Tagged “pip”
CVEs tagged pip, newest first.
4667 CVEsRSS
CVE-2022-3101Medium· 5.5tripleo-ansible may disclose important configuration details from an OpenStack deployment
tripleo-ansible may disclose important configuration details from an OpenStack deployment
CVE-2023-28117High· 7.6Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`
Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`
CVE-2023-27586Critical· 9.9CairoSVG improperly processes SVG files loaded from external resources
CairoSVG improperly processes SVG files loaded from external resources
CVE-2017-20182Medium· 6.1Cross-site Scripting in django-ajax-utilities
Cross-site Scripting in django-ajax-utilities
CVE-2022-3277Medium· 6.5openstack-neutron uncontrolled resource consumption flaw
openstack-neutron uncontrolled resource consumption flaw
CVE-2023-27522High· 7.5httpd: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)
An HTTP Response Smuggling vulnerability was found in the Apache HTTP Server via mod_proxy_uwsgi. This security issue occurs when special characters in the origin response header can truncate or split the response forwarded to the client.
CVE-2023-22432Medium· 6.1PoCOpen redirect in web2py
Open redirect in web2py
CVE-2023-26051Medium· 6.5Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
CVE-2023-26052Low· 3.7Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions
Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions
CVE-2023-30797High· 7.5Lemur subject to insecure random generation
Lemur subject to insecure random generation
CVE-2023-22738Medium· 6.5vantage6 vulnerable to Improper Preservation of Permissions
vantage6 vulnerable to Improper Preservation of Permissions
CVE-2023-23929High· 8.8vantage6 refresh tokens do not expire
vantage6 refresh tokens do not expire
CVE-2022-39228Medium· 6.5vantage6 vulnerable to Observable Response Discrepancy
vantage6 vulnerable to Observable Response Discrepancy
CVE-2023-25956High· 7.5Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information
Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information
CVE-2023-25692High· 7.5Apache Airflow Google Provider Improper Input Validation vulnerability
Apache Airflow Google Provider Improper Input Validation vulnerability
CVE-2023-25823Medium· 5.4Update share links to use FRP instead of SSH tunneling
Update share links to use FRP instead of SSH tunneling
CVE-2023-0860High· 7.5PoCImproper Restriction of Excessive Authentication Attempts in modoboa
Improper Restriction of Excessive Authentication Attempts in modoboa
CVE-2023-25577High· 7.5High resource usage when parsing multipart form data with many fields
High resource usage when parsing multipart form data with many fields
CVE-2023-23934Low· 2.6Incorrect parsing of nameless cookies leads to __Host- cookies bypass
Incorrect parsing of nameless cookies leads to __Host- cookies bypass
CVE-2023-25171High· 7.5Denial of service vulnerability on Password reset page
Denial of service vulnerability on Password reset page
CVE-2023-25156High· 7.5No protection against brute-force attacks on login page
No protection against brute-force attacks on login page
CVE-2023-30798High· 7.5MultipartParser denial of service with too many fields or files
MultipartParser denial of service with too many fields or files
CVE-2023-24816Medium· 4.5IPython vulnerable to command injection via set_term_title
IPython vulnerable to command injection via set_term_title
CVE-2023-23931Medium· 6.5Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf
Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf
CVE-2023-0286High· 7.4openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)
A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability ma…
CVE-2023-0488Medium· 5.4Cross-site Scripting in pyload-ng
Cross-site Scripting in pyload-ng
CVE-2023-0509High· 7.4Improper Certificate Validation in pyload-ng
Improper Certificate Validation in pyload-ng
CVE-2022-47951Medium· 5.7OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
CVE-2022-4510High· 7.8PoCPath traversal in binwalk
Path traversal in binwalk
CVE-2023-23608Medium· 5.4Path traversal in spotipy
Path traversal in spotipy