Tagged “pip”
CVEs tagged pip, newest first.
4662 CVEsRSS
CVE-2024-26151High· 8.2Potentially untrusted input is rendered as HTML in final output
Potentially untrusted input is rendered as HTML in final output
CVE-2024-26130High· 7.5cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private …
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
CVE-2024-3572High· 7.5Scrapy decompression bomb vulnerability
Scrapy decompression bomb vulnerability
CVE-2024-3574High· 7.5Scrapy authorization header leakage on cross-domain redirect
Scrapy authorization header leakage on cross-domain redirect
CVE-2024-24762High· 7.5python-multipart vulnerable to Content-Type Header ReDoS
python-multipart vulnerable to Content-Type Header ReDoS
CVE-2024-21624Medium· 5.7NoneBot Potential Information Leak in User-Constructed Message Templates
NoneBot Potential Information Leak in User-Constructed Message Templates
CVE-2024-24825Critical· 9.1DIRAC's TokenManager does not check permissions on cached tokens
DIRAC's TokenManager does not check permissions on cached tokens
CVE-2024-1314High· 8.6Kinto Attachment's attachments can be replaced on read-only records
Kinto Attachment's attachments can be replaced on read-only records
CVE-2024-24811Critical· 9.8SQLAlchemyDA unauthenticated arbitrary SQL query execution
SQLAlchemyDA unauthenticated arbitrary SQL query execution
CVE-2024-24563Critical· 9.8Vyper negative array index bounds checks
Vyper negative array index bounds checks
CVE-2024-24591High· 8.8Allegro AI ClearML path traversal vulnerability
Allegro AI ClearML path traversal vulnerability
CVE-2024-24595Medium· 6.0Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance
Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance
CVE-2024-24590High· 8.8PoCAllegro AI ClearML vulnerable to deserialization of untrusted data
Allegro AI ClearML vulnerable to deserialization of untrusted data
CVE-2024-24559Low· 3.7Vyper sha3 codegen bug
Vyper sha3 codegen bug
CVE-2024-24808Medium· 6.1pyLoad open redirect vulnerability due to improper validation of the is_safe_url function
pyLoad open redirect vulnerability due to improper validation of the is_safe_url function
CVE-2023-50781High· 7.5A flaw was found in m2crypto
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
CVE-2023-50782High· 7.5Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
CVE-2024-24560Low· 3.7Vyper's external calls can overflow return data to return input buffer
Vyper's external calls can overflow return data to return input buffer
CVE-2024-24561Critical· 9.8Vyper's bounds check on built-in `slice()` function can be overflowed
Vyper's bounds check on built-in `slice()` function can be overflowed
CVE-2024-1141Medium· 5.5glance-store logs s3 access keys
glance-store logs s3 access keys
CVE-2023-47116Medium· 5.3Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
CVE-2024-23637Medium· 4.2OctoPrint Unverified Password Change via Access Control Settings
OctoPrint Unverified Password Change via Access Control Settings
CVE-2024-24567Medium· 4.8Vyper's raw_call `value=` kwargs not disabled for static and delegate calls
Vyper's raw_call `value=` kwargs not disabled for static and delegate calls
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability
vantage6 remote code execution vulnerability
CVE-2024-22193Low· 3.5vantage6 may create unencrypted tasks in encrypted collaboration
vantage6 may create unencrypted tasks in encrypted collaboration
CVE-2024-21671Low· 3.7vantage6 vulnerable to username timing attack
vantage6 vulnerable to username timing attack
CVE-2024-21653Medium· 6.5vantage6 has insecure SSH configuration for node and server containers
vantage6 has insecure SSH configuration for node and server containers
CVE-2024-23334Medium· 5.9PoCaiohttp is vulnerable to directory traversal
aiohttp is vulnerable to directory traversal
CVE-2024-0960Medium· 5.0ai-flow Deserialization of Untrusted Data vulnerability
ai-flow Deserialization of Untrusted Data vulnerability
CVE-2024-0727Medium· 5.5Null pointer dereference in PKCS12 parsing
Null pointer dereference in PKCS12 parsing