VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4666 CVEsRSS

CVE-2023-28635Medium· 5.4
2y ago

Defining resource name as integer may give unintended access in vantage6

Defining resource name as integer may give unintended access in vantage6

▾ Sunlitvantage6 · vantage6EPSS 0.41%via OSV
CVE-2023-45129Medium· 4.9
2y ago

matrix-synapse vulnerable to denial of service due to malicious server ACL events

matrix-synapse vulnerable to denial of service due to malicious server ACL events

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.2%via OSV
CVE-2023-4570High· 8.8
2y ago

NI MeasurementLink Python Services Improper Access Restriction vulnerability

NI MeasurementLink Python Services Improper Access Restriction vulnerability

▾ Twilightni-measurementlink-service · ni-measurementlink-serviceEPSS 0.28%via OSV
CVE-2023-44389Low· 3.1
2y ago

Zope management interface vulnerable to stored cross site scripting via the title property

Zope management interface vulnerable to stored cross site scripting via the title property

▾ Sunlitzope · zopeEPSS 0.40%via OSV
CVE-2023-4237Medium· 6.5
2y ago

Ansible may expose private key

Ansible may expose private key

▾ Sunlitansible-core · ansible-coreEPSS 0.25%via OSV
CVE-2023-43804Medium· 5.9PoC
2y ago

`Cookie` HTTP header isn't stripped on cross-origin redirects

`Cookie` HTTP header isn't stripped on cross-origin redirects

▾ Twilighturllib3 · urllib3EPSS 1.2%via OSV
CVE-2023-43654Critical· 9.8PoC
2y ago

TorchServe Server-Side Request Forgery vulnerability

TorchServe Server-Side Request Forgery vulnerability

▾ Abyssaltorchserve · torchserveEPSS 40%via OSV
CVE-2023-43810High· 7.5
2y ago

opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics

opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics

▾ Twilightopentelemetry-instrumentation · opentelemetry-instrumentationEPSS 0.69%via OSV
CVE-2023-44464High· 7.8
3y ago

pretix allows Pillow to parse EPS files

pretix allows Pillow to parse EPS files

▾ Twilightpretix · pretixEPSS 0.30%via OSV
CVE-2023-42453Low· 3.1
3y ago

matrix-synapse vulnerable to improper validation of receipts allows forged read receipts

matrix-synapse vulnerable to improper validation of receipts allows forged read receipts

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.78%via OSV
CVE-2023-41335Low· 3.7
3y ago

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.39%via OSV
CVE-2023-41419Critical· 9.8
3y ago

Gevent allows remote attacker to escalate privileges

Gevent allows remote attacker to escalate privileges

▾ Midnightgevent · geventEPSS 1.8%via OSV
CVE-2023-43364Critical· 9.8PoC
3y ago

Searchor CLI's Search vulnerable to Arbitrary Code using Eval

Searchor CLI's Search vulnerable to Arbitrary Code using Eval

▾ Abyssalsearchor · searchorEPSS 2.9%via OSV
CVE-2023-40581High· 8.3
3y ago

yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`

yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`

▾ Twilightyt-dlp · yt-dlpEPSS 1.3%via OSV
CVE-2023-1636Medium· 6.0
3y ago

OpenStack Barbican information disclosure vulnerability

OpenStack Barbican information disclosure vulnerability

▾ Sunlitbarbican · barbicanEPSS 0.48%via OSV
CVE-2023-1633Medium· 6.6
3y ago

OpenStack Barbican credential leak flaw

OpenStack Barbican credential leak flaw

▾ Sunlitbarbican · barbicanEPSS 0.19%via OSV
CVE-2023-1625High· 7.4
3y ago

OpenStack Heat information leak vulnerability

OpenStack Heat information leak vulnerability

▾ Twilightopenstack-heat · openstack-heatEPSS 0.71%via OSV
CVE-2023-5002Medium· 6.0
3y ago

pgAdmin failed to properly control the server code

pgAdmin failed to properly control the server code

▾ Sunlitpgadmin4 · pgadmin4EPSS 1.8%via OSV
GHSA-v8gr-m533-ghj9Low
3y ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

▾ Sunlitcryptography · cryptographyvia OSV
CVE-2023-42458Low· 3.7
3y ago

Zope vulnerable to Stored Cross Site Scripting with SVG images

Zope vulnerable to Stored Cross Site Scripting with SVG images

▾ Sunlitzope · zopeEPSS 0.71%via OSV
CVE-2023-42439High· 7.5
3y ago

GeoNode vulnerable to SSRF Bypass to return internal host data

GeoNode vulnerable to SSRF Bypass to return internal host data

▾ Twilightgeonode · geonodeEPSS 0.96%via OSV
CVE-2023-42441Medium· 5.3
3y ago

Vyper has incorrect re-entrancy lock when key is empty string

Vyper has incorrect re-entrancy lock when key is empty string

▾ Sunlitvyper · vyperEPSS 0.51%via OSV
CVE-2023-41626Medium· 4.8
3y ago

Gradio arbitrary file upload vulnerability

Gradio arbitrary file upload vulnerability

▾ Sunlitgradio · gradioEPSS 0.41%via OSV
CVE-2023-41267High· 7.8
3y ago

Apache HDFS Provider error message suggested

Apache HDFS Provider error message suggested

▾ Twilightapache-airflow-providers-apache-hdfs · apache-airflow-providers-apache-hdfsEPSS 0.60%via OSV
CVE-2023-41319High· 8.8
3y ago

Remote Code Execution in Custom Integration Upload

Remote Code Execution in Custom Integration Upload

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.94%via OSV
CVE-2023-41050Medium· 6.8
3y ago

Information disclosure in AccessControl

Information disclosure in AccessControl

▾ Sunlitaccesscontrol · accesscontrolEPSS 0.64%via OSV
CVE-2023-27523Medium· 5.0
3y ago

Apache Superset vulnerable to improper data authorization

Apache Superset vulnerable to improper data authorization

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2023-39265Medium· 6.5PoC
3y ago

Apache Superset Improper Input Validation vulnerability

Apache Superset Improper Input Validation vulnerability

▾ Twilightapache-superset · apache-supersetEPSS 86%via OSV
CVE-2023-37941Medium· 6.6PoC
3y ago

Apache Superset Deserialization of Untrusted Data vulnerability

Apache Superset Deserialization of Untrusted Data vulnerability

▾ Twilightapache-superset · apache-supersetEPSS 35%via OSV
CVE-2023-38201Medium· 6.5
3y ago

Keylime registrar and (untrusted) Agent can be bypassed by an attacker

Keylime registrar and (untrusted) Agent can be bypassed by an attacker

▾ Sunlitkeylime · keylimeEPSS 0.49%via OSV
CVEs tagged “pip” — page 120 · VulnSea