VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-14274None
1mo ago

Malicious code in reqcrypt-dev (PyPI)

Malicious code in reqcrypt-dev (PyPI)

▾ Sunlitreqcrypt-dev · reqcrypt-devvia OSV
MAL-2026-14158None
1mo ago

Malicious code in deepface-weight (PyPI)

Malicious code in deepface-weight (PyPI)

▾ Sunlitdeepface-weight · deepface-weightvia OSV
MAL-2026-14133None
1mo ago

Malicious code in reqcrypt (PyPI)

Malicious code in reqcrypt (PyPI)

▾ Sunlitreqcrypt · reqcryptvia OSV
MAL-2026-14132None
1mo ago

Malicious code in deepface-weights (PyPI)

Malicious code in deepface-weights (PyPI)

▾ Sunlitdeepface-weights · deepface-weightsvia OSV
MAL-2026-14131None
1mo ago

Malicious code in infogram-bot (PyPI)

Malicious code in infogram-bot (PyPI)

▾ Sunlitinfogram-bot · infogram-botvia OSV
MAL-2026-14130None
1mo ago

Malicious code in httpz-requests (PyPI)

Malicious code in httpz-requests (PyPI)

▾ Sunlithttpz-requests · httpz-requestsvia OSV
GHSA-qxq5-qhx6-94qwHigh· 7.8
1mo ago

Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

▾ Twilightmonai · monaivia GHSA
GHSA-rghg-q7wp-9767High
1mo ago

MONAI vulnerable to OS command injection

MONAI vulnerable to OS command injection

▾ TwilightMONAI · MONAIvia GHSA
GHSA-wg9g-w2j2-8pgrHigh· 7.8
1mo ago

MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files

MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files

▾ Twilightmonai · monaivia GHSA
CVE-2026-70666High· 7.4
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/authorities/ without revalidation and direct setup_acme_client_no_retry to an attacker-controlled ACME server. ACME…

▾ Twilightlemur · lemurEPSS 0.22%via NVD
CVE-2026-70667Medium· 6.3
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the original CRL or OCSP URL but the later request could reach a different destination. The CRL requests.get call fo…

▾ Sunlitlemur · lemurEPSS 0.18%via NVD
CVE-2026-71303High· 7.7
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when an authority was created, but PUT /api/1/authorities/ passed options to lemur/authorities/service.py without applying …

▾ Twilightlemur · lemurEPSS 0.28%via NVD
CVE-2026-71307High· 7.7
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibling write handlers required admin_permission. DestinationOutputSchema returned raw optio…

▾ Twilightlemur · lemurEPSS 0.31%via NVD
CVE-2026-71308High· 8.1
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetch_objects without a Certific…

▾ Twilightlemur · lemurEPSS 0.32%via NVD
CVE-2026-71317Medium· 6.5
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent authority when ADMIN_ONLY_AUTHORITY_CREATION was false. AssociatedAuthoritySchema resolved …

▾ Sunlitlemur · lemurEPSS 0.10%via NVD
CVE-2026-71322Medium· 4.3
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check inside the plugin.requires_key branch for POST /api/1/certificates//export. A plugin declaring requires_key false …

▾ Sunlitlemur · lemurEPSS 0.23%via NVD
CVE-2026-71417High· 7.3
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using another certificate body, authority_id, serial, or external_id without requiring permiss…

▾ Twilightlemur · lemurEPSS 0.10%via NVD
CVE-2026-73974Medium· 5.5
1mo ago

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linux…

▾ Sunlitlinuxfabrik-lib · linuxfabrik-libEPSS 0.17%via NVD
CVE-2026-68924Medium· 4.9
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/views/common/shared_func.py logs that an archive member exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE is being skipped but do…

▾ Sunlitmobsf · mobsfEPSS 0.59%via NVD
CVE-2026-68927Low· 3.0
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only an Android manifest android:host value with valid_host before ap…

▾ Sunlitmobsf · mobsfEPSS 0.33%via NVD
CVE-2026-68923Medium· 6.5
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middleware.csrf.CsrfViewMiddleware only in the deprecated MIDDLEWARE_CLASSES setting and omits it from the active MIDDLEWARE …

▾ Sunlitmobsf · mobsfEPSS 0.26%via NVD
CVE-2026-68922Medium· 5.5
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py uses the Android manifest android:icon value to construct paths under the scan resource d…

▾ Sunlitmobsf · mobsfEPSS 0.46%via NVD
CVE-2026-70657Medium· 4.3
1mo ago

Copyparty is a portable file server

Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the conta…

▾ Sunlitcopyparty · copypartyEPSS 0.33%via NVD
CVE-2026-63632Low· 3.3
1mo ago

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/vers…

▾ Sunlitonnx · onnxEPSS 0.17%via NVD
CVE-2026-54552High· 7.9
1mo ago

sh provides Python process launching

sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. When sh runs from an elevated process and launches a command with _uid set to an unprivi…

▾ Twilightsh · shEPSS 0.17%via NVD
CVE-2026-53533Medium
1mo ago

aiosmtplib is an asynchronous SMTP client for use with asyncio

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is…

▾ Sunlitaiosmtplib · aiosmtplibEPSS 0.53%via NVD
CVE-2026-55426High· 7.8
1mo ago

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases u…

▾ Twilightlinuxfabrik-lib · linuxfabrik-libEPSS 0.21%via NVD
CVE-2026-53759Low
1mo ago

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 4.2.0, db_sqlite.py created SQLite databases at predictable paths in the shared /tmp directory and followed att…

▾ Sunlitlinuxfabrik-lib · linuxfabrik-libEPSS 0.19%via NVD
CVE-2026-49452Medium· 6.5
1mo ago

WeasyPrint helps web developers to create PDF documents

WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background attribute…

▾ Sunlitweasyprint · weasyprintEPSS 0.37%via NVD
CVE-2026-52817High
1mo ago

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga account to execute /usr/bin/apt-get…

▾ Twilightlinuxfabrik-lib · linuxfabrik-libEPSS 0.18%via NVD
CVEs tagged “pip” — page 18 · VulnSea