6.3
2y ago

OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack

OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack

▾ Sunlitmagnum · magnumEPSS 1.1%via OSV
CVEs tagged “pip” — page 111 · VulnSea