VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4682 CVEsRSS

CVE-2019-16785High· 7.1
6y ago

HTTP Request Smuggling: LF vs CRLF handling in Waitress

HTTP Request Smuggling: LF vs CRLF handling in Waitress

▾ Twilightwaitress · waitressEPSS 2.5%via OSV
CVE-2019-16786High· 7.1
6y ago

HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress

HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress

▾ Twilightwaitress · waitressEPSS 2.4%via OSV
CVE-2019-16792Critical
6y ago

HTTP Request Smuggling: Content-Length Sent Twice in Waitress

HTTP Request Smuggling: Content-Length Sent Twice in Waitress

▾ Midnightwaitress · waitressEPSS 2.0%via OSV
CVE-2019-16778Low· 2.6
6y ago

Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow

Heap buffer overflow in `UnsortedSegmentSum` in TensorFlow

▾ Sunlittensorflow · tensorflowEPSS 0.79%via OSV
CVE-2019-16766High· 8.7
6y ago

2FA bypass in Wagtail through new device path

2FA bypass in Wagtail through new device path

▾ Twilightwagtail-2fa · wagtail-2faEPSS 1.5%via OSV
CVE-2019-12417Medium· 4.8
6y ago

Apache Airflow vulnerable to XSS and local file disclosure

Apache Airflow vulnerable to XSS and local file disclosure

▾ Sunlitairflow · airflowEPSS 1.3%via OSV
CVE-2017-18638High· 7.5PoC
6y ago

graphite.composer.views.send_email vulnerable to SSRF

graphite.composer.views.send_email vulnerable to SSRF

▾ Midnightgraphite-web · graphite-webEPSS 15%via OSV
CVE-2019-10751High· 8.8
7y ago

Open Redirect in httpie

Open Redirect in httpie

▾ Twilighthttpie · httpieEPSS 2.0%via OSV
CVE-2019-1020003Medium· 5.4
7y ago

Cross-site scripting invenio-records

Cross-site scripting invenio-records

▾ Sunlitinvenio-records · invenio-recordsEPSS 0.66%via OSV
CVE-2019-1020005Medium· 5.4
7y ago

Cross-site Scripting in invenio-communities

Cross-site Scripting in invenio-communities

▾ Sunlitinvenio-communities · invenio-communitiesEPSS 0.68%via OSV
CVE-2019-1020019Medium· 6.1
7y ago

Cross-site Scripting in invenio-previewer

Cross-site Scripting in invenio-previewer

▾ Sunlitinvenio-previewer · invenio-previewerEPSS 0.90%via OSV
CVE-2019-1020006Medium· 6.1
7y ago

Invenio-App vulnerable to host header injection attack

Invenio-App vulnerable to host header injection attack

▾ Sunlitinvenio-app · invenio-appEPSS 0.93%via OSV
CVE-2019-16791Medium· 6.9
7y ago

postfix-mta-sts-resolver Algorithm Downgrade vulnerability

postfix-mta-sts-resolver Algorithm Downgrade vulnerability

▾ Sunlitpostfix-mta-sts-resolver · postfix-mta-sts-resolverEPSS 0.78%via OSV
CVE-2019-13177Critical· 9.8
7y ago

Improper Verification of Cryptographic Signature in django-rest-registration

Improper Verification of Cryptographic Signature in django-rest-registration

▾ Midnightdjango-rest-registration · django-rest-registrationEPSS 1.6%via OSV
CVE-2019-10255Medium· 6.1
7y ago

Open Redirect vulnerability in jupyterhub and notebook

Open Redirect vulnerability in jupyterhub and notebook

▾ Sunlitnotebook · notebookEPSS 1.8%via OSV
CVE-2018-13796Medium· 6.5
8y ago

Moderate severity vulnerability that affects mailman

Moderate severity vulnerability that affects mailman

▾ Sunlitmailman · mailmanEPSS 2.5%via OSV
CVE-2011-1948Medium· 6.1
8y ago

Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool

Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool

▾ Sunlitproducts-passwordresettool · products-passwordresettoolEPSS 2.4%via OSV
CVE-2011-1950Medium· 6.5⚠ Exploited
8y ago

Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts

Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts

▾ Twilightplone-app-users · plone-app-usersEPSS 2.3%via OSV
CVE-2010-1104Medium
8y ago

Moderate severity vulnerability that affects Zope2

Moderate severity vulnerability that affects Zope2

▾ Sunlitzope2 · zope2EPSS 2.0%via OSV
CVE-2009-0662Medium
8y ago

Moderate severity vulnerability that affects Products.PlonePAS

Moderate severity vulnerability that affects Products.PlonePAS

▾ Sunlitproducts-plonepas · products-plonepasEPSS 0.97%via OSV
CVE-2011-2528High
8y ago

High severity vulnerability that affects Plone and Zope2

High severity vulnerability that affects Plone and Zope2

▾ Twilightplone · ploneEPSS 2.0%via OSV
CVE-2017-2673High· 7.2
8y ago

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated fe…

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles…

▾ Twilightkeystone · keystoneEPSS 2.1%via OSV
CVE-2018-1000164High· 7.5
8y ago

Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers

Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers

▾ Twilightgunicorn · gunicornEPSS 2.4%via OSV
CVE-2018-1000516Medium· 6.1
8y ago

The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in …

The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Many templates used in the Galaxy server did not properly sanitize user's input, which would allow f…

▾ Sunlitgalaxy-app · galaxy-appEPSS 1.1%via OSV
CVE-2016-6903Critical· 9.9
9y ago

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.

▾ Midnightlimited-shell · limited-shellEPSS 5.0%via OSV
CVE-2016-6902Critical· 9.9
9y ago

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.

▾ Midnightlimited-shell · limited-shellEPSS 5.1%via OSV
CVE-2017-7200Medium· 5.8
9y ago

An SSRF issue was discovered in OpenStack Glance before Newton

An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'ht…

▾ Sunlitopenstack · glanceEPSS 2.1%via NVD
CVE-2015-1881None
11y ago

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …

▾ Sunlitglance · glanceEPSS 2.1%via OSV
CVE-2014-9684None
11y ago

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …

▾ Sunlitglance · glanceEPSS 2.0%via OSV
CVE-2014-0006None
12y ago

The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers …

The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.

▾ Sunlitswift · swiftEPSS 1.9%via OSV
CVEs tagged “pip” — page 156 · VulnSea