Tagged “pip”
CVEs tagged pip, newest first.
4663 CVEsRSS
CVE-2024-28717High· 7.8OpenStack Storlets arbitrary code execution vulnerability
OpenStack Storlets arbitrary code execution vulnerability
CVE-2024-29733Low· 2.7Improper Certificate Validation vulnerability in Apache Airflow FTP Provider
Improper Certificate Validation vulnerability in Apache Airflow FTP Provider
CVE-2024-1681Medium· 5.3flask-cors vulnerable to log injection when the log level is set to debug
flask-cors vulnerable to log injection when the log level is set to debug
CVE-2024-27306Medium· 6.1aiohttp Cross-site Scripting vulnerability on index pages for static file handling
aiohttp Cross-site Scripting vulnerability on index pages for static file handling
CVE-2024-32474High· 7.3Sentry vulnerable to leaking superuser cleartext password in logs
Sentry vulnerable to leaking superuser cleartext password in logs
CVE-2024-31869Medium· 4.3Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
CVE-2024-31580High· 7.5PyTorch heap buffer overflow vulnerability
PyTorch heap buffer overflow vulnerability
CVE-2024-1135High· 8.2Request smuggling leading to endpoint restriction bypass in Gunicorn
Request smuggling leading to endpoint restriction bypass in Gunicorn
CVE-2024-3571Medium· 6.5langchain vulnerable to path traversal
langchain vulnerable to path traversal
CVE-2024-1183Medium· 6.5PoCgradio Server-Side Request Forgery vulnerability
gradio Server-Side Request Forgery vulnerability
CVE-2024-1594High· 7.5mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-1558High· 7.5mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-1561High· 7.5PoCgradio vulnerable to Path Traversal
gradio vulnerable to Path Traversal
CVE-2024-1483High· 7.5PoCmlflow Path Traversal vulnerability
mlflow Path Traversal vulnerability
CVE-2024-1593High· 7.5mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-1560High· 8.1mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-3772Medium· 5.9Pydantic regular expression denial of service
Pydantic regular expression denial of service
CVE-2024-4340High· 7.5sqlparse parsing heavily nested list leads to Denial of Service
sqlparse parsing heavily nested list leads to Denial of Service
CVE-2024-32005High· 8.2NiceGUI allows potential access to local file system
NiceGUI allows potential access to local file system
CVE-2024-28718Medium· 6.3OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack
OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack
CVE-2024-3651Medium· 6.2PoCInternationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode
Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode
CVE-2023-29483Medium· 5.9Potential DoS via the Tudoor mechanism in eventlet and dnspython
Potential DoS via the Tudoor mechanism in eventlet and dnspython
CVE-2024-2195Critical· 9.8Aim Web API vulnerable to Remote Code Execution
Aim Web API vulnerable to Remote Code Execution
CVE-2024-2217High· 7.5gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnera…
gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is present in both authenticated and unauthenticated versions of the application, enabling at…
CVE-2024-22423High· 8.3yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)
yt-dlp: `--exec` command injection when using `%q` in yt-dlp on Windows (Bypass of CVE-2023-40581)
CVE-2024-2196High· 8.8Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations
Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations
CVE-2024-2952Critical· 9.8LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
CVE-2024-3568Low· 3.4PoCTransformers Deserialization of Untrusted Data vulnerability
Transformers Deserialization of Untrusted Data vulnerability
CVE-2024-29905High· 8.1DIRAC: Unauthorized users can read proxy contents during generation
DIRAC: Unauthorized users can read proxy contents during generation
CVE-2024-28732High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability