Tagged “pip”
CVEs tagged pip, newest first.
4667 CVEsRSS
CVE-2024-21671Low· 3.7vantage6 vulnerable to username timing attack
vantage6 vulnerable to username timing attack
CVE-2024-21653Medium· 6.5vantage6 has insecure SSH configuration for node and server containers
vantage6 has insecure SSH configuration for node and server containers
CVE-2024-23334Medium· 5.9PoCaiohttp is vulnerable to directory traversal
aiohttp is vulnerable to directory traversal
CVE-2024-0960Medium· 5.0ai-flow Deserialization of Untrusted Data vulnerability
ai-flow Deserialization of Untrusted Data vulnerability
CVE-2024-0727Medium· 5.5Null pointer dereference in PKCS12 parsing
Null pointer dereference in PKCS12 parsing
CVE-2023-47115High· 7.1PoCCross-site Scripting Vulnerability on Avatar Upload
Cross-site Scripting Vulnerability on Avatar Upload
CVE-2024-23633Medium· 4.7Cross-site Scripting Vulnerability on Data Import
Cross-site Scripting Vulnerability on Data Import
CVE-2024-23345High· 7.1XSS potential in rendered Markdown fields (comments, description, notes, etc.)
XSS potential in rendered Markdown fields (comments, description, notes, etc.)
CVE-2024-23329Low· 3.7changedetection.io API endpoint is not secured with API token
changedetection.io API endpoint is not secured with API token
CVE-2024-23341Medium· 6.1html injection vulnerability in the `tuitse_html` function.
html injection vulnerability in the `tuitse_html` function.
CVE-2024-23342High· 7.4Minerva timing attack on P-256 in python-ecdsa
Minerva timing attack on P-256 in python-ecdsa
CVE-2024-0521Critical· 9.3Code Injection in paddlepaddle
Code Injection in paddlepaddle
CVE-2024-22416Critical· 9.6PoCCross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
CVE-2023-50447High· 8.1Arbitrary Code Execution in Pillow
Arbitrary Code Execution in Pillow
CVE-2024-22419High· 7.3concat built-in can corrupt memory in vyper
concat built-in can corrupt memory in vyper
CVE-2024-22420Medium· 6.5JupyterLab vulnerable to SXSS in Markdown Preview
JupyterLab vulnerable to SXSS in Markdown Preview
CVE-2024-22421High· 7.6JupyterLab vulnerable to potential authentication and CSRF tokens leak
JupyterLab vulnerable to potential authentication and CSRF tokens leak
CVE-2024-0669High· 7.1Cross-Frame Scripting vulnerability has been found on Plone CMS
Cross-Frame Scripting vulnerability has been found on Plone CMS
CVE-2024-22415High· 7.3Unsecured endpoints in the jupyter-lsp server extension
Unsecured endpoints in the jupyter-lsp server extension
CVE-2023-6395Medium· 6.7Privilege escalation for users that can access mock configuration
Privilege escalation for users that can access mock configuration
CVE-2023-52289High· 7.5Path traversal in flaskcode
Path traversal in flaskcode
CVE-2023-52288High· 7.5Path traversal in flaskcode
Path traversal in flaskcode
CVE-2024-22194Low· 2.2cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code
cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code
CVE-2024-22195Medium· 5.4Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
CVE-2024-22190High· 7.8Untrusted search path under some conditions on Windows allows arbitrary code execution
Untrusted search path under some conditions on Windows allows arbitrary code execution
CVE-2024-21669Critical· 9.9Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
CVE-2023-45139High· 7.5fonttools XML External Entity Injection (XXE) Vulnerability
fonttools XML External Entity Injection (XXE) Vulnerability
CVE-2024-21644High· 7.5PoCpyload Unauthenticated Flask Configuration Leakage vulnerability
pyload Unauthenticated Flask Configuration Leakage vulnerability
CVE-2024-21645Medium· 5.3PoCpyload Log Injection vulnerability
pyload Log Injection vulnerability
CVE-2023-52323Medium· 5.3PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption