VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4682 CVEsRSS

CVE-2021-29586Low· 2.5
5y ago

Division by zero in optimized pooling implementations in TFLite

Division by zero in optimized pooling implementations in TFLite

▾ Sunlittensorflow · tensorflowEPSS 0.20%via OSV
CVE-2021-29590Low· 2.5
5y ago

Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`

Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`

▾ Sunlittensorflow · tensorflowEPSS 0.20%via OSV
CVE-2021-29471Low· 3.7
5y ago

Denial of service attack via push rule patterns in matrix-synapse

Denial of service attack via push rule patterns in matrix-synapse

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.6%via OSV
CVE-2021-29510Low· 3.3
5y ago

Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic

Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic

▾ Sunlitpydantic · pydanticEPSS 0.97%via OSV
CVE-2021-21419Medium· 5.3
5y ago

Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet

Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet

▾ Sunliteventlet · eventletEPSS 1.8%via OSV
CVE-2020-25032High· 7.5
5y ago

Flask-Cors Directory Traversal vulnerability

Flask-Cors Directory Traversal vulnerability

▾ Twilightflask-cors · flask-corsEPSS 4.0%via OSV
GHSA-qrmm-w4v4-q7f8High
5y ago

Unauthorized access through URL manipulation

Unauthorized access through URL manipulation

▾ Twilightdocassemble · docassemblevia OSV
CVE-2021-29434Medium· 6.1
5y ago

Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields

Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields

▾ Sunlitwagtail · wagtailEPSS 0.63%via OSV
CVE-2021-29421High· 7.5
5y ago

Improper Restriction of XML External Entity Reference in pikepdf

Improper Restriction of XML External Entity Reference in pikepdf

▾ Twilightpikepdf · pikepdfEPSS 1.7%via OSV
CVE-2021-29430High· 7.5
5y ago

Sydent vulnerable to denial of service attack via memory exhaustion

Sydent vulnerable to denial of service attack via memory exhaustion

▾ Twilightmatrix-sydent · matrix-sydentEPSS 1.8%via OSV
CVE-2021-29432Medium· 5.3
5y ago

Malicious users could abuse Sydent to control the content of invitation emails

Malicious users could abuse Sydent to control the content of invitation emails

▾ Sunlitmatrix-sydent · matrix-sydentEPSS 0.93%via OSV
CVE-2021-29431High· 7.7
5y ago

SSRF in Sydent due to missing validation of hostnames

SSRF in Sydent due to missing validation of hostnames

▾ Twilightmatrix-sydent · matrix-sydentEPSS 1.2%via OSV
CVE-2021-29433Medium· 4.3
5y ago

Sydent DoS (via resource exhaustion) due to improper input validation

Sydent DoS (via resource exhaustion) due to improper input validation

▾ Sunlitmatrix-sydent · matrix-sydentEPSS 0.93%via OSV
CVE-2021-30459Critical· 9.8
5y ago

SQL Injection via in django-debug-toolbar

SQL Injection via in django-debug-toolbar

▾ Midnightdjango-debug-toolbar · django-debug-toolbarEPSS 1.9%via OSV
CVE-2021-21394Medium· 5.3
5y ago

Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints

Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.5%via OSV
CVE-2021-21393Medium· 5.3
5y ago

Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints

Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.6%via OSV
CVE-2021-21392Medium· 6.3
5y ago

Open redirect via transitional IPv6 addresses on dual-stack networks

Open redirect via transitional IPv6 addresses on dual-stack networks

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.94%via OSV
CVE-2021-21431High· 7.6
5y ago

Improper Input Validation in sopel-plugins.channelmgnt

Improper Input Validation in sopel-plugins.channelmgnt

▾ Twilightsopel-plugins-channelmgnt · sopel-plugins-channelmgntEPSS 1.1%via OSV
CVE-2020-28735High· 8.8
5y ago

SSRF attacks via tracebacks in Plone

SSRF attacks via tracebacks in Plone

▾ Twilightplone · ploneEPSS 1.5%via OSV
CVE-2020-28734High· 8.8
5y ago

Improper Restriction of XML External Entity Reference in Plone

Improper Restriction of XML External Entity Reference in Plone

▾ Twilightplone · ploneEPSS 1.5%via OSV
CVE-2020-28736High· 8.8
5y ago

Improper Restriction of XML External Entity Reference in Plone

Improper Restriction of XML External Entity Reference in Plone

▾ Twilightplone · ploneEPSS 1.5%via OSV
CVE-2021-21416Low· 3.7
5y ago

Potential sensitive information disclosed in error reports

Potential sensitive information disclosed in error reports

▾ Sunlitdjango-registration · django-registrationEPSS 0.41%via OSV
CVE-2021-21333Medium· 6.1
5y ago

HTML injection in email and account expiry notifications

HTML injection in email and account expiry notifications

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.4%via OSV
CVE-2021-21332Medium· 6.9
5y ago

Cross-site scripting (XSS) vulnerability in the password reset endpoint

Cross-site scripting (XSS) vulnerability in the password reset endpoint

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.2%via OSV
CVE-2021-21376Medium· 6.4
5y ago

OMERO.web exposes some unnecessary session information in the page

OMERO.web exposes some unnecessary session information in the page

▾ Sunlitomero-web · omero-webEPSS 1.5%via OSV
CVE-2021-21377Medium· 4.8
5y ago

OMERO webclient does not validate URL redirects on login or switching group.

OMERO webclient does not validate URL redirects on login or switching group.

▾ Sunlitomero-web · omero-webEPSS 0.83%via OSV
CVE-2021-28363Medium· 6.5
5y ago

Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection

Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection

▾ Sunliturllib3 · urllib3EPSS 2.1%via OSV
CVE-2021-21371Medium· 5.0
5y ago

Execution of untrusted code through config file

Execution of untrusted code through config file

▾ Sunlittenable-jira-cloud · tenable-jira-cloudEPSS 0.45%via OSV
CVE-2021-21360Medium· 5.3
5y ago

Exposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetup

Exposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetup

▾ Sunlitproducts-genericsetup · products-genericsetupEPSS 1.5%via OSV
CVE-2021-21336Medium· 6.5
5y ago

Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager

Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager

▾ Sunlitproducts-pluggableauthservice · products-pluggableauthserviceEPSS 1.5%via OSV
CVEs tagged “pip” — page 152 · VulnSea