Tagged “pip”
CVEs tagged pip, newest first.
4668 CVEsRSS
CVE-2023-38686Critical· 9.3Sydent does not verify email server certificates
Sydent does not verify email server certificates
CVE-2023-38670Medium· 4.7Null pointer dereference in PaddlePaddle
Null pointer dereference in PaddlePaddle
CVE-2023-38671High· 8.3Heap buffer overflow in PaddlePaddle
Heap buffer overflow in PaddlePaddle
CVE-2023-38672Medium· 4.7Float point exception (FPE) in paddlepaddle
Float point exception (FPE) in paddlepaddle
CVE-2023-38673Critical· 9.6Command injection in PaddlePaddle
Command injection in PaddlePaddle
CVE-2023-38669High· 8.3Use after free in PaddlePaddle
Use after free in PaddlePaddle
CVE-2023-37920High· 7.5Removal of e-Tugra root certificate
Removal of e-Tugra root certificate
CVE-2023-36826High· 7.7Improper authorization on debug and artifact file downloads
Improper authorization on debug and artifact file downloads
CVE-2023-3637Medium· 6.5Denial of service in neutron
Denial of service in neutron
CVE-2023-37480Low· 2.7Fides Webserver Vulnerable to Zip Bomb File Uploads
Fides Webserver Vulnerable to Zip Bomb File Uploads
CVE-2023-37481Low· 2.7Fides Webserver Vulnerable to SVG Bomb File Uploads
Fides Webserver Vulnerable to SVG Bomb File Uploads
CVE-2023-37474High· 7.5PoCcopyparty vulnerable to path traversal attack
copyparty vulnerable to path traversal attack
CVE-2023-38325High· 7.5cryptography mishandles SSH certificates
cryptography mishandles SSH certificates
CVE-2023-37415High· 8.8Apache Airflow Apache Hive Provider Improper Input Validation vulnerability
Apache Airflow Apache Hive Provider Improper Input Validation vulnerability
CVE-2023-37271High· 8.4RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape
RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape
CVE-2023-36827High· 7.5ethyca-fides Webserver API Path Traversal vulnerability
ethyca-fides Webserver API Path Traversal vulnerability
CVE-2023-36829Medium· 6.8Sentry CORS misconfiguration
Sentry CORS misconfiguration
CVE-2023-35934Medium· 6.1yt-dlp File Downloader cookie leak
yt-dlp File Downloader cookie leak
CVE-2023-25504Medium· 6.5Apache Superset Server-Side Request Forgery vulnerability
Apache Superset Server-Side Request Forgery vulnerability
CVE-2023-30776Medium· 6.5Apache Superset vulnerable to Exposure of Sensitive Information
Apache Superset vulnerable to Exposure of Sensitive Information
CVE-2023-36188Critical· 9.8langchain vulnerable to arbitrary code execution
langchain vulnerable to arbitrary code execution
CVE-2023-34457Medium· 5.9MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
CVE-2023-36814High· 7.5Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module
Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module
CVE-2023-36809High· 8.1Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
CVE-2023-37365Medium· 6.5hnswlib Double Free vulnerability
hnswlib Double Free vulnerability
CVE-2023-36810Medium· 6.2PyPDF2 quadratic runtime with malformed PDF missing xref marker
PyPDF2 quadratic runtime with malformed PDF missing xref marker
CVE-2023-36807Medium· 6.2PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects
PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects
CVE-2023-36464Medium· 6.2pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character
pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character
CVE-2023-22886High· 8.8Apache Airflow JDBC Provider Improper Input Validation vulnerability
Apache Airflow JDBC Provider Improper Input Validation vulnerability
CVE-2023-35798Medium· 4.3Apache Airflow ODBC Provider, Apache Airflow MSSQL Provider Improper Input Validation vulnerability
Apache Airflow ODBC Provider, Apache Airflow MSSQL Provider Improper Input Validation vulnerability