Tagged “pip”
CVEs tagged pip, newest first.
4682 CVEsRSS
CVE-2021-29586Low· 2.5Division by zero in optimized pooling implementations in TFLite
Division by zero in optimized pooling implementations in TFLite
CVE-2021-29590Low· 2.5Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`
Heap OOB read in TFLite's implementation of `Minimum` or `Maximum`
CVE-2021-29471Low· 3.7Denial of service attack via push rule patterns in matrix-synapse
Denial of service attack via push rule patterns in matrix-synapse
CVE-2021-29510Low· 3.3Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
CVE-2021-21419Medium· 5.3Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
CVE-2020-25032High· 7.5Flask-Cors Directory Traversal vulnerability
Flask-Cors Directory Traversal vulnerability
GHSA-qrmm-w4v4-q7f8HighUnauthorized access through URL manipulation
Unauthorized access through URL manipulation
CVE-2021-29434Medium· 6.1Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields
Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields
CVE-2021-29421High· 7.5Improper Restriction of XML External Entity Reference in pikepdf
Improper Restriction of XML External Entity Reference in pikepdf
CVE-2021-29430High· 7.5Sydent vulnerable to denial of service attack via memory exhaustion
Sydent vulnerable to denial of service attack via memory exhaustion
CVE-2021-29432Medium· 5.3Malicious users could abuse Sydent to control the content of invitation emails
Malicious users could abuse Sydent to control the content of invitation emails
CVE-2021-29431High· 7.7SSRF in Sydent due to missing validation of hostnames
SSRF in Sydent due to missing validation of hostnames
CVE-2021-29433Medium· 4.3Sydent DoS (via resource exhaustion) due to improper input validation
Sydent DoS (via resource exhaustion) due to improper input validation
CVE-2021-30459Critical· 9.8SQL Injection via in django-debug-toolbar
SQL Injection via in django-debug-toolbar
CVE-2021-21394Medium· 5.3Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
CVE-2021-21393Medium· 5.3Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
CVE-2021-21392Medium· 6.3Open redirect via transitional IPv6 addresses on dual-stack networks
Open redirect via transitional IPv6 addresses on dual-stack networks
CVE-2021-21431High· 7.6Improper Input Validation in sopel-plugins.channelmgnt
Improper Input Validation in sopel-plugins.channelmgnt
CVE-2020-28735High· 8.8SSRF attacks via tracebacks in Plone
SSRF attacks via tracebacks in Plone
CVE-2020-28734High· 8.8Improper Restriction of XML External Entity Reference in Plone
Improper Restriction of XML External Entity Reference in Plone
CVE-2020-28736High· 8.8Improper Restriction of XML External Entity Reference in Plone
Improper Restriction of XML External Entity Reference in Plone
CVE-2021-21416Low· 3.7Potential sensitive information disclosed in error reports
Potential sensitive information disclosed in error reports
CVE-2021-21333Medium· 6.1HTML injection in email and account expiry notifications
HTML injection in email and account expiry notifications
CVE-2021-21332Medium· 6.9Cross-site scripting (XSS) vulnerability in the password reset endpoint
Cross-site scripting (XSS) vulnerability in the password reset endpoint
CVE-2021-21376Medium· 6.4OMERO.web exposes some unnecessary session information in the page
OMERO.web exposes some unnecessary session information in the page
CVE-2021-21377Medium· 4.8OMERO webclient does not validate URL redirects on login or switching group.
OMERO webclient does not validate URL redirects on login or switching group.
CVE-2021-28363Medium· 6.5Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
CVE-2021-21371Medium· 5.0Execution of untrusted code through config file
Execution of untrusted code through config file
CVE-2021-21360Medium· 5.3Exposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetup
Exposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetup
CVE-2021-21336Medium· 6.5Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager
Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager