VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4669 CVEsRSS

CVE-2021-32849High· 8.8PoC
4y ago

An authenticated user can execute arbitrary command in Gerapy

An authenticated user can execute arbitrary command in Gerapy

▾ Midnightgerapy · gerapyEPSS 7.6%via OSV
CVE-2021-43837High· 8.4
4y ago

vault-cli contains possible RCE when reading user-defined data

vault-cli contains possible RCE when reading user-defined data

▾ Twilightvault-cli · vault-cliEPSS 5.0%via OSV
CVE-2021-43818High· 8.2
4y ago

lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through

lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through

▾ Twilightlxml · lxmlEPSS 2.5%via OSV
CVE-2021-37941High· 7.8
4y ago

APM Java Agent Local Privilege Escalation

APM Java Agent Local Privilege Escalation

▾ Twilightelastic-apm · elastic-apmEPSS 0.21%via OSV
CVE-2021-41265High· 8.1
4y ago

Improper Authentication in Flask-AppBuilder

Improper Authentication in Flask-AppBuilder

▾ Twilightflask-appbuilder · flask-appbuilderEPSS 1.3%via OSV
CVE-2021-43811High· 7.8PoC
4y ago

Code injection via unsafe YAML loading

Code injection via unsafe YAML loading

▾ Midnightsockeye · sockeyeEPSS 2.4%via OSV
CVE-2021-43781Medium· 6.4
4y ago

Permissions not properly checked in Invenio-Drafts-Resources

Permissions not properly checked in Invenio-Drafts-Resources

▾ Sunlitinvenio-drafts-resources · invenio-drafts-resourcesEPSS 0.68%via OSV
CVE-2019-14867High· 8.8
4y ago

Code injection in FreeIPA

Code injection in FreeIPA

▾ Twilightipa · ipaEPSS 7.4%via OSV
CVE-2021-44227High· 8.0
4y ago

mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover (CVE-2021-44227)

A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right type of user when performing admin operations and a token created by a regular user can be use…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v. 8.2)EPSS 0.76%via CSAF
CVE-2021-43775High· 8.6
4y ago

Arbitrary file reading vulnerability in Aim

Arbitrary file reading vulnerability in Aim

▾ Twilightaim · aimEPSS 1.9%via OSV
CVE-2021-41281High· 7.5
4y ago

Path traversal in Matrix Synapse

Path traversal in Matrix Synapse

▾ Twilightmatrix-synapse · matrix-synapseEPSS 1.6%via OSV
CVE-2021-41867Medium
4y ago

Information disclosure vulnerability in OnionShare

Information disclosure vulnerability in OnionShare

▾ Sunlitonionshare-cli · onionshare-cliEPSS 1.8%via OSV
CVE-2021-41202Medium· 5.5
4y ago

Overflow/crash in `tf.range`

Overflow/crash in `tf.range`

▾ Sunlittensorflow · tensorflowEPSS 0.21%via OSV
CVE-2021-41215Medium· 5.5
4y ago

Null pointer exception in `DeserializeSparse`

Null pointer exception in `DeserializeSparse`

▾ Sunlittensorflow · tensorflowEPSS 0.19%via OSV
CVE-2021-41214High· 7.8
4y ago

Reference binding to `nullptr` in `tf.ragged.cross`

Reference binding to `nullptr` in `tf.ragged.cross`

▾ Twilighttensorflow · tensorflowEPSS 0.22%via OSV
CVE-2021-41224High· 7.1
4y ago

`SparseFillEmptyRows` heap OOB

`SparseFillEmptyRows` heap OOB

▾ Twilighttensorflow · tensorflowEPSS 0.21%via OSV
CVE-2021-41197Medium· 5.5
4y ago

Crashes due to overflow and `CHECK`-fail in ops with large tensor shapes

Crashes due to overflow and `CHECK`-fail in ops with large tensor shapes

▾ Sunlittensorflow · tensorflowEPSS 0.32%via OSV
CVE-2021-41206High· 7.0
4y ago

Incomplete validation of shapes in multiple TF ops

Incomplete validation of shapes in multiple TF ops

▾ Twilighttensorflow · tensorflowEPSS 0.18%via OSV
CVE-2021-41196Medium· 5.5
4y ago

Crash in `max_pool3d` when size argument is 0 or negative

Crash in `max_pool3d` when size argument is 0 or negative

▾ Sunlittensorflow · tensorflowEPSS 0.24%via OSV
CVE-2021-41210High· 7.1
4y ago

Heap OOB read in `tf.raw_ops.SparseCountSparseOutput`

Heap OOB read in `tf.raw_ops.SparseCountSparseOutput`

▾ Twilighttensorflow · tensorflowEPSS 0.15%via OSV
CVE-2021-41227Medium· 6.6
4y ago

Arbitrary memory read in `ImmutableConst`

Arbitrary memory read in `ImmutableConst`

▾ Sunlittensorflow · tensorflowEPSS 0.24%via OSV
CVE-2021-41201High· 7.8
4y ago

Unitialized access in `EinsumHelper::ParseEquation`

Unitialized access in `EinsumHelper::ParseEquation`

▾ Twilighttensorflow · tensorflowEPSS 0.25%via OSV
CVE-2021-41213Medium· 5.5
4y ago

Deadlock in mutually recursive `tf.function` objects

Deadlock in mutually recursive `tf.function` objects

▾ Sunlittensorflow · tensorflowEPSS 0.24%via OSV
CVE-2021-41220High· 7.8
4y ago

Use after free / memory leak in `CollectiveReduceV2`

Use after free / memory leak in `CollectiveReduceV2`

▾ Twilighttensorflow · tensorflowEPSS 0.21%via OSV
CVE-2021-41200Medium· 5.5
4y ago

Incomplete validation in `tf.summary.create_file_writer`

Incomplete validation in `tf.summary.create_file_writer`

▾ Sunlittensorflow · tensorflowEPSS 0.24%via OSV
CVE-2021-41212High· 7.1
4y ago

Heap OOB read in `tf.ragged.cross`

Heap OOB read in `tf.ragged.cross`

▾ Twilighttensorflow · tensorflowEPSS 0.21%via OSV
CVE-2021-41223High· 7.1
4y ago

Heap OOB in `FusedBatchNorm` kernels

Heap OOB in `FusedBatchNorm` kernels

▾ Twilighttensorflow · tensorflowEPSS 0.21%via OSV
CVE-2021-41211High· 7.1
4y ago

Heap OOB in shape inference for `QuantizeV2`

Heap OOB in shape inference for `QuantizeV2`

▾ Twilighttensorflow · tensorflowEPSS 0.21%via OSV
CVE-2021-41221High· 7.8
4y ago

Access to invalid memory during shape inference in `Cudnn*` ops

Access to invalid memory during shape inference in `Cudnn*` ops

▾ Twilighttensorflow · tensorflowEPSS 0.22%via OSV
CVE-2021-41195Medium· 5.5
4y ago

Crash in `tf.math.segment_*` operations

Crash in `tf.math.segment_*` operations

▾ Sunlittensorflow · tensorflowEPSS 0.21%via OSV
CVEs tagged “pip” — page 142 · VulnSea