VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4662 CVEsRSS

CVE-2024-31215Medium· 6.3
2y ago

Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check

Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check

▾ Sunlitmobsf · mobsfEPSS 0.51%via OSV
CVE-2024-3116High· 7.4PoC
2y ago

pgAdmin Remote Code Execution (RCE) vulnerability

pgAdmin Remote Code Execution (RCE) vulnerability

▾ Midnightpgadmin4 · pgadmin4EPSS 66%via OSV
CVE-2024-28219Medium· 6.7
2y ago

Pillow buffer overflow vulnerability

Pillow buffer overflow vulnerability

▾ Sunlitpillow · pillowEPSS 1.00%via OSV
CVE-2024-30265High· 7.5
2y ago

Voilà Local file inclusion

Voilà Local file inclusion

▾ Twilightvoila · voilaEPSS 0.73%via OSV
CVE-2024-30248High· 7.7
2y ago

Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page

Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page

▾ Twilightpiccolo-admin · piccolo-adminEPSS 0.49%via OSV
CVE-2024-29888Medium· 4.2
2y ago

Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method

Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method

▾ Sunlitsaleor · saleorEPSS 0.53%via OSV
CVE-2024-28233High· 8.1
2y ago

Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing

Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing

▾ Twilightjupyterhub · jupyterhubEPSS 0.33%via OSV
CVE-2024-2206High· 7.3
2y ago

gradio Server-Side Request Forgery vulnerability

gradio Server-Side Request Forgery vulnerability

▾ Twilightgradio · gradioEPSS 0.42%via OSV
CVE-2024-1455Medium· 5.9
2y ago

LangChain's XMLOutputParser vulnerable to XML Entity Expansion

LangChain's XMLOutputParser vulnerable to XML Entity Expansion

▾ Sunlitlangchain-core · langchain-coreEPSS 0.76%via OSV
CVE-2024-29199Low· 3.7
2y ago

Unauthenticated views may expose information to anonymous users

Unauthenticated views may expose information to anonymous users

▾ Sunlitnautobot · nautobotEPSS 0.63%via OSV
CVE-2024-29735Medium· 5.3
2y ago

Apache Airflow Improper Preservation of Permissions vulnerability

Apache Airflow Improper Preservation of Permissions vulnerability

▾ Sunlitapache-airflow · apache-airflowEPSS 1.5%via OSV
CVE-2024-29189High· 7.4
2y ago

ansys-geometry-core OS Command Injection vulnerability

ansys-geometry-core OS Command Injection vulnerability

▾ Twilightansys-geometry-core · ansys-geometry-coreEPSS 0.34%via OSV
CVE-2024-1603High· 7.5
2y ago

PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file

PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file

▾ Twilightpaddlepaddle · paddlepaddleEPSS 0.56%via OSV
CVE-2024-29190High· 7.3
2y ago

SSRF Vulnerability on assetlinks_check(act_name, well_knowns)

SSRF Vulnerability on assetlinks_check(act_name, well_knowns)

▾ Twilightmobsfscan · mobsfscanEPSS 0.72%via OSV
CVE-2024-29019High· 8.1
2y ago

ESPHome vulnerable to Authentication bypass via Cross site request forgery

ESPHome vulnerable to Authentication bypass via Cross site request forgery

▾ Twilightesphome · esphomeEPSS 0.27%via OSV
CVE-2024-29032Medium· 5.3
2y ago

`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code

`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code

▾ Sunlitqiskit-ibm-runtime · qiskit-ibm-runtimeEPSS 0.37%via OSV
CVE-2024-29033High· 7.5
2y ago

GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace

GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace

▾ Twilightoauthenticator · oauthenticatorEPSS 0.59%via OSV
CVE-2024-21503Medium· 5.3
2y ago

Black vulnerable to Regular Expression Denial of Service (ReDoS)

Black vulnerable to Regular Expression Denial of Service (ReDoS)

▾ Sunlitblack · blackEPSS 0.98%via OSV
CVE-2024-28865High· 7.5
2y ago

Denial of service via regular expression

Denial of service via regular expression

▾ Twilightwiki · wikiEPSS 0.61%via OSV
CVE-2024-29156Medium· 6.5
2y ago

Information leakage in YAQL

Information leakage in YAQL

▾ Sunlityaql · yaqlEPSS 0.75%via OSV
CVE-2023-41334High· 8.4
2y ago

RCE in TranformGraph().to_dot_graph function

RCE in TranformGraph().to_dot_graph function

▾ Twilightastropy · astropyEPSS 1.1%via OSV
CVE-2024-22513LowPoC
2y ago

Improper Privilege Management in djangorestframework-simplejwt

Improper Privilege Management in djangorestframework-simplejwt

▾ Twilightdjangorestframework-simplejwt · djangorestframework-simplejwtEPSS 0.80%via OSV
CVE-2024-27351Medium· 5.3
2y ago

Regular expression denial-of-service in Django

Regular expression denial-of-service in Django

▾ Sunlitdjango · djangoEPSS 1.9%via OSV
CVE-2024-24770Medium· 5.3
2y ago

vantage6 vulnerable to a username timing attack on recover password/MFA token

vantage6 vulnerable to a username timing attack on recover password/MFA token

▾ Sunlitvantage6 · vantage6EPSS 0.40%via OSV
CVE-2024-23823Medium· 4.2
2y ago

vantage6's CORS settings overly permissive

vantage6's CORS settings overly permissive

▾ Sunlitvantage6 · vantage6EPSS 0.31%via OSV
CVE-2024-28423Critical· 9.8
2y ago

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vuln…

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.

▾ Midnightairflow-diagrams · airflow-diagramsEPSS 0.78%via OSV
CVE-2024-27097Medium· 4.3
2y ago

Potential log injection in reset user endpoint in CKAN

Potential log injection in reset user endpoint in CKAN

▾ Sunlitckan · ckanEPSS 0.44%via OSV
CVE-2024-26164High· 8.8
2y ago

Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server

Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server

▾ Twilightmssql-django · mssql-djangoEPSS 2.1%via OSV
CVE-2024-52288Medium· 5.1
2y ago

LibOSDP RMAC revert to the beginning of the session

LibOSDP RMAC revert to the beginning of the session

▾ Sunlitlibosdp · libosdpEPSS 0.13%via OSV
CVE-2024-2319Medium· 5.4
2y ago

Django MarkdownX Cross-Site Scripting (XSS) vulnerability

Django MarkdownX Cross-Site Scripting (XSS) vulnerability

▾ Sunlitdjango-markdownx · django-markdownxEPSS 0.39%via OSV
CVEs tagged “pip” — page 113 · VulnSea