VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4667 CVEsRSS

CVE-2023-38201Medium· 6.5
3y ago

Keylime registrar and (untrusted) Agent can be bypassed by an attacker

Keylime registrar and (untrusted) Agent can be bypassed by an attacker

▾ Sunlitkeylime · keylimeEPSS 0.49%via OSV
CVE-2023-39264Medium· 4.3
3y ago

Apache Superset may expose internal traces on REST API endpoints

Apache Superset may expose internal traces on REST API endpoints

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVE-2023-27526Medium· 4.3
3y ago

Apache Superset users may incorrectly create resources using the import charts feature

Apache Superset users may incorrectly create resources using the import charts feature

▾ Sunlitapache-superset · apache-supersetEPSS 1.2%via OSV
CVE-2023-36387Medium· 5.4
3y ago

Apache Superset has improper default REST API permission for Gamma users

Apache Superset has improper default REST API permission for Gamma users

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVE-2023-32672Medium· 4.3
3y ago

Apache Superset has incorrect authorization check

Apache Superset has incorrect authorization check

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2023-36388Medium· 4.3
3y ago

Apache Superset Server Side Request Forgery vulnerability

Apache Superset Server Side Request Forgery vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVE-2023-41052Medium· 5.3
3y ago

incorrect order of evaluation of side effects for some builtins

incorrect order of evaluation of side effects for some builtins

▾ Sunlitvyper · vyperEPSS 0.54%via OSV
CVE-2023-41057Low· 3.3
3y ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-it

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-it

▾ Sunlithyper-bump-it · hyper-bump-itEPSS 0.36%via OSV
CVE-2023-40590High· 7.8
3y ago

GitPython untrusted search path on Windows systems leading to arbitrary code execution

GitPython untrusted search path on Windows systems leading to arbitrary code execution

▾ Twilightgitpython · gitpythonEPSS 0.51%via OSV
CVE-2023-39968Medium· 6.1
3y ago

Open Redirect Vulnerability in jupyter-server

Open Redirect Vulnerability in jupyter-server

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.68%via OSV
CVE-2023-40170Medium· 4.6
3y ago

cross-site inclusion (XSSI) of files in jupyter-server

cross-site inclusion (XSSI) of files in jupyter-server

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.62%via OSV
CVE-2023-27604High· 8.8
3y ago

Airflow Sqoop Provider RCE Vulnerability

Airflow Sqoop Provider RCE Vulnerability

▾ Twilightapache-airflow-providers-apache-sqoop · apache-airflow-providers-apache-sqoopEPSS 1.7%via OSV
CVE-2023-40587Medium· 5.3
3y ago

Pyramid static view path traversal up one directory

Pyramid static view path traversal up one directory

▾ Sunlitpyramid · pyramidEPSS 0.75%via OSV
CVE-2023-39441Medium· 5.9
3y ago

Apache Airflow missing Certificate Validation

Apache Airflow missing Certificate Validation

▾ Sunlitapache-airflow-providers-smtp · apache-airflow-providers-smtpEPSS 0.80%via OSV
CVE-2023-39660High
3y ago

pandasai vulnerable to prompt injection

pandasai vulnerable to prompt injection

▾ Twilightpandasai · pandasaiEPSS 1.5%via OSV
CVE-2023-40272High· 7.5
3y ago

Apache Airflow Spark Provider Improper Input Validation vulnerability

Apache Airflow Spark Provider Improper Input Validation vulnerability

▾ Twilightapache-airflow-providers-apache-spark · apache-airflow-providers-apache-sparkEPSS 2.1%via OSV
CVE-2023-40024Medium· 6.1
3y ago

Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint

Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint

▾ Sunlitscancodeio · scancodeioEPSS 0.51%via OSV
CVE-2023-39553High· 7.5
3y ago

apache-airflow-providers-apache-drill Improper Input Validation vulnerability

apache-airflow-providers-apache-drill Improper Input Validation vulnerability

▾ Twilightapache-airflow-providers-apache-drill · apache-airflow-providers-apache-drillEPSS 2.3%via OSV
CVE-2023-27506Medium· 5.5
3y ago

Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow

Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow

▾ Sunlitintel-tensorflow · intel-tensorflowEPSS 0.16%via OSV
CVE-2020-35141High· 7.5
3y ago

FaucetSDN Ryu Denial of Service Vulnerability

FaucetSDN Ryu Denial of Service Vulnerability

▾ Twilightryu · ryuEPSS 0.95%via OSV
CVE-2020-35139High· 7.5
3y ago

FaucetSDN Ryu Denial of Service Vulnerability

FaucetSDN Ryu Denial of Service Vulnerability

▾ Twilightryu · ryuEPSS 0.95%via OSV
CVE-2023-39363High· 8.7
3y ago

Vyper has incorrectly allocated named re-entrancy locks

Vyper has incorrectly allocated named re-entrancy locks

▾ Twilightvyper · vyperEPSS 0.82%via OSV
CVE-2023-39531Medium· 6.5
3y ago

Sentry vulnerable to incorrect credential validation on OAuth token requests

Sentry vulnerable to incorrect credential validation on OAuth token requests

▾ Sunlitsentry · sentryEPSS 0.36%via OSV
CVE-2023-33953High· 7.5
3y ago

Excessive Iteration in gRPC

Excessive Iteration in gRPC

▾ Twilightgrpcio · grpcioEPSS 0.48%via OSV
CVE-2023-39523Medium· 6.8
3y ago

ScanCode.io command injection in docker image fetch process

ScanCode.io command injection in docker image fetch process

▾ Sunlitscancodeio · scancodeioEPSS 2.9%via OSV
CVE-2023-39349High· 8.1
3y ago

Privilege escalation via ApiTokensEndpoint

Privilege escalation via ApiTokensEndpoint

▾ Twilightsentry · sentryEPSS 1.1%via OSV
CVE-2023-4138Medium· 4.2
3y ago

RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling

RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling

▾ Sunlitrdiffweb · rdiffwebEPSS 0.45%via OSV
GHSA-jm77-qphf-c4w8Low
3y ago

pyca/cryptography's wheels include vulnerable OpenSSL

pyca/cryptography's wheels include vulnerable OpenSSL

▾ Sunlitcryptography · cryptographyvia OSV
CVE-2023-38200High· 7.5
3y ago

Keylime's registrar vulnerable to Denial-of-service attack via a single open connection

Keylime's registrar vulnerable to Denial-of-service attack via a single open connection

▾ Twilightkeylime · keylimeEPSS 1.4%via OSV
CVE-2023-38686Critical· 9.3
3y ago

Sydent does not verify email server certificates

Sydent does not verify email server certificates

▾ Midnightmatrix-sydent · matrix-sydentEPSS 0.27%via OSV
CVEs tagged “pip” — page 121 · VulnSea