Tagged “pip”
CVEs tagged pip, newest first.
4668 CVEsRSS
CVE-2023-34395High· 7.8Apache Airflow ODBC Provider Argument Injection vulnerability
Apache Airflow ODBC Provider Argument Injection vulnerability
GHSA-hj8m-9fhf-v7jpCritical· 10.0fief-server Server-Side Template Injection vulnerability
fief-server Server-Side Template Injection vulnerability
CVE-2023-35932High· 7.1jcvi vulnerable to Configuration Injection due to unsanitized user input
jcvi vulnerable to Configuration Injection due to unsanitized user input
CVE-2023-34239High· 7.3Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
CVE-2023-32682Medium· 5.4Synapse has improper checks for deactivated users during login
Synapse has improper checks for deactivated users during login
CVE-2023-33977High· 8.1PoCkiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
CVE-2023-33733High· 7.8PoCReportlab vulnerable to remote code execution
Reportlab vulnerable to remote code execution
GHSA-5cpq-8wj7-hf2vLowVulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2023-2970Low· 3.5MindSpore vulnerable to memory corruption
MindSpore vulnerable to memory corruption
CVE-2023-32321Critical· 9.8Ckan remote code execution and private information access via crafted resource ids
Ckan remote code execution and private information access via crafted resource ids
CVE-2023-33185Medium· 4.6Incorrect signature verification in django-ses
Incorrect signature verification in django-ses
CVE-2023-32681Medium· 6.1PoCUnintended leak of Proxy-Authorization header in requests
Unintended leak of Proxy-Authorization header in requests
CVE-2023-32686Medium· 5.4kiwitcms vulnerable to stored XSS via unrestricted files upload
kiwitcms vulnerable to stored XSS via unrestricted files upload
CVE-2023-29159Low· 3.7Starlette has Path Traversal vulnerability in StaticFiles
Starlette has Path Traversal vulnerability in StaticFiles
CVE-2023-32309High· 7.5PoCAny file can be included with the pymdown-snippets extension
Any file can be included with the pymdown-snippets extension
CVE-2023-32758High· 7.5git-url-parse Regular Expression Denial of Service
git-url-parse Regular Expression Denial of Service
CVE-2023-32059High· 7.5Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls
Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls
CVE-2023-32058High· 7.5Vyper vulnerable to integer overflow in loop
Vyper vulnerable to integer overflow in loop
CVE-2023-31146High· 7.5Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment
Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment
CVE-2023-30837High· 7.5vyper vulnerable to storage allocator overflow
vyper vulnerable to storage allocator overflow
CVE-2023-30861High· 7.5PoCFlask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
CVE-2022-37454Critical· 9.8Buffer overflow in sponge queue functions
Buffer overflow in sponge queue functions
CVE-2023-30629High· 7.5Incorrect success value returned in vyper
Incorrect success value returned in vyper
CVE-2023-30613High· 7.7Unrestricted file upload in kiwi TCMS
Unrestricted file upload in kiwi TCMS
CVE-2023-30544None· 0.0kiwi TCMS has possibility for user to update email address to unverified one
kiwi TCMS has possibility for user to update email address to unverified one
CVE-2023-27524High· 8.9CISA KEVPoCApache superset missing check for default SECRET_KEY
Apache superset missing check for default SECRET_KEY
CVE-2023-27525Medium· 4.3Apache Superset vulnerable to Improper Authorization
Apache Superset vulnerable to Improper Authorization
CVE-2023-2106High· 7.3Weak Password Requirements in calibreweb
Weak Password Requirements in calibreweb
CVE-2022-2525MediumImproper Restriction of Excessive Authentication Attempts in calibreweb
Improper Restriction of Excessive Authentication Attempts in calibreweb
CVE-2023-25392Medium· 5.9Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation
Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation