VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4667 CVEsRSS

CVE-2022-3101Medium· 5.5
3y ago

tripleo-ansible may disclose important configuration details from an OpenStack deployment

tripleo-ansible may disclose important configuration details from an OpenStack deployment

▾ Sunlittripleo-ansible · tripleo-ansibleEPSS 0.20%via OSV
CVE-2023-28117High· 7.6
3y ago

Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`

Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`

▾ Twilightsentry-sdk · sentry-sdkEPSS 0.65%via OSV
CVE-2023-27586Critical· 9.9
3y ago

CairoSVG improperly processes SVG files loaded from external resources

CairoSVG improperly processes SVG files loaded from external resources

▾ Midnightcairosvg · cairosvgEPSS 0.72%via OSV
CVE-2017-20182Medium· 6.1
3y ago

Cross-site Scripting in django-ajax-utilities

Cross-site Scripting in django-ajax-utilities

▾ Sunlitdjango-ajax-utilities · django-ajax-utilitiesEPSS 0.57%via OSV
CVE-2022-3277Medium· 6.5
3y ago

openstack-neutron uncontrolled resource consumption flaw

openstack-neutron uncontrolled resource consumption flaw

▾ Sunlitneutron · neutronEPSS 1.1%via OSV
CVE-2023-27522High· 7.5
3y ago

httpd: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)

An HTTP Response Smuggling vulnerability was found in the Apache HTTP Server via mod_proxy_uwsgi. This security issue occurs when special characters in the origin response header can truncate or split the response forwarded to the client.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.8.6)EPSS 2.1%via CSAF
CVE-2023-22432Medium· 6.1PoC
3y ago

Open redirect in web2py

Open redirect in web2py

▾ Twilightweb2py · web2pyEPSS 2.4%via OSV
CVE-2023-26051Medium· 6.5
3y ago

Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions

Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions

▾ Sunlitsaleor · saleorEPSS 0.82%via OSV
CVE-2023-26052Low· 3.7
3y ago

Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions

Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions

▾ Sunlitsaleor · saleorEPSS 0.76%via OSV
CVE-2023-30797High· 7.5
3y ago

Lemur subject to insecure random generation

Lemur subject to insecure random generation

▾ Twilightlemur · lemurEPSS 0.79%via OSV
CVE-2023-22738Medium· 6.5
3y ago

vantage6 vulnerable to Improper Preservation of Permissions

vantage6 vulnerable to Improper Preservation of Permissions

▾ Sunlitvantage6 · vantage6EPSS 0.38%via OSV
CVE-2023-23929High· 8.8
3y ago

vantage6 refresh tokens do not expire

vantage6 refresh tokens do not expire

▾ Twilightvantage6 · vantage6EPSS 0.57%via OSV
CVE-2022-39228Medium· 6.5
3y ago

vantage6 vulnerable to Observable Response Discrepancy

vantage6 vulnerable to Observable Response Discrepancy

▾ Sunlitvantage6 · vantage6EPSS 0.60%via OSV
CVE-2023-25956High· 7.5
3y ago

Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information

Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information

▾ Twilightapache-airflow-providers-amazon · apache-airflow-providers-amazonEPSS 1.5%via OSV
CVE-2023-25692High· 7.5
3y ago

Apache Airflow Google Provider Improper Input Validation vulnerability

Apache Airflow Google Provider Improper Input Validation vulnerability

▾ Twilightapache-airflow-providers-google · apache-airflow-providers-googleEPSS 1.8%via OSV
CVE-2023-25823Medium· 5.4
3y ago

Update share links to use FRP instead of SSH tunneling

Update share links to use FRP instead of SSH tunneling

▾ Sunlitgradio · gradioEPSS 0.55%via OSV
CVE-2023-0860High· 7.5PoC
3y ago

Improper Restriction of Excessive Authentication Attempts in modoboa

Improper Restriction of Excessive Authentication Attempts in modoboa

▾ Midnightmodoboa · modoboaEPSS 0.66%via OSV
CVE-2023-25577High· 7.5
3y ago

High resource usage when parsing multipart form data with many fields

High resource usage when parsing multipart form data with many fields

▾ Twilightwerkzeug · werkzeugEPSS 1.4%via OSV
CVE-2023-23934Low· 2.6
3y ago

Incorrect parsing of nameless cookies leads to __Host- cookies bypass

Incorrect parsing of nameless cookies leads to __Host- cookies bypass

▾ Sunlitwerkzeug · werkzeugEPSS 0.51%via OSV
CVE-2023-25171High· 7.5
3y ago

Denial of service vulnerability on Password reset page

Denial of service vulnerability on Password reset page

▾ Twilightkiwitcms · kiwitcmsEPSS 0.92%via OSV
CVE-2023-25156High· 7.5
3y ago

No protection against brute-force attacks on login page

No protection against brute-force attacks on login page

▾ Twilightkiwitcms · kiwitcmsEPSS 0.91%via OSV
CVE-2023-30798High· 7.5
3y ago

MultipartParser denial of service with too many fields or files

MultipartParser denial of service with too many fields or files

▾ Twilightstarlette · starletteEPSS 1.3%via OSV
CVE-2023-24816Medium· 4.5
3y ago

IPython vulnerable to command injection via set_term_title

IPython vulnerable to command injection via set_term_title

▾ Sunlitipython · ipythonEPSS 1.3%via OSV
CVE-2023-23931Medium· 6.5
3y ago

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

▾ Sunlitcryptography · cryptographyEPSS 1.3%via OSV
CVE-2023-0286High· 7.4
3y ago

openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)

A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability ma…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 60%via CSAF
CVE-2023-0488Medium· 5.4
3y ago

Cross-site Scripting in pyload-ng

Cross-site Scripting in pyload-ng

▾ Sunlitpyload-ng · pyload-ngEPSS 0.83%via OSV
CVE-2023-0509High· 7.4
3y ago

Improper Certificate Validation in pyload-ng

Improper Certificate Validation in pyload-ng

▾ Twilightpyload-ng · pyload-ngEPSS 0.53%via OSV
CVE-2022-47951Medium· 5.7
3y ago

OpenStack Cinder, glance, and Nova vulnerable to Path Traversal

OpenStack Cinder, glance, and Nova vulnerable to Path Traversal

▾ Sunlitcinder · cinderEPSS 1.0%via OSV
CVE-2022-4510High· 7.8PoC
3y ago

Path traversal in binwalk

Path traversal in binwalk

▾ Midnightbinwalk · binwalkEPSS 22%via OSV
CVE-2023-23608Medium· 5.4
3y ago

Path traversal in spotipy

Path traversal in spotipy

▾ Sunlitspotipy · spotipyEPSS 0.66%via OSV
CVEs tagged “pip” — page 125 · VulnSea