VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4663 CVEsRSS

CVE-2024-28717High· 7.8
2y ago

OpenStack Storlets arbitrary code execution vulnerability

OpenStack Storlets arbitrary code execution vulnerability

▾ Twilightstorlets · storletsEPSS 0.89%via OSV
CVE-2024-29733Low· 2.7
2y ago

Improper Certificate Validation vulnerability in Apache Airflow FTP Provider

Improper Certificate Validation vulnerability in Apache Airflow FTP Provider

▾ Sunlitapache-airflow-providers-ftp · apache-airflow-providers-ftpEPSS 0.63%via OSV
CVE-2024-1681Medium· 5.3
2y ago

flask-cors vulnerable to log injection when the log level is set to debug

flask-cors vulnerable to log injection when the log level is set to debug

▾ Sunlitflask-cors · flask-corsEPSS 0.58%via OSV
CVE-2024-27306Medium· 6.1
2y ago

aiohttp Cross-site Scripting vulnerability on index pages for static file handling

aiohttp Cross-site Scripting vulnerability on index pages for static file handling

▾ Sunlitaiohttp · aiohttpEPSS 0.67%via OSV
CVE-2024-32474High· 7.3
2y ago

Sentry vulnerable to leaking superuser cleartext password in logs

Sentry vulnerable to leaking superuser cleartext password in logs

▾ Twilightsentry · sentryEPSS 0.43%via OSV
CVE-2024-31869Medium· 4.3
2y ago

Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used

Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used

▾ Sunlitapache-airflow · apache-airflowEPSS 1.1%via OSV
CVE-2024-31580High· 7.5
2y ago

PyTorch heap buffer overflow vulnerability

PyTorch heap buffer overflow vulnerability

▾ Twilighttorch · torchEPSS 0.22%via OSV
CVE-2024-1135High· 8.2
2y ago

Request smuggling leading to endpoint restriction bypass in Gunicorn

Request smuggling leading to endpoint restriction bypass in Gunicorn

▾ Twilightgunicorn · gunicornEPSS 3.0%via OSV
CVE-2024-3571Medium· 6.5
2y ago

langchain vulnerable to path traversal

langchain vulnerable to path traversal

▾ Sunlitlangchain · langchainEPSS 1.9%via OSV
CVE-2024-1183Medium· 6.5PoC
2y ago

gradio Server-Side Request Forgery vulnerability

gradio Server-Side Request Forgery vulnerability

▾ Twilightgradio · gradioEPSS 1.8%via OSV
CVE-2024-1594High· 7.5
2y ago

mlflow vulnerable to Path Traversal

mlflow vulnerable to Path Traversal

▾ Twilightmlflow · mlflowEPSS 0.71%via OSV
CVE-2024-1558High· 7.5
2y ago

mlflow vulnerable to Path Traversal

mlflow vulnerable to Path Traversal

▾ Twilightmlflow · mlflowEPSS 0.86%via OSV
CVE-2024-1561High· 7.5PoC
2y ago

gradio vulnerable to Path Traversal

gradio vulnerable to Path Traversal

▾ Midnightgradio · gradioEPSS 9.3%via OSV
CVE-2024-1483High· 7.5PoC
2y ago

mlflow Path Traversal vulnerability

mlflow Path Traversal vulnerability

▾ Midnightmlflow · mlflowEPSS 2.7%via OSV
CVE-2024-1593High· 7.5
2y ago

mlflow vulnerable to Path Traversal

mlflow vulnerable to Path Traversal

▾ Twilightmlflow · mlflowEPSS 0.70%via OSV
CVE-2024-1560High· 8.1
2y ago

mlflow vulnerable to Path Traversal

mlflow vulnerable to Path Traversal

▾ Twilightmlflow · mlflowEPSS 0.86%via OSV
CVE-2024-3772Medium· 5.9
2y ago

Pydantic regular expression denial of service

Pydantic regular expression denial of service

▾ Sunlitpydantic · pydanticEPSS 0.96%via OSV
CVE-2024-4340High· 7.5
2y ago

sqlparse parsing heavily nested list leads to Denial of Service

sqlparse parsing heavily nested list leads to Denial of Service

▾ Twilightsqlparse · sqlparseEPSS 3.2%via OSV
CVE-2024-32005High· 8.2
2y ago

NiceGUI allows potential access to local file system

NiceGUI allows potential access to local file system

▾ Twilightnicegui · niceguiEPSS 0.76%via OSV
CVE-2024-28718Medium· 6.3
2y ago

OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack

OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack

▾ Sunlitmagnum · magnumEPSS 1.1%via OSV
CVE-2024-3651Medium· 6.2PoC
2y ago

Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode

Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode

▾ Twilightidna · idnaEPSS 1.4%via OSV
CVE-2023-29483Medium· 5.9
2y ago

Potential DoS via the Tudoor mechanism in eventlet and dnspython

Potential DoS via the Tudoor mechanism in eventlet and dnspython

▾ Sunliteventlet · eventletEPSS 1.9%via OSV
CVE-2024-2195Critical· 9.8
2y ago

Aim Web API vulnerable to Remote Code Execution

Aim Web API vulnerable to Remote Code Execution

▾ Midnightaim · aimEPSS 1.8%via OSV
CVE-2024-2217High· 7.5
2y ago

gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnera…

gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is present in both authenticated and unauthenticated versions of the application, enabling at…

▾ Twilightchuanhuchatgpt · chuanhuchatgptEPSS 0.78%via OSV
CVE-2024-22423High· 8.3
2y ago

yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)

yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)

▾ Twilightyt-dlp · yt-dlpEPSS 1.3%via OSV
CVE-2024-2196High· 8.8
2y ago

Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations

Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations

▾ Twilightaim · aimEPSS 0.59%via OSV
CVE-2024-2952Critical· 9.8
2y ago

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

▾ Midnightlitellm · litellmEPSS 1.3%via OSV
CVE-2024-3568Low· 3.4PoC
2y ago

Transformers Deserialization of Untrusted Data vulnerability

Transformers Deserialization of Untrusted Data vulnerability

▾ Twilighttransformers · transformersEPSS 2.1%via OSV
CVE-2024-29905High· 8.1
2y ago

DIRAC: Unauthorized users can read proxy contents during generation

DIRAC: Unauthorized users can read proxy contents during generation

▾ Twilightdirac · diracEPSS 0.32%via OSV
CVE-2024-28732High· 7.5
2y ago

Ryu Infinite Loop vulnerability

Ryu Infinite Loop vulnerability

▾ Twilightryu · ryuEPSS 0.82%via OSV
CVEs tagged “pip” — page 112 · VulnSea