VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4666 CVEsRSS

CVE-2023-48224High· 8.2
2y ago

Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity Verification

Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity Verification

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.99%via OSV
CVE-2023-6022High· 8.8
2y ago

Cross-Site Request Forgery vulnerability in Prefect

Cross-Site Request Forgery vulnerability in Prefect

▾ Twilightprefect · prefectEPSS 0.39%via OSV
CVE-2023-5189Medium· 6.3
2y ago

Ansible galaxy-importer Path Traversal vulnerability

Ansible galaxy-importer Path Traversal vulnerability

▾ Sunlitgalaxy-importer · galaxy-importerEPSS 0.98%via OSV
CVE-2023-46121Medium· 5.0
2y ago

yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection

yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection

▾ Sunlityt-dlp · yt-dlpEPSS 0.32%via OSV
CVE-2023-47631High· 7.2
2y ago

vantage6-server node accepts non-whitelisted algorithms from malicious server

vantage6-server node accepts non-whitelisted algorithms from malicious server

▾ Twilightvantage6-server · vantage6-serverEPSS 0.45%via OSV
CVE-2023-47627Medium· 5.3
2y ago

AIOHTTP has problems in HTTP parser (the python one, not llhttp)

AIOHTTP has problems in HTTP parser (the python one, not llhttp)

▾ Sunlitaiohttp · aiohttpEPSS 0.86%via OSV
CVE-2023-47117High· 7.5PoC
2y ago

Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task

Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task

▾ Midnightlabel-studio · label-studioEPSS 4.1%via OSV
CVE-2023-47248Critical· 9.8PoC
2y ago

PyArrow: Arbitrary code execution when loading a malicious data file

PyArrow: Arbitrary code execution when loading a malicious data file

▾ Abyssalpyarrow · pyarrowEPSS 15%via OSV
CVE-2023-46445Medium· 5.3
2y ago

AsyncSSH Rogue Extension Negotiation

AsyncSSH Rogue Extension Negotiation

▾ Sunlitasyncssh · asyncsshEPSS 0.59%via OSV
CVE-2023-46446High· 8.1
2y ago

AsyncSSH Rogue Session Attack

AsyncSSH Rogue Session Attack

▾ Twilightasyncssh · asyncsshEPSS 0.87%via OSV
CVE-2023-47114Medium· 4.3
2y ago

Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages

Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.61%via OSV
CVE-2023-43796Medium· 5.3
2y ago

Synapse vulnerable to leak of remote user device information

Synapse vulnerable to leak of remote user device information

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.90%via OSV
CVE-2023-46250Medium· 5.1
2y ago

Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF

Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF

▾ Sunlitpypdf · pypdfEPSS 0.24%via OSV
CVE-2023-46215High· 7.5
2y ago

Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability

Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability

▾ Twilightapache-airflow-providers-celery · apache-airflow-providers-celeryEPSS 1.2%via OSV
CVE-2023-41893Medium· 4.3
2y ago

Home Assistant vulnerable to account takeover via auth_callback login

Home Assistant vulnerable to account takeover via auth_callback login

▾ Sunlithomeassistant · homeassistantEPSS 0.40%via OSV
CVE-2023-5752Medium· 5.5
2y ago

Command Injection in pip when used with Mercurial

Command Injection in pip when used with Mercurial

▾ Sunlitpip · pipEPSS 0.48%via OSV
CVE-2023-46136Medium· 5.7PoC
2y ago

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

▾ Twilightwerkzeug · werkzeugEPSS 1.1%via OSV
CVE-2023-46134Medium· 6.1
2y ago

dtale vulnerable to Remote Code Execution through the Custom Filter Input

dtale vulnerable to Remote Code Execution through the Custom Filter Input

▾ Sunlitdtale · dtaleEPSS 0.76%via OSV
CVE-2023-46128High· 7.7
2y ago

Nautobot vulnerable to exposure of hashed user passwords via REST API

Nautobot vulnerable to exposure of hashed user passwords via REST API

▾ Twilightnautobot · nautobotEPSS 0.53%via OSV
CVE-2023-46125Medium· 6.5
2y ago

Fides Information Disclosure Vulnerability in Config API Endpoint

Fides Information Disclosure Vulnerability in Config API Endpoint

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.73%via OSV
CVE-2023-46124High· 8.2
2y ago

Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload

Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.68%via OSV
CVE-2023-46126Low· 3.9
2y ago

Fides JavaScript Injection Vulnerability in Privacy Center URL

Fides JavaScript Injection Vulnerability in Privacy Center URL

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.61%via OSV
CVE-2023-32786High· 7.5
2y ago

Langchain Server-Side Request Forgery vulnerability

Langchain Server-Side Request Forgery vulnerability

▾ Twilightlangchain · langchainEPSS 0.70%via OSV
CVE-2023-44690Medium
2y ago

mycli has Inadequate Encryption Strength

mycli has Inadequate Encryption Strength

▾ Sunlitmycli · mycliEPSS 0.22%via OSV
CVE-2023-45805High· 7.8
2y ago

PDM Trojan Lockfile

PDM Trojan Lockfile

▾ Twilightpdm · pdmEPSS 0.51%via OSV
CVE-2023-45813Medium· 4.6
2y ago

TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link

TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link

▾ Sunlittorbot · torbotEPSS 0.80%via OSV
CVE-2023-45803Medium· 4.2
2y ago

urllib3's request body not stripped after redirect from 303 status changes request method to GET

urllib3's request body not stripped after redirect from 303 status changes request method to GET

▾ Sunliturllib3 · urllib3EPSS 0.54%via OSV
CVE-2023-41881Low· 3.7
2y ago

vantage6 does not properly delete linked resources when deleting a collaboration

vantage6 does not properly delete linked resources when deleting a collaboration

▾ Sunlitvantage6 · vantage6EPSS 0.32%via OSV
CVE-2023-45853Critical· 9.8⚖ disputed
2y ago

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pymini…

▾ Midnightzlib · zlibEPSS 3.2%via NVD
CVE-2023-23930High· 7.2
2y ago

Pickle serialization vulnerable to Deserialization of Untrusted Data

Pickle serialization vulnerable to Deserialization of Untrusted Data

▾ Twilightvantage6 · vantage6EPSS 0.89%via OSV
CVEs tagged “pip” — page 119 · VulnSea