VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-13731None
1mo ago

Malicious code in morpho-sdk (PyPI)

Malicious code in morpho-sdk (PyPI)

▾ Sunlitmorpho-sdk · morpho-sdkvia OSV
MAL-2026-13730None
1mo ago

Malicious code in euler-sdk (PyPI)

Malicious code in euler-sdk (PyPI)

▾ Sunliteuler-sdk · euler-sdkvia OSV
MAL-2026-13729None
1mo ago

Malicious code in dlmm-sdk (PyPI)

Malicious code in dlmm-sdk (PyPI)

▾ Sunlitdlmm-sdk · dlmm-sdkvia OSV
MAL-2026-13728None
1mo ago

Malicious code in dlmm (PyPI)

Malicious code in dlmm (PyPI)

▾ Sunlitdlmm · dlmmvia OSV
CVE-2026-48809High· 7.5
1mo ago

python-engineio is a Python implementation of the Engine.IO realtime client and server

python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before …

▾ Twilightpython-engineio · python-engineioEPSS 0.49%via NVD
CVE-2026-48802High· 7.5
1mo ago

python-engineio is a Python implementation of the Engine.IO realtime client and server

python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbe…

▾ Twilightpython-engineio · python-engineioEPSS 0.57%via NVD
CVE-2026-48804High· 7.5
1mo ago

python-socketio is a Python implementation of the Socket.IO realtime client and server

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attach…

▾ Twilightpython-socketio · python-socketioEPSS 0.49%via NVD
CVE-2026-48813LowPoC
1mo ago

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Inj…

▾ Twilightflawfinder · flawfinderEPSS 0.44%via NVD
CVE-2026-69112High· 7.1
1mo ago

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can…

▾ Twilightaccelerate · accelerateEPSS 0.19%via NVD
CVE-2026-68871Medium· 6.5
1mo ago

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with thi…

▾ Sunlitapache · apache-airflow-providers-apache-yandexEPSS 0.60%via NVD
CVE-2026-68872Medium· 6.5
1mo ago

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deploymen…

▾ Sunlitapache · apache-airflow-providers-amazonEPSS 0.60%via NVD
MAL-2026-13712None
1mo ago

Malicious code in bigtime (PyPI)

Malicious code in bigtime (PyPI)

▾ Sunlitbigtime · bigtimevia OSV
MAL-2026-13711None
1mo ago

Malicious code in plp-contract (PyPI)

Malicious code in plp-contract (PyPI)

▾ Sunlitplp-contract · plp-contractvia OSV
MAL-2026-13710None
1mo ago

Malicious code in neutrl-core (PyPI)

Malicious code in neutrl-core (PyPI)

▾ Sunlitneutrl-core · neutrl-corevia OSV
MAL-2026-13709None
1mo ago

Malicious code in neutrl-contracts (PyPI)

Malicious code in neutrl-contracts (PyPI)

▾ Sunlitneutrl-contracts · neutrl-contractsvia OSV
MAL-2026-13686None
1mo ago

Malicious code in chaintest (PyPI)

Malicious code in chaintest (PyPI)

▾ Sunlitchaintest · chaintestvia OSV
MAL-2026-13685None
1mo ago

Malicious code in pytablute (PyPI)

Malicious code in pytablute (PyPI)

▾ Sunlitpytablute · pytablutevia OSV
MAL-2026-13683None
1mo ago

Malicious code in kotoraka (PyPI)

Malicious code in kotoraka (PyPI)

▾ Sunlitkotoraka · kotorakavia OSV
MAL-2026-13682None
1mo ago

Malicious code in btcflx (PyPI)

Malicious code in btcflx (PyPI)

▾ Sunlitbtcflx · btcflxvia OSV
MAL-2026-13681None
1mo ago

Malicious code in btcflip (PyPI)

Malicious code in btcflip (PyPI)

▾ Sunlitbtcflip · btcflipvia OSV
CVE-2026-12570Medium· 5.5
1mo ago

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving…

▾ Sunlitkeras · kerasEPSS 0.13%via NVD
MAL-2026-13667None
1mo ago

Malicious code in kotanku (PyPI)

Malicious code in kotanku (PyPI)

▾ Sunlitkotanku · kotankuvia OSV
CVE-2026-12372Low· 3.7
1mo ago

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, f…

▾ Sunlitnltk · nltkEPSS 0.31%via NVD
MAL-2026-13666None
1mo ago

Malicious code in cubesat-upstream-driver (PyPI)

Malicious code in cubesat-upstream-driver (PyPI)

▾ Sunlitcubesat-upstream-driver · cubesat-upstream-drivervia OSV
MAL-2026-13665None
1mo ago

Malicious code in riakcs (PyPI)

Malicious code in riakcs (PyPI)

▾ Sunlitriakcs · riakcsvia OSV
CVE-2026-76217Medium· 6.5
1mo ago

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

▾ Sunlitgitpython · gitpythonEPSS 0.41%via OSV
CVE-2026-71870Medium
1mo ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a fo…

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
MAL-2026-13619None
1mo ago

Malicious code in atlas-internal (PyPI)

Malicious code in atlas-internal (PyPI)

▾ Sunlitatlas-internal · atlas-internalvia OSV
MAL-2026-13607None
1mo ago

Malicious code in speed-hashes (PyPI)

Malicious code in speed-hashes (PyPI)

▾ Sunlitspeed-hashes · speed-hashesvia OSV
MAL-2026-13606None
1mo ago

Malicious code in cdktn-provider-azurerm (PyPI)

Malicious code in cdktn-provider-azurerm (PyPI)

▾ Sunlitcdktn-provider-azurerm · cdktn-provider-azurermvia OSV
CVEs tagged “pip” — page 22 · VulnSea