VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4666 CVEsRSS

CVE-2023-46247High· 7.5
2y ago

incorrect storage layout for contracts containing large arrays

incorrect storage layout for contracts containing large arrays

▾ Twilightvyper · vyperEPSS 0.70%via OSV
CVE-2023-5764Medium· 6.6
2y ago

Ansible template injection vulnerability

Ansible template injection vulnerability

▾ Sunlitansible-core · ansible-coreEPSS 0.54%via OSV
CVE-2023-50248Medium· 4.5
2y ago

Out of memory error when submitting the dataset form with a specially-crafted field

Out of memory error when submitting the dataset form with a specially-crafted field

▾ Sunlitckan · ckanEPSS 0.58%via OSV
CVE-2023-50423Critical· 9.1
2y ago

Improper Privilege Management in sap-xssec

Improper Privilege Management in sap-xssec

▾ Midnightsap-xssec · sap-xssecEPSS 1.1%via OSV
CVE-2023-49795Medium· 6.5
2y ago

Server-Side Request Forgery in mindsdb

Server-Side Request Forgery in mindsdb

▾ Sunlitmindsdb · mindsdbEPSS 0.42%via OSV
CVE-2023-35625Medium· 4.7
2y ago

Exposure of Sensitive Information in mltable

Exposure of Sensitive Information in mltable

▾ Sunlitmltable · mltableEPSS 0.71%via OSV
CVE-2023-48311Medium· 4.3
2y ago

DockerSpawner allows any image by default

DockerSpawner allows any image by default

▾ Sunlitdockerspawner · dockerspawnerEPSS 0.64%via OSV
CVE-2023-49297Low· 3.3
2y ago

PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution

PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution

▾ Sunlitpydrive2 · pydrive2EPSS 0.51%via OSV
CVE-2023-49080Medium· 4.3
2y ago

jupyter-server errors include tracebacks with path information

jupyter-server errors include tracebacks with path information

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.84%via OSV
CVE-2023-43472High· 7.5PoC
2y ago

Information exposure in MLflow

Information exposure in MLflow

▾ Midnightmlflow · mlflowEPSS 37%via OSV
CVE-2023-49277Medium· 6.1
2y ago

Reflected XSS Vulnerability in dpaste

Reflected XSS Vulnerability in dpaste

▾ Sunlitdpaste · dpasteEPSS 0.52%via OSV
CVE-2023-49081High· 7.2
2y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker co…

▾ Twilightaiohttp · aiohttpEPSS 0.88%via NVD
CVE-2023-49082Medium· 5.3
2y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker…

▾ Sunlitaiohttp · aiohttpEPSS 0.95%via NVD
CVE-2023-49083Medium· 5.9
2y ago

cryptography vulnerable to NULL-dereference when loading PKCS7 certificates

cryptography vulnerable to NULL-dereference when loading PKCS7 certificates

▾ Sunlitcryptography · cryptographyEPSS 0.98%via OSV
CVE-2023-48022Critical· 9.8PoC
2y ago

Ray has arbitrary code execution via jobs submission API

Ray has arbitrary code execution via jobs submission API

▾ Abyssalray · rayEPSS 84%via OSV
CVE-2023-42502Medium· 5.4
2y ago

Apache Superset Open Redirect vulnerability

Apache Superset Open Redirect vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 0.83%via OSV
CVE-2023-42505Medium· 4.3
2y ago

Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2023-40610High· 7.3
2y ago

Apache Superset - Elevation of Privilege

Apache Superset - Elevation of Privilege

▾ Twilightapache-superset · apache-supersetEPSS 1.3%via OSV
CVE-2023-42504Medium· 6.5
2y ago

Apache Superset Allocation of Resources Without Limits or Throttling vulnerability

Apache Superset Allocation of Resources Without Limits or Throttling vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
GHSA-pjjw-qhg8-p2p9Medium
2y ago

aiohttp has vulnerable dependency that is vulnerable to request smuggling

aiohttp has vulnerable dependency that is vulnerable to request smuggling

▾ Sunlitaiohttp · aiohttpvia OSV
CVE-2023-43701Medium· 4.3
2y ago

Apache Superset Cross-site Scripting vulnerability

Apache Superset Cross-site Scripting vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2023-42501Medium· 4.3
2y ago

Apache Superset has Incorrect Default Permissions

Apache Superset has Incorrect Default Permissions

▾ Sunlitapache-superset · apache-supersetEPSS 0.86%via OSV
CVE-2023-48699High· 8.4
2y ago

Eval Injection in fastbots

Eval Injection in fastbots

▾ Twilightfastbots · fastbotsEPSS 0.74%via OSV
CVE-2023-48700Medium· 5.7
2y ago

Clear Text Credentials Exposed via Onboarding Task

Clear Text Credentials Exposed via Onboarding Task

▾ Sunlitnautobot-device-onboarding · nautobot-device-onboardingEPSS 0.41%via OSV
CVE-2023-48299Medium· 5.3
2y ago

TorchServe ZipSlip

TorchServe ZipSlip

▾ Sunlittorchserve · torchserveEPSS 0.68%via OSV
CVE-2023-47890High· 7.6
2y ago

Download to arbitrary folder can lead to RCE

Download to arbitrary folder can lead to RCE

▾ Twilightpyload-ng · pyload-ngEPSS 1.1%via OSV
CVE-2023-6019Critical· 9.8PoC
2y ago

Ray OS Command Injection vulnerability

Ray OS Command Injection vulnerability

▾ Abyssalray · rayEPSS 75%via OSV
CVE-2023-48052High· 7.4
2y ago

HTTPie allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack

HTTPie allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack

▾ Twilighthttpie · httpieEPSS 0.31%via OSV
CVE-2023-6020Critical· 9.3PoC
2y ago

Ray Missing Authorization vulnerability

Ray Missing Authorization vulnerability

▾ Abyssalray · rayEPSS 15%via OSV
CVE-2023-6021Critical· 9.3PoC
2y ago

Ray Path Traversal vulnerability

Ray Path Traversal vulnerability

▾ Abyssalray · rayEPSS 37%via OSV
CVEs tagged “pip” — page 118 · VulnSea