VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4667 CVEsRSS

CVE-2024-21671Low· 3.7
2y ago

vantage6 vulnerable to username timing attack

vantage6 vulnerable to username timing attack

▾ Sunlitvantage6-server · vantage6-serverEPSS 0.40%via OSV
CVE-2024-21653Medium· 6.5
2y ago

vantage6 has insecure SSH configuration for node and server containers

vantage6 has insecure SSH configuration for node and server containers

▾ Sunlitvantage6 · vantage6EPSS 0.47%via OSV
CVE-2024-23334Medium· 5.9PoC
2y ago

aiohttp is vulnerable to directory traversal

aiohttp is vulnerable to directory traversal

▾ Twilightaiohttp · aiohttpEPSS 77%via OSV
CVE-2024-0960Medium· 5.0
2y ago

ai-flow Deserialization of Untrusted Data vulnerability

ai-flow Deserialization of Untrusted Data vulnerability

▾ Sunlitai-flow · ai-flowEPSS 0.72%via OSV
CVE-2024-0727Medium· 5.5
2y ago

Null pointer dereference in PKCS12 parsing

Null pointer dereference in PKCS12 parsing

▾ Sunlitcryptography · cryptographyEPSS 3.2%via OSV
CVE-2023-47115High· 7.1PoC
2y ago

Cross-site Scripting Vulnerability on Avatar Upload

Cross-site Scripting Vulnerability on Avatar Upload

▾ Midnightlabel-studio · label-studioEPSS 1.4%via OSV
CVE-2024-23633Medium· 4.7
2y ago

Cross-site Scripting Vulnerability on Data Import

Cross-site Scripting Vulnerability on Data Import

▾ Sunlitlabel-studio · label-studioEPSS 0.59%via OSV
CVE-2024-23345High· 7.1
2y ago

XSS potential in rendered Markdown fields (comments, description, notes, etc.)

XSS potential in rendered Markdown fields (comments, description, notes, etc.)

▾ Twilightnautobot · nautobotEPSS 0.43%via OSV
CVE-2024-23329Low· 3.7
2y ago

changedetection.io API endpoint is not secured with API token

changedetection.io API endpoint is not secured with API token

▾ Sunlitchangedetection-io · changedetection-ioEPSS 0.59%via OSV
CVE-2024-23341Medium· 6.1
2y ago

html injection vulnerability in the `tuitse_html` function.

html injection vulnerability in the `tuitse_html` function.

▾ Sunlittuitse-tsusin · tuitse-tsusinEPSS 0.43%via OSV
CVE-2024-23342High· 7.4
2y ago

Minerva timing attack on P-256 in python-ecdsa

Minerva timing attack on P-256 in python-ecdsa

▾ Twilightecdsa · ecdsaEPSS 0.98%via OSV
CVE-2024-0521Critical· 9.3
2y ago

Code Injection in paddlepaddle

Code Injection in paddlepaddle

▾ Midnightpaddlepaddle · paddlepaddleEPSS 0.46%via OSV
CVE-2024-22416Critical· 9.6PoC
2y ago

Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation

Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation

▾ Abyssalpyload-ng · pyload-ngEPSS 0.95%via OSV
CVE-2023-50447High· 8.1
2y ago

Arbitrary Code Execution in Pillow

Arbitrary Code Execution in Pillow

▾ Twilightpillow · pillowEPSS 1.7%via OSV
CVE-2024-22419High· 7.3
2y ago

concat built-in can corrupt memory in vyper

concat built-in can corrupt memory in vyper

▾ Twilightvyper · vyperEPSS 0.77%via OSV
CVE-2024-22420Medium· 6.5
2y ago

JupyterLab vulnerable to SXSS in Markdown Preview

JupyterLab vulnerable to SXSS in Markdown Preview

▾ Sunlitjupyterlab · jupyterlabEPSS 0.57%via OSV
CVE-2024-22421High· 7.6
2y ago

JupyterLab vulnerable to potential authentication and CSRF tokens leak

JupyterLab vulnerable to potential authentication and CSRF tokens leak

▾ Twilightjupyterlab · jupyterlabEPSS 0.67%via OSV
CVE-2024-0669High· 7.1
2y ago

Cross-Frame Scripting vulnerability has been found on Plone CMS

Cross-Frame Scripting vulnerability has been found on Plone CMS

▾ Twilightplone · ploneEPSS 0.29%via OSV
CVE-2024-22415High· 7.3
2y ago

Unsecured endpoints in the jupyter-lsp server extension

Unsecured endpoints in the jupyter-lsp server extension

▾ Twilightjupyter-lsp · jupyter-lspEPSS 0.49%via OSV
CVE-2023-6395Medium· 6.7
2y ago

Privilege escalation for users that can access mock configuration

Privilege escalation for users that can access mock configuration

▾ Sunlittemplated-dictionary · templated-dictionaryEPSS 1.6%via OSV
CVE-2023-52289High· 7.5
2y ago

Path traversal in flaskcode

Path traversal in flaskcode

▾ Twilightflaskcode · flaskcodeEPSS 0.72%via OSV
CVE-2023-52288High· 7.5
2y ago

Path traversal in flaskcode

Path traversal in flaskcode

▾ Twilightflaskcode · flaskcodeEPSS 0.80%via OSV
CVE-2024-22194Low· 2.2
2y ago

cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code

cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code

▾ Sunlitcdo-local-uuid · cdo-local-uuidEPSS 0.41%via OSV
CVE-2024-22195Medium· 5.4
2y ago

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

▾ Sunlitjinja2 · jinja2EPSS 0.89%via OSV
CVE-2024-22190High· 7.8
2y ago

Untrusted search path under some conditions on Windows allows arbitrary code execution

Untrusted search path under some conditions on Windows allows arbitrary code execution

▾ Twilightgitpython · gitpythonEPSS 0.32%via OSV
CVE-2024-21669Critical· 9.9
2y ago

Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC

Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC

▾ Midnightaries-cloudagent · aries-cloudagentEPSS 0.63%via OSV
CVE-2023-45139High· 7.5
2y ago

fonttools XML External Entity Injection (XXE) Vulnerability

fonttools XML External Entity Injection (XXE) Vulnerability

▾ Twilightfonttools · fonttoolsEPSS 1.2%via OSV
CVE-2024-21644High· 7.5PoC
2y ago

pyload Unauthenticated Flask Configuration Leakage vulnerability

pyload Unauthenticated Flask Configuration Leakage vulnerability

▾ Midnightpyload-ng · pyload-ngEPSS 42%via OSV
CVE-2024-21645Medium· 5.3PoC
2y ago

pyload Log Injection vulnerability

pyload Log Injection vulnerability

▾ Twilightpyload-ng · pyload-ngEPSS 25%via OSV
CVE-2023-52323Medium· 5.3
2y ago

PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption

PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption

▾ Sunlitpycryptodomex · pycryptodomexEPSS 0.62%via OSV
CVEs tagged “pip” — page 116 · VulnSea