Tagged “pip”
CVEs tagged pip, newest first.
4662 CVEsRSS
CVE-2024-52296Medium· 6.5LibOSDP vulnerable to a null pointer deref in osdp_reply_name
LibOSDP vulnerable to a null pointer deref in osdp_reply_name
CVE-2024-28184High· 7.4WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
CVE-2024-0917Critical· 9.8PaddlePaddle vulnerable to remote code execution
PaddlePaddle vulnerable to remote code execution
CVE-2024-0818Critical· 9.1PaddlePaddle Path Traversal vulnerability
PaddlePaddle Path Traversal vulnerability
CVE-2024-0815High· 8.8PaddlePaddle command injection in paddle.utils.download._wget_download
PaddlePaddle command injection in paddle.utils.download._wget_download
CVE-2024-0817High· 7.8PaddlePaddle command injection vulnerability
PaddlePaddle command injection vulnerability
CVE-2024-22889Medium· 5.5PoCPhone information disclosure vulnerability
Phone information disclosure vulnerability
CVE-2024-28102Medium· 6.8JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
CVE-2024-27758High· 8.5RPyC's missing security check results in code execution when using numpy.array on the server-side.
RPyC's missing security check results in code execution when using numpy.array on the server-side.
CVE-2024-27287Medium· 6.5esphome vulnerable to stored Cross-site Scripting in edit configuration file API
esphome vulnerable to stored Cross-site Scripting in edit configuration file API
GHSA-3qwc-47jf-5rf7Mediumeth-abi is vulnerable to recursive DoS
eth-abi is vulnerable to recursive DoS
CVE-2024-27081High· 7.2ESPHome vulnerable to remote code execution via arbitrary file write
ESPHome vulnerable to remote code execution via arbitrary file write
CVE-2024-27290Medium· 6.1Docassemble HTML and javascript injection
Docassemble HTML and javascript injection
CVE-2024-27292High· 7.5PoCDocassemble unauthorized access through URL manipulation
Docassemble unauthorized access through URL manipulation
CVE-2024-27291Medium· 6.1Docassemble open redirect
Docassemble open redirect
CVE-2024-25128Critical· 9.1Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID
Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID
CVE-2024-24779Medium· 5.0Apache Superset: Improper data authorization when creating a new dataset
Apache Superset: Improper data authorization when creating a new dataset
CVE-2024-25169MediumPoCMezzanine allows attackers to bypass access control mechanisms
Mezzanine allows attackers to bypass access control mechanisms
CVE-2024-24772Medium· 4.3Apache Superset: Improper Neutralization of custom SQL on embedded context
Apache Superset: Improper Neutralization of custom SQL on embedded context
CVE-2024-27315Medium· 4.3Apache Superset: Improper error handling on alerts
Apache Superset: Improper error handling on alerts
CVE-2024-27083Medium· 4.3Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)
Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)
CVE-2024-24773Medium· 4.9Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
CVE-2024-26016Medium· 4.3Apache Superset: Improper authorization validation on dashboards and charts import
Apache Superset: Improper authorization validation on dashboards and charts import
CVE-2024-25170MediumPoCMezzanine allows attackers to bypass access controls via manipulating the Host header
Mezzanine allows attackers to bypass access controls via manipulating the Host header
CVE-2024-25723Medium· 6.5PoCZenML Server Remote Privilege Escalation Vulnerability
ZenML Server Remote Privilege Escalation Vulnerability
CVE-2024-27454High· 7.5orjson does not limit recursion for deeply nested JSON documents
orjson does not limit recursion for deeply nested JSON documents
CVE-2024-0243Low· 3.7langchain Server-Side Request Forgery vulnerability
langchain Server-Side Request Forgery vulnerability
CVE-2024-27318High· 7.5Onnx Directory Traversal vulnerability
Onnx Directory Traversal vulnerability
CVE-2024-27319Medium· 4.4Onnx Out-of-bounds Read vulnerability
Onnx Out-of-bounds Read vulnerability
CVE-2024-1729Medium· 5.9Gradio apps vulnerable to timing attacks to guess password
Gradio apps vulnerable to timing attacks to guess password