VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4662 CVEsRSS

CVE-2024-26151High· 8.2
2y ago

Potentially untrusted input is rendered as HTML in final output

Potentially untrusted input is rendered as HTML in final output

▾ Twilightmjml · mjmlEPSS 0.62%via OSV
CVE-2024-26130High· 7.5
2y ago

cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private …

cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override

▾ Twilightcryptography · cryptographyEPSS 0.83%via OSV
CVE-2024-3572High· 7.5
2y ago

Scrapy decompression bomb vulnerability

Scrapy decompression bomb vulnerability

▾ Twilightscrapy · scrapyEPSS 0.81%via OSV
CVE-2024-3574High· 7.5
2y ago

Scrapy authorization header leakage on cross-domain redirect

Scrapy authorization header leakage on cross-domain redirect

▾ Twilightscrapy · scrapyEPSS 0.65%via OSV
CVE-2024-24762High· 7.5
2y ago

python-multipart vulnerable to Content-Type Header ReDoS

python-multipart vulnerable to Content-Type Header ReDoS

▾ Twilightpython-multipart · python-multipartEPSS 1.5%via OSV
CVE-2024-21624Medium· 5.7
2y ago

NoneBot Potential Information Leak in User-Constructed Message Templates

NoneBot Potential Information Leak in User-Constructed Message Templates

▾ Sunlitnonebot2 · nonebot2EPSS 0.49%via OSV
CVE-2024-24825Critical· 9.1
2y ago

DIRAC's TokenManager does not check permissions on cached tokens

DIRAC's TokenManager does not check permissions on cached tokens

▾ Midnightdirac · diracEPSS 0.53%via OSV
CVE-2024-1314High· 8.6
2y ago

Kinto Attachment's attachments can be replaced on read-only records

Kinto Attachment's attachments can be replaced on read-only records

▾ Twilightkinto-attachment · kinto-attachmentvia OSV
CVE-2024-24811Critical· 9.8
2y ago

SQLAlchemyDA unauthenticated arbitrary SQL query execution

SQLAlchemyDA unauthenticated arbitrary SQL query execution

▾ Midnightproducts-sqlalchemyda · products-sqlalchemydaEPSS 0.89%via OSV
CVE-2024-24563Critical· 9.8
2y ago

Vyper negative array index bounds checks

Vyper negative array index bounds checks

▾ Midnightvyper · vyperEPSS 1.5%via OSV
CVE-2024-24591High· 8.8
2y ago

Allegro AI ClearML path traversal vulnerability

Allegro AI ClearML path traversal vulnerability

▾ Twilightclearml · clearmlEPSS 0.80%via OSV
CVE-2024-24595Medium· 6.0
2y ago

Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance

Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance

▾ Sunlitclearml · clearmlEPSS 0.26%via OSV
CVE-2024-24590High· 8.8PoC
2y ago

Allegro AI ClearML vulnerable to deserialization of untrusted data

Allegro AI ClearML vulnerable to deserialization of untrusted data

▾ Midnightclearml · clearmlEPSS 2.5%via OSV
CVE-2024-24559Low· 3.7
2y ago

Vyper sha3 codegen bug

Vyper sha3 codegen bug

▾ Sunlitvyper · vyperEPSS 0.26%via OSV
CVE-2024-24808Medium· 6.1
2y ago

pyLoad open redirect vulnerability due to improper validation of the is_safe_url function

pyLoad open redirect vulnerability due to improper validation of the is_safe_url function

▾ Sunlitpyload-ng · pyload-ngEPSS 0.55%via OSV
CVE-2023-50781High· 7.5
2y ago

A flaw was found in m2crypto

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

▾ Twilightredhat · update_infrastructureEPSS 1.1%via NVD
CVE-2023-50782High· 7.5
2y ago

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

▾ Twilightcryptography · cryptographyEPSS 1.1%via OSV
CVE-2024-24560Low· 3.7
2y ago

Vyper's external calls can overflow return data to return input buffer

Vyper's external calls can overflow return data to return input buffer

▾ Sunlitvyper · vyperEPSS 0.53%via OSV
CVE-2024-24561Critical· 9.8
2y ago

Vyper's bounds check on built-in `slice()` function can be overflowed

Vyper's bounds check on built-in `slice()` function can be overflowed

▾ Midnightvyper · vyperEPSS 0.90%via OSV
CVE-2024-1141Medium· 5.5
2y ago

glance-store logs s3 access keys

glance-store logs s3 access keys

▾ Sunlitglance-store · glance-storeEPSS 0.23%via OSV
CVE-2023-47116Medium· 5.3
2y ago

Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections

Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections

▾ Sunlitlabel-studio · label-studioEPSS 0.74%via OSV
CVE-2024-23637Medium· 4.2
2y ago

OctoPrint Unverified Password Change via Access Control Settings

OctoPrint Unverified Password Change via Access Control Settings

▾ Sunlitoctoprint · octoprintEPSS 0.52%via OSV
CVE-2024-24567Medium· 4.8
2y ago

Vyper's raw_call `value=` kwargs not disabled for static and delegate calls

Vyper's raw_call `value=` kwargs not disabled for static and delegate calls

▾ Sunlitvyper · vyperEPSS 0.48%via OSV
CVE-2024-21649High· 8.8
2y ago

vantage6 remote code execution vulnerability

vantage6 remote code execution vulnerability

▾ Twilightvantage6 · vantage6EPSS 1.3%via OSV
CVE-2024-22193Low· 3.5
2y ago

vantage6 may create unencrypted tasks in encrypted collaboration

vantage6 may create unencrypted tasks in encrypted collaboration

▾ Sunlitvantage6 · vantage6EPSS 0.26%via OSV
CVE-2024-21671Low· 3.7
2y ago

vantage6 vulnerable to username timing attack

vantage6 vulnerable to username timing attack

▾ Sunlitvantage6-server · vantage6-serverEPSS 0.40%via OSV
CVE-2024-21653Medium· 6.5
2y ago

vantage6 has insecure SSH configuration for node and server containers

vantage6 has insecure SSH configuration for node and server containers

▾ Sunlitvantage6 · vantage6EPSS 0.47%via OSV
CVE-2024-23334Medium· 5.9PoC
2y ago

aiohttp is vulnerable to directory traversal

aiohttp is vulnerable to directory traversal

▾ Twilightaiohttp · aiohttpEPSS 77%via OSV
CVE-2024-0960Medium· 5.0
2y ago

ai-flow Deserialization of Untrusted Data vulnerability

ai-flow Deserialization of Untrusted Data vulnerability

▾ Sunlitai-flow · ai-flowEPSS 0.72%via OSV
CVE-2024-0727Medium· 5.5
2y ago

Null pointer dereference in PKCS12 parsing

Null pointer dereference in PKCS12 parsing

▾ Sunlitcryptography · cryptographyEPSS 3.2%via OSV
CVEs tagged “pip” — page 115 · VulnSea