VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-7025None
2mo ago

Malicious code in tronsev (PyPI)

Malicious code in tronsev (PyPI)

▾ Sunlittronsev · tronsevvia OSV
MAL-2026-7023None
2mo ago

Malicious code in dbzy-tools (PyPI)

Malicious code in dbzy-tools (PyPI)

▾ Sunlitdbzy-tools · dbzy-toolsvia OSV
MAL-2026-6961None
2mo ago

Malicious code in waymo-waymax (PyPI)

Malicious code in waymo-waymax (PyPI)

▾ Sunlitwaymo-waymax · waymo-waymaxvia OSV
MAL-2026-6960None
2mo ago

Malicious code in pyqt6darktheme (PyPI)

Malicious code in pyqt6darktheme (PyPI)

▾ Sunlitpyqt6darktheme · pyqt6darkthemevia OSV
CVE-2026-49471High· 8.3
2mo ago

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

▾ Twilightserena-agent · serena-agentEPSS 0.37%via GHSA
GHSA-mxwc-wh95-pw4gMedium· 5.3
2mo ago

Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler

Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler

▾ Sunlittrapster · trapstervia GHSA
MAL-2026-7015None
2mo ago

Malicious code in turbom (PyPI)

Malicious code in turbom (PyPI)

▾ Sunlitturbom · turbomvia OSV
MAL-2026-7007None
2mo ago

Malicious code in manom (PyPI)

Malicious code in manom (PyPI)

▾ Sunlitmanom · manomvia OSV
MAL-2026-7006None
2mo ago

Malicious code in manik (PyPI)

Malicious code in manik (PyPI)

▾ Sunlitmanik · manikvia OSV
MAL-2026-6983None
2mo ago

Malicious code in tronpak (PyPI)

Malicious code in tronpak (PyPI)

▾ Sunlittronpak · tronpakvia OSV
MAL-2026-6979None
2mo ago

Malicious code in turbod (PyPI)

Malicious code in turbod (PyPI)

▾ Sunlitturbod · turbodvia OSV
MAL-2026-6978None
2mo ago

Malicious code in manin (PyPI)

Malicious code in manin (PyPI)

▾ Sunlitmanin · maninvia OSV
MAL-2026-6977None
2mo ago

Malicious code in rarcore (PyPI)

Malicious code in rarcore (PyPI)

▾ Sunlitrarcore · rarcorevia OSV
MAL-2026-6976None
2mo ago

Malicious code in py-slugify (PyPI)

Malicious code in py-slugify (PyPI)

▾ Sunlitpy-slugify · py-slugifyvia OSV
MAL-2026-6975None
2mo ago

Malicious code in oxntime (PyPI)

Malicious code in oxntime (PyPI)

▾ Sunlitoxntime · oxntimevia OSV
MAL-2026-6974None
2mo ago

Malicious code in tronhapy (PyPI)

Malicious code in tronhapy (PyPI)

▾ Sunlittronhapy · tronhapyvia OSV
MAL-2026-6971None
2mo ago

Malicious code in tronhap (PyPI)

Malicious code in tronhap (PyPI)

▾ Sunlittronhap · tronhapvia OSV
MAL-2026-6970None
2mo ago

Malicious code in jsonschemavalid (PyPI)

Malicious code in jsonschemavalid (PyPI)

▾ Sunlitjsonschemavalid · jsonschemavalidvia OSV
CVE-2026-48828Medium· 6.5
2mo ago

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …

▾ Sunlitapache · airflowEPSS 0.66%via NVD
CVE-2026-58473Critical· 9.1
2mo ago

Cognee allows non-superusers to overwrite global LLM configuration

Cognee allows non-superusers to overwrite global LLM configuration

▾ Midnightcognee · cogneeEPSS 0.51%via OSV
CVE-2026-53878Medium· 6.1
2mo ago

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

▾ Sunlitdjango · djangoEPSS 0.33%via OSV
CVE-2026-53877Medium· 4.8
2mo ago

Django: GDALRaster may over-read heap memory when constructed from bytes

Django: GDALRaster may over-read heap memory when constructed from bytes

▾ Sunlitdjango · djangoEPSS 0.44%via OSV
CVE-2026-48588Low· 3.1
2mo ago

Django: cache middleware may expose private responses when unrelated request cookies are present

Django: cache middleware may expose private responses when unrelated request cookies are present

▾ Sunlitdjango · djangoEPSS 0.43%via OSV
CVE-2026-49487Medium· 6.5
2mo ago

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, a…

▾ Sunlitapache · airflowEPSS 0.66%via NVD
CVE-2026-48892Medium· 6.5
2mo ago

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options wh…

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options wh…

▾ Sunlitapache · airflowEPSS 0.66%via NVD
CVE-2026-48891Medium· 4.3
2mo ago

A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of …

A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of …

▾ Sunlitapache · airflowEPSS 0.64%via NVD
CVE-2026-49296Medium· 6.5
2mo ago

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the en…

▾ Sunlitapache · airflowEPSS 0.60%via NVD
CVE-2026-33264Critical· 9.8
2mo ago

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler /…

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain…

▾ Midnightapache-airflow · apache-airflowEPSS 1.6%via OSV
MAL-2026-7467None
2mo ago

Malicious code in scanvia (PyPI)

Malicious code in scanvia (PyPI)

▾ Sunlitscanvia · scanviavia OSV
MAL-2026-7466None
2mo ago

Malicious code in scan-checker (PyPI)

Malicious code in scan-checker (PyPI)

▾ Sunlitscan-checker · scan-checkervia OSV
CVEs tagged “pip” — page 35 · VulnSea