Tagged “pip”
CVEs tagged pip, newest first.
4666 CVEsRSS
CVE-2023-48224High· 8.2Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity Verification
Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity Verification
CVE-2023-6022High· 8.8Cross-Site Request Forgery vulnerability in Prefect
Cross-Site Request Forgery vulnerability in Prefect
CVE-2023-5189Medium· 6.3Ansible galaxy-importer Path Traversal vulnerability
Ansible galaxy-importer Path Traversal vulnerability
CVE-2023-46121Medium· 5.0yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection
yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection
CVE-2023-47631High· 7.2vantage6-server node accepts non-whitelisted algorithms from malicious server
vantage6-server node accepts non-whitelisted algorithms from malicious server
CVE-2023-47627Medium· 5.3AIOHTTP has problems in HTTP parser (the python one, not llhttp)
AIOHTTP has problems in HTTP parser (the python one, not llhttp)
CVE-2023-47117High· 7.5PoCLabel Studio Object Relational Mapper Leak Vulnerability in Filtering Task
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
CVE-2023-47248Critical· 9.8PoCPyArrow: Arbitrary code execution when loading a malicious data file
PyArrow: Arbitrary code execution when loading a malicious data file
CVE-2023-46445Medium· 5.3AsyncSSH Rogue Extension Negotiation
AsyncSSH Rogue Extension Negotiation
CVE-2023-46446High· 8.1AsyncSSH Rogue Session Attack
AsyncSSH Rogue Session Attack
CVE-2023-47114Medium· 4.3Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages
Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages
CVE-2023-43796Medium· 5.3Synapse vulnerable to leak of remote user device information
Synapse vulnerable to leak of remote user device information
CVE-2023-46250Medium· 5.1Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF
Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF
CVE-2023-46215High· 7.5Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
CVE-2023-41893Medium· 4.3Home Assistant vulnerable to account takeover via auth_callback login
Home Assistant vulnerable to account takeover via auth_callback login
CVE-2023-5752Medium· 5.5Command Injection in pip when used with Mercurial
Command Injection in pip when used with Mercurial
CVE-2023-46136Medium· 5.7PoCWerkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
CVE-2023-46134Medium· 6.1dtale vulnerable to Remote Code Execution through the Custom Filter Input
dtale vulnerable to Remote Code Execution through the Custom Filter Input
CVE-2023-46128High· 7.7Nautobot vulnerable to exposure of hashed user passwords via REST API
Nautobot vulnerable to exposure of hashed user passwords via REST API
CVE-2023-46125Medium· 6.5Fides Information Disclosure Vulnerability in Config API Endpoint
Fides Information Disclosure Vulnerability in Config API Endpoint
CVE-2023-46124High· 8.2Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
CVE-2023-46126Low· 3.9Fides JavaScript Injection Vulnerability in Privacy Center URL
Fides JavaScript Injection Vulnerability in Privacy Center URL
CVE-2023-32786High· 7.5Langchain Server-Side Request Forgery vulnerability
Langchain Server-Side Request Forgery vulnerability
CVE-2023-44690Mediummycli has Inadequate Encryption Strength
mycli has Inadequate Encryption Strength
CVE-2023-45805High· 7.8PDM Trojan Lockfile
PDM Trojan Lockfile
CVE-2023-45813Medium· 4.6TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link
TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link
CVE-2023-45803Medium· 4.2urllib3's request body not stripped after redirect from 303 status changes request method to GET
urllib3's request body not stripped after redirect from 303 status changes request method to GET
CVE-2023-41881Low· 3.7vantage6 does not properly delete linked resources when deleting a collaboration
vantage6 does not properly delete linked resources when deleting a collaboration
CVE-2023-45853Critical· 9.8⚖ disputedMiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pymini…
CVE-2023-23930High· 7.2Pickle serialization vulnerable to Deserialization of Untrusted Data
Pickle serialization vulnerable to Deserialization of Untrusted Data