Tagged “pip”
CVEs tagged pip, newest first.
4666 CVEsRSS
CVE-2023-28635Medium· 5.4Defining resource name as integer may give unintended access in vantage6
Defining resource name as integer may give unintended access in vantage6
CVE-2023-45129Medium· 4.9matrix-synapse vulnerable to denial of service due to malicious server ACL events
matrix-synapse vulnerable to denial of service due to malicious server ACL events
CVE-2023-4570High· 8.8NI MeasurementLink Python Services Improper Access Restriction vulnerability
NI MeasurementLink Python Services Improper Access Restriction vulnerability
CVE-2023-44389Low· 3.1Zope management interface vulnerable to stored cross site scripting via the title property
Zope management interface vulnerable to stored cross site scripting via the title property
CVE-2023-4237Medium· 6.5Ansible may expose private key
Ansible may expose private key
CVE-2023-43804Medium· 5.9PoC`Cookie` HTTP header isn't stripped on cross-origin redirects
`Cookie` HTTP header isn't stripped on cross-origin redirects
CVE-2023-43654Critical· 9.8PoCTorchServe Server-Side Request Forgery vulnerability
TorchServe Server-Side Request Forgery vulnerability
CVE-2023-43810High· 7.5opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics
opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics
CVE-2023-44464High· 7.8pretix allows Pillow to parse EPS files
pretix allows Pillow to parse EPS files
CVE-2023-42453Low· 3.1matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
CVE-2023-41335Low· 3.7matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
CVE-2023-41419Critical· 9.8Gevent allows remote attacker to escalate privileges
Gevent allows remote attacker to escalate privileges
CVE-2023-43364Critical· 9.8PoCSearchor CLI's Search vulnerable to Arbitrary Code using Eval
Searchor CLI's Search vulnerable to Arbitrary Code using Eval
CVE-2023-40581High· 8.3yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`
yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`
CVE-2023-1636Medium· 6.0OpenStack Barbican information disclosure vulnerability
OpenStack Barbican information disclosure vulnerability
CVE-2023-1633Medium· 6.6OpenStack Barbican credential leak flaw
OpenStack Barbican credential leak flaw
CVE-2023-1625High· 7.4OpenStack Heat information leak vulnerability
OpenStack Heat information leak vulnerability
CVE-2023-5002Medium· 6.0pgAdmin failed to properly control the server code
pgAdmin failed to properly control the server code
GHSA-v8gr-m533-ghj9LowVulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2023-42458Low· 3.7Zope vulnerable to Stored Cross Site Scripting with SVG images
Zope vulnerable to Stored Cross Site Scripting with SVG images
CVE-2023-42439High· 7.5GeoNode vulnerable to SSRF Bypass to return internal host data
GeoNode vulnerable to SSRF Bypass to return internal host data
CVE-2023-42441Medium· 5.3Vyper has incorrect re-entrancy lock when key is empty string
Vyper has incorrect re-entrancy lock when key is empty string
CVE-2023-41626Medium· 4.8Gradio arbitrary file upload vulnerability
Gradio arbitrary file upload vulnerability
CVE-2023-41267High· 7.8Apache HDFS Provider error message suggested
Apache HDFS Provider error message suggested
CVE-2023-41319High· 8.8Remote Code Execution in Custom Integration Upload
Remote Code Execution in Custom Integration Upload
CVE-2023-41050Medium· 6.8Information disclosure in AccessControl
Information disclosure in AccessControl
CVE-2023-27523Medium· 5.0Apache Superset vulnerable to improper data authorization
Apache Superset vulnerable to improper data authorization
CVE-2023-39265Medium· 6.5PoCApache Superset Improper Input Validation vulnerability
Apache Superset Improper Input Validation vulnerability
CVE-2023-37941Medium· 6.6PoCApache Superset Deserialization of Untrusted Data vulnerability
Apache Superset Deserialization of Untrusted Data vulnerability
CVE-2023-38201Medium· 6.5Keylime registrar and (untrusted) Agent can be bypassed by an attacker
Keylime registrar and (untrusted) Agent can be bypassed by an attacker