VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4668 CVEsRSS

CVE-2023-34395High· 7.8
3y ago

Apache Airflow ODBC Provider Argument Injection vulnerability

Apache Airflow ODBC Provider Argument Injection vulnerability

▾ Twilightapache-airflow-providers-odbc · apache-airflow-providers-odbcEPSS 0.76%via OSV
GHSA-hj8m-9fhf-v7jpCritical· 10.0
3y ago

fief-server Server-Side Template Injection vulnerability

fief-server Server-Side Template Injection vulnerability

▾ Midnightfief-server · fief-servervia OSV
CVE-2023-35932High· 7.1
3y ago

jcvi vulnerable to Configuration Injection due to unsanitized user input

jcvi vulnerable to Configuration Injection due to unsanitized user input

▾ Twilightjcvi · jcviEPSS 1.9%via OSV
CVE-2023-34239High· 7.3
3y ago

Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs

Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs

▾ Twilightgradio · gradioEPSS 0.65%via OSV
CVE-2023-32682Medium· 5.4
3y ago

Synapse has improper checks for deactivated users during login

Synapse has improper checks for deactivated users during login

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.75%via OSV
CVE-2023-33977High· 8.1PoC
3y ago

kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload

kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload

▾ Midnightkiwitcms · kiwitcmsEPSS 0.87%via OSV
CVE-2023-33733High· 7.8PoC
3y ago

Reportlab vulnerable to remote code execution

Reportlab vulnerable to remote code execution

▾ Midnightreportlab · reportlabEPSS 2.1%via OSV
GHSA-5cpq-8wj7-hf2vLow
3y ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

▾ Sunlitcryptography · cryptographyvia OSV
CVE-2023-2970Low· 3.5
3y ago

MindSpore vulnerable to memory corruption

MindSpore vulnerable to memory corruption

▾ Sunlitmindspore · mindsporeEPSS 0.88%via OSV
CVE-2023-32321Critical· 9.8
3y ago

Ckan remote code execution and private information access via crafted resource ids

Ckan remote code execution and private information access via crafted resource ids

▾ Midnightckan · ckanEPSS 1.7%via OSV
CVE-2023-33185Medium· 4.6
3y ago

Incorrect signature verification in django-ses

Incorrect signature verification in django-ses

▾ Sunlitdjango-ses · django-sesEPSS 0.23%via OSV
CVE-2023-32681Medium· 6.1PoC
3y ago

Unintended leak of Proxy-Authorization header in requests

Unintended leak of Proxy-Authorization header in requests

▾ Twilightrequests · requestsEPSS 3.0%via OSV
CVE-2023-32686Medium· 5.4
3y ago

kiwitcms vulnerable to stored XSS via unrestricted files upload

kiwitcms vulnerable to stored XSS via unrestricted files upload

▾ Sunlitkiwitcms · kiwitcmsEPSS 0.43%via OSV
CVE-2023-29159Low· 3.7
3y ago

Starlette has Path Traversal vulnerability in StaticFiles

Starlette has Path Traversal vulnerability in StaticFiles

▾ Sunlitstarlette · starletteEPSS 2.0%via OSV
CVE-2023-32309High· 7.5PoC
3y ago

Any file can be included with the pymdown-snippets extension

Any file can be included with the pymdown-snippets extension

▾ Midnightpymdown-extensions · pymdown-extensionsEPSS 1.7%via OSV
CVE-2023-32758High· 7.5
3y ago

git-url-parse Regular Expression Denial of Service

git-url-parse Regular Expression Denial of Service

▾ Twilightgit-url-parse · git-url-parseEPSS 1.0%via OSV
CVE-2023-32059High· 7.5
3y ago

Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls

Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls

▾ Twilightvyper · vyperEPSS 0.73%via OSV
CVE-2023-32058High· 7.5
3y ago

Vyper vulnerable to integer overflow in loop

Vyper vulnerable to integer overflow in loop

▾ Twilightvyper · vyperEPSS 0.91%via OSV
CVE-2023-31146High· 7.5
3y ago

Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment

Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment

▾ Twilightvyper · vyperEPSS 1.2%via OSV
CVE-2023-30837High· 7.5
3y ago

vyper vulnerable to storage allocator overflow

vyper vulnerable to storage allocator overflow

▾ Twilightvyper · vyperEPSS 0.70%via OSV
CVE-2023-30861High· 7.5PoC
3y ago

Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header

Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header

▾ Midnightflask · flaskEPSS 1.3%via OSV
CVE-2022-37454Critical· 9.8
3y ago

Buffer overflow in sponge queue functions

Buffer overflow in sponge queue functions

▾ Midnightpysha3 · pysha3EPSS 5.8%via OSV
CVE-2023-30629High· 7.5
3y ago

Incorrect success value returned in vyper

Incorrect success value returned in vyper

▾ Twilightvyper · vyperEPSS 0.88%via OSV
CVE-2023-30613High· 7.7
3y ago

Unrestricted file upload in kiwi TCMS

Unrestricted file upload in kiwi TCMS

▾ Twilightkiwitcms · kiwitcmsEPSS 1.0%via OSV
CVE-2023-30544None· 0.0
3y ago

kiwi TCMS has possibility for user to update email address to unverified one

kiwi TCMS has possibility for user to update email address to unverified one

▾ Sunlitkiwitcms · kiwitcmsEPSS 0.42%via OSV
CVE-2023-27524High· 8.9CISA KEVPoC
3y ago

Apache superset missing check for default SECRET_KEY

Apache superset missing check for default SECRET_KEY

▾ Abyssalapache-superset · apache-supersetEPSS 97%via OSV
CVE-2023-27525Medium· 4.3
3y ago

Apache Superset vulnerable to Improper Authorization

Apache Superset vulnerable to Improper Authorization

▾ Sunlitapache-superset · apache-supersetEPSS 0.78%via OSV
CVE-2023-2106High· 7.3
3y ago

Weak Password Requirements in calibreweb

Weak Password Requirements in calibreweb

▾ Twilightcalibreweb · calibrewebEPSS 0.75%via OSV
CVE-2022-2525Medium
3y ago

Improper Restriction of Excessive Authentication Attempts in calibreweb

Improper Restriction of Excessive Authentication Attempts in calibreweb

▾ Sunlitcalibreweb · calibrewebEPSS 0.77%via OSV
CVE-2023-25392Medium· 5.9
3y ago

Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation

Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation

▾ Sunlitbigflow · bigflowEPSS 0.43%via OSV
CVEs tagged “pip” — page 123 · VulnSea