Tagged “pip”
CVEs tagged pip, newest first.
4662 CVEsRSS
CVE-2024-31215Medium· 6.3Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check
Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check
CVE-2024-3116High· 7.4PoCpgAdmin Remote Code Execution (RCE) vulnerability
pgAdmin Remote Code Execution (RCE) vulnerability
CVE-2024-28219Medium· 6.7Pillow buffer overflow vulnerability
Pillow buffer overflow vulnerability
CVE-2024-30265High· 7.5Voilà Local file inclusion
Voilà Local file inclusion
CVE-2024-30248High· 7.7Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page
Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page
CVE-2024-29888Medium· 4.2Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method
Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method
CVE-2024-28233High· 8.1Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
CVE-2024-2206High· 7.3gradio Server-Side Request Forgery vulnerability
gradio Server-Side Request Forgery vulnerability
CVE-2024-1455Medium· 5.9LangChain's XMLOutputParser vulnerable to XML Entity Expansion
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
CVE-2024-29199Low· 3.7Unauthenticated views may expose information to anonymous users
Unauthenticated views may expose information to anonymous users
CVE-2024-29735Medium· 5.3Apache Airflow Improper Preservation of Permissions vulnerability
Apache Airflow Improper Preservation of Permissions vulnerability
CVE-2024-29189High· 7.4ansys-geometry-core OS Command Injection vulnerability
ansys-geometry-core OS Command Injection vulnerability
CVE-2024-1603High· 7.5PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file
PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file
CVE-2024-29190High· 7.3SSRF Vulnerability on assetlinks_check(act_name, well_knowns)
SSRF Vulnerability on assetlinks_check(act_name, well_knowns)
CVE-2024-29019High· 8.1ESPHome vulnerable to Authentication bypass via Cross site request forgery
ESPHome vulnerable to Authentication bypass via Cross site request forgery
CVE-2024-29032Medium· 5.3`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code
`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code
CVE-2024-29033High· 7.5GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
CVE-2024-21503Medium· 5.3Black vulnerable to Regular Expression Denial of Service (ReDoS)
Black vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2024-28865High· 7.5Denial of service via regular expression
Denial of service via regular expression
CVE-2024-29156Medium· 6.5Information leakage in YAQL
Information leakage in YAQL
CVE-2023-41334High· 8.4RCE in TranformGraph().to_dot_graph function
RCE in TranformGraph().to_dot_graph function
CVE-2024-22513LowPoCImproper Privilege Management in djangorestframework-simplejwt
Improper Privilege Management in djangorestframework-simplejwt
CVE-2024-27351Medium· 5.3Regular expression denial-of-service in Django
Regular expression denial-of-service in Django
CVE-2024-24770Medium· 5.3vantage6 vulnerable to a username timing attack on recover password/MFA token
vantage6 vulnerable to a username timing attack on recover password/MFA token
CVE-2024-23823Medium· 4.2vantage6's CORS settings overly permissive
vantage6's CORS settings overly permissive
CVE-2024-28423Critical· 9.8Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vuln…
Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.
CVE-2024-27097Medium· 4.3Potential log injection in reset user endpoint in CKAN
Potential log injection in reset user endpoint in CKAN
CVE-2024-26164High· 8.8Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server
Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server
CVE-2024-52288Medium· 5.1LibOSDP RMAC revert to the beginning of the session
LibOSDP RMAC revert to the beginning of the session
CVE-2024-2319Medium· 5.4Django MarkdownX Cross-Site Scripting (XSS) vulnerability
Django MarkdownX Cross-Site Scripting (XSS) vulnerability