VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4668 CVEsRSS

CVE-2022-36026Medium· 5.9
4y ago

TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`

TensorFlow vulnerable to `CHECK` fail in `QuantizeAndDequantizeV3`

▾ Sunlittensorflow · tensorflowEPSS 0.48%via OSV
CVE-2022-35985Medium· 5.9
4y ago

TensorFlow vulnerable to `CHECK` fail in `LRNGrad`

TensorFlow vulnerable to `CHECK` fail in `LRNGrad`

▾ Sunlittensorflow · tensorflowEPSS 0.48%via OSV
CVE-2022-35935Medium· 5.9
4y ago

TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation

TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation

▾ Sunlittensorflow · tensorflowEPSS 0.53%via OSV
CVE-2022-35963Medium· 5.9
4y ago

TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`

TensorFlow vulnerable to `CHECK` failures in `FractionalAvgPoolGrad`

▾ Sunlittensorflow · tensorflowEPSS 0.48%via OSV
CVE-2022-36013Medium· 5.9
4y ago

TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`

TensorFlow vulnerable to null-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef`

▾ Sunlittensorflow · tensorflowEPSS 0.70%via OSV
CVE-2022-36014Medium· 5.9
4y ago

TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`

TensorFlow vulnerable to null-dereference in `mlir::tfg::TFOp::nameAttr`

▾ Sunlittensorflow · tensorflowEPSS 0.72%via OSV
CVE-2022-36027Medium· 5.9
4y ago

TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions

TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions

▾ Sunlittensorflow · tensorflowEPSS 0.77%via OSV
CVE-2022-35973Medium· 5.9
4y ago

TensorFlow vulnerable to segfault in `QuantizedMatMul`

TensorFlow vulnerable to segfault in `QuantizedMatMul`

▾ Sunlittensorflow · tensorflowEPSS 0.51%via OSV
CVE-2022-35966Medium· 5.9
4y ago

TensorFlow vulnerable to segfault in `QuantizedAvgPool`

TensorFlow vulnerable to segfault in `QuantizedAvgPool`

▾ Sunlittensorflow · tensorflowEPSS 0.49%via OSV
CVE-2022-35972Medium· 5.9
4y ago

TensorFlow vulnerable to segfault in `QuantizedBiasAdd`

TensorFlow vulnerable to segfault in `QuantizedBiasAdd`

▾ Sunlittensorflow · tensorflowEPSS 0.49%via OSV
CVE-2022-35982Medium· 5.9
4y ago

TensorFlow vulnerable to segfault in `SparseBincount`

TensorFlow vulnerable to segfault in `SparseBincount`

▾ Sunlittensorflow · tensorflowEPSS 0.51%via OSV
CVE-2022-35999Medium· 5.9
4y ago

TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`

TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`

▾ Sunlittensorflow · tensorflowEPSS 0.48%via OSV
CVE-2022-35968Medium· 5.9
4y ago

TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`

TensorFlow vulnerable to `CHECK` fail in `AvgPoolGrad`

▾ Sunlittensorflow · tensorflowEPSS 0.48%via OSV
CVE-2022-37189High· 7.5
4y ago

MEI2Volpiano is vulnerable to XML External Entity (XXE), leading to a Denial of Service (DoS)

MEI2Volpiano is vulnerable to XML External Entity (XXE), leading to a Denial of Service (DoS)

▾ Twilightmei2volpiano · mei2volpianoEPSS 1.4%via OSV
CVE-2022-23451High· 8.1
4y ago

Barbican authorization flaw before v14.0.0

Barbican authorization flaw before v14.0.0

▾ Twilightbarbican · barbicanEPSS 1.3%via OSV
CVE-2022-38369High· 8.8
4y ago

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

▾ Twilightapache-iotdb · apache-iotdbEPSS 1.3%via OSV
CVE-2022-2806Medium· 5.5
4y ago

sosreport Exposure of Sensitive Information vulnerability

sosreport Exposure of Sensitive Information vulnerability

▾ Sunlitsosreport · sosreportEPSS 0.25%via OSV
CVE-2022-23452Medium· 4.9
4y ago

openstack-barbican Denial of Service vulnerability

openstack-barbican Denial of Service vulnerability

▾ Sunlitbarbican · barbicanEPSS 1.3%via OSV
CVE-2022-36046Medium· 5.3
4y ago

Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affecte…

Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CVE: Next.js version 12.2.3, Node.js version above v15.0.0 being used with strict `unhandl…

▾ Sunlitnextjs · nextjsEPSS 1.2%via OSV
CVE-2022-34668Critical· 9.8PoC
4y ago

NVFLARE unsafe deserialization due to Pickle

NVFLARE unsafe deserialization due to Pickle

▾ Abyssalnvflare · nvflareEPSS 11%via OSV
CVE-2022-25304High· 7.5
4y ago

Uncontrolled Resource Consumption in asyncua and opcua

Uncontrolled Resource Consumption in asyncua and opcua

▾ Twilightasyncua · asyncuaEPSS 1.3%via OSV
CVE-2022-1930Medium· 5.9
4y ago

Regular expression denial of service in eth-account

Regular expression denial of service in eth-account

▾ Sunliteth-account · eth-accountEPSS 0.89%via OSV
CVE-2022-38362High· 8.8
4y ago

Remote code execution in Apache Airflow Docker's Provider

Remote code execution in Apache Airflow Docker's Provider

▾ Twilightapache-airflow-providers-docker · apache-airflow-providers-dockerEPSS 1.9%via OSV
CVE-2022-2822Low· 3.7
4y ago

OctoPrint does not have rate limiting on the login page

OctoPrint does not have rate limiting on the login page

▾ Sunlitoctoprint · octoprintEPSS 0.85%via OSV
CVE-2021-32862Medium· 5.4
4y ago

nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths

nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths

▾ Sunlitnbconvert · nbconvertEPSS 1.4%via OSV
CVE-2022-35920High· 8.3
4y ago

sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs

sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs

▾ Twilightsanic · sanicEPSS 1.2%via OSV
CVE-2022-37394Low· 3.3
4y ago

OpenStack Nova Changing vnic_type breaks compute service restart

OpenStack Nova Changing vnic_type breaks compute service restart

▾ Sunlitnova · novaEPSS 0.31%via OSV
CVE-2022-34558Critical· 9.8
4y ago

WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execut…

WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.

▾ Midnightglobal-workqueue · global-workqueueEPSS 1.3%via OSV
CVE-2022-2514Medium· 6.1
4y ago

Fava time and filter parameters vulnerable to reflected Cross-site Scripting

Fava time and filter parameters vulnerable to reflected Cross-site Scripting

▾ Sunlitfava · favaEPSS 0.85%via OSV
CVE-2022-24294High· 7.5
4y ago

Apache MXNet vulnerable to potential denial-of-service by excessive resource consumption

Apache MXNet vulnerable to potential denial-of-service by excessive resource consumption

▾ Twilightmxnet · mxnetEPSS 1.8%via OSV
CVEs tagged “pip” — page 130 · VulnSea