Tagged “pip”
CVEs tagged pip, newest first.
4666 CVEsRSS
CVE-2023-46247High· 7.5incorrect storage layout for contracts containing large arrays
incorrect storage layout for contracts containing large arrays
CVE-2023-5764Medium· 6.6Ansible template injection vulnerability
Ansible template injection vulnerability
CVE-2023-50248Medium· 4.5Out of memory error when submitting the dataset form with a specially-crafted field
Out of memory error when submitting the dataset form with a specially-crafted field
CVE-2023-50423Critical· 9.1Improper Privilege Management in sap-xssec
Improper Privilege Management in sap-xssec
CVE-2023-49795Medium· 6.5Server-Side Request Forgery in mindsdb
Server-Side Request Forgery in mindsdb
CVE-2023-35625Medium· 4.7Exposure of Sensitive Information in mltable
Exposure of Sensitive Information in mltable
CVE-2023-48311Medium· 4.3DockerSpawner allows any image by default
DockerSpawner allows any image by default
CVE-2023-49297Low· 3.3PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution
PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution
CVE-2023-49080Medium· 4.3jupyter-server errors include tracebacks with path information
jupyter-server errors include tracebacks with path information
CVE-2023-43472High· 7.5PoCInformation exposure in MLflow
Information exposure in MLflow
CVE-2023-49277Medium· 6.1Reflected XSS Vulnerability in dpaste
Reflected XSS Vulnerability in dpaste
CVE-2023-49081High· 7.2aiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker co…
CVE-2023-49082Medium· 5.3aiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker…
CVE-2023-49083Medium· 5.9cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
CVE-2023-48022Critical· 9.8PoCRay has arbitrary code execution via jobs submission API
Ray has arbitrary code execution via jobs submission API
CVE-2023-42502Medium· 5.4Apache Superset Open Redirect vulnerability
Apache Superset Open Redirect vulnerability
CVE-2023-42505Medium· 4.3Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-40610High· 7.3Apache Superset - Elevation of Privilege
Apache Superset - Elevation of Privilege
CVE-2023-42504Medium· 6.5Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
GHSA-pjjw-qhg8-p2p9Mediumaiohttp has vulnerable dependency that is vulnerable to request smuggling
aiohttp has vulnerable dependency that is vulnerable to request smuggling
CVE-2023-43701Medium· 4.3Apache Superset Cross-site Scripting vulnerability
Apache Superset Cross-site Scripting vulnerability
CVE-2023-42501Medium· 4.3Apache Superset has Incorrect Default Permissions
Apache Superset has Incorrect Default Permissions
CVE-2023-48699High· 8.4Eval Injection in fastbots
Eval Injection in fastbots
CVE-2023-48700Medium· 5.7Clear Text Credentials Exposed via Onboarding Task
Clear Text Credentials Exposed via Onboarding Task
CVE-2023-48299Medium· 5.3TorchServe ZipSlip
TorchServe ZipSlip
CVE-2023-47890High· 7.6Download to arbitrary folder can lead to RCE
Download to arbitrary folder can lead to RCE
CVE-2023-6019Critical· 9.8PoCRay OS Command Injection vulnerability
Ray OS Command Injection vulnerability
CVE-2023-48052High· 7.4HTTPie allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack
HTTPie allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack
CVE-2023-6020Critical· 9.3PoCRay Missing Authorization vulnerability
Ray Missing Authorization vulnerability
CVE-2023-6021Critical· 9.3PoCRay Path Traversal vulnerability
Ray Path Traversal vulnerability