Tagged “pip”
CVEs tagged pip, newest first.
4667 CVEsRSS
CVE-2023-38201Medium· 6.5Keylime registrar and (untrusted) Agent can be bypassed by an attacker
Keylime registrar and (untrusted) Agent can be bypassed by an attacker
CVE-2023-39264Medium· 4.3Apache Superset may expose internal traces on REST API endpoints
Apache Superset may expose internal traces on REST API endpoints
CVE-2023-27526Medium· 4.3Apache Superset users may incorrectly create resources using the import charts feature
Apache Superset users may incorrectly create resources using the import charts feature
CVE-2023-36387Medium· 5.4Apache Superset has improper default REST API permission for Gamma users
Apache Superset has improper default REST API permission for Gamma users
CVE-2023-32672Medium· 4.3Apache Superset has incorrect authorization check
Apache Superset has incorrect authorization check
CVE-2023-36388Medium· 4.3Apache Superset Server Side Request Forgery vulnerability
Apache Superset Server Side Request Forgery vulnerability
CVE-2023-41052Medium· 5.3incorrect order of evaluation of side effects for some builtins
incorrect order of evaluation of side effects for some builtins
CVE-2023-41057Low· 3.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-it
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-it
CVE-2023-40590High· 7.8GitPython untrusted search path on Windows systems leading to arbitrary code execution
GitPython untrusted search path on Windows systems leading to arbitrary code execution
CVE-2023-39968Medium· 6.1Open Redirect Vulnerability in jupyter-server
Open Redirect Vulnerability in jupyter-server
CVE-2023-40170Medium· 4.6cross-site inclusion (XSSI) of files in jupyter-server
cross-site inclusion (XSSI) of files in jupyter-server
CVE-2023-27604High· 8.8Airflow Sqoop Provider RCE Vulnerability
Airflow Sqoop Provider RCE Vulnerability
CVE-2023-40587Medium· 5.3Pyramid static view path traversal up one directory
Pyramid static view path traversal up one directory
CVE-2023-39441Medium· 5.9Apache Airflow missing Certificate Validation
Apache Airflow missing Certificate Validation
CVE-2023-39660Highpandasai vulnerable to prompt injection
pandasai vulnerable to prompt injection
CVE-2023-40272High· 7.5Apache Airflow Spark Provider Improper Input Validation vulnerability
Apache Airflow Spark Provider Improper Input Validation vulnerability
CVE-2023-40024Medium· 6.1Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
CVE-2023-39553High· 7.5apache-airflow-providers-apache-drill Improper Input Validation vulnerability
apache-airflow-providers-apache-drill Improper Input Validation vulnerability
CVE-2023-27506Medium· 5.5Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow
Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow
CVE-2020-35141High· 7.5FaucetSDN Ryu Denial of Service Vulnerability
FaucetSDN Ryu Denial of Service Vulnerability
CVE-2020-35139High· 7.5FaucetSDN Ryu Denial of Service Vulnerability
FaucetSDN Ryu Denial of Service Vulnerability
CVE-2023-39363High· 8.7Vyper has incorrectly allocated named re-entrancy locks
Vyper has incorrectly allocated named re-entrancy locks
CVE-2023-39531Medium· 6.5Sentry vulnerable to incorrect credential validation on OAuth token requests
Sentry vulnerable to incorrect credential validation on OAuth token requests
CVE-2023-33953High· 7.5Excessive Iteration in gRPC
Excessive Iteration in gRPC
CVE-2023-39523Medium· 6.8ScanCode.io command injection in docker image fetch process
ScanCode.io command injection in docker image fetch process
CVE-2023-39349High· 8.1Privilege escalation via ApiTokensEndpoint
Privilege escalation via ApiTokensEndpoint
CVE-2023-4138Medium· 4.2RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling
RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling
GHSA-jm77-qphf-c4w8Lowpyca/cryptography's wheels include vulnerable OpenSSL
pyca/cryptography's wheels include vulnerable OpenSSL
CVE-2023-38200High· 7.5Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
CVE-2023-38686Critical· 9.3Sydent does not verify email server certificates
Sydent does not verify email server certificates