Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
MAL-2026-6749NoneMalicious code in ipa-user-collector (PyPI)
Malicious code in ipa-user-collector (PyPI)
MAL-2026-6748NoneMalicious code in haproxy-config-client (PyPI)
Malicious code in haproxy-config-client (PyPI)
CVE-2026-8147High· 8.1MLflow: trace API endpoints lack proper authorization validators
MLflow: trace API endpoints lack proper authorization validators
MAL-2026-6736NoneMalicious code in unreal-mladapter (PyPI)
Malicious code in unreal-mladapter (PyPI)
MAL-2026-6735NoneMalicious code in ue-python-tools (PyPI)
Malicious code in ue-python-tools (PyPI)
MAL-2026-6734NoneMalicious code in horde-python-client (PyPI)
Malicious code in horde-python-client (PyPI)
MAL-2026-6733NoneMalicious code in epic-build-scripts (PyPI)
Malicious code in epic-build-scripts (PyPI)
MAL-2026-6728NoneMalicious code in dt-validator (PyPI)
Malicious code in dt-validator (PyPI)
CVE-2026-52830Critical· 9.4fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
CVE-2026-49852Highjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
CVE-2026-50180HighLangroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
CVE-2026-50181High· 7.1PoCLangroid: Path traversal in the file tools allows read/write outside configured current directory
Langroid: Path traversal in the file tools allows read/write outside configured current directory
CVE-2026-12480Medium· 5.5Keras: HDF5 virtual datasets can disclose local files
Keras: HDF5 virtual datasets can disclose local files
CVE-2026-57516High· 8.8PoCRay < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader
Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_dec…
CVE-2026-49119NoneGradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticat…
Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory…
MAL-2026-6724Critical⚠ ExploitedMalicious code in starlette-healthcheck (PyPI)
Malicious code in starlette-healthcheck (PyPI)
MAL-2026-6711NoneMalicious code in twrap-tool (PyPI)
Malicious code in twrap-tool (PyPI)
CVE-2025-10997High· 7.8Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies
Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies
CVE-2025-10998Low· 5.5Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines
Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines
CVE-2025-10999Medium· 5.5Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt
Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt
CVE-2025-11000Medium· 4.4Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)
Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)
CVE-2022-37331High· 7.8Open Babel has out-of-bounds write in Gaussian coords_type orientation parser
Open Babel has out-of-bounds write in Gaussian coords_type orientation parser
CVE-2022-41793High· 7.8Open Babel has out-of-bounds write in CSR PadString (title field)
Open Babel has out-of-bounds write in CSR PadString (title field)
CVE-2022-42885High· 7.8Open Babel has uninitialized pointer dereference in GRO residue parser
Open Babel has uninitialized pointer dereference in GRO residue parser
CVE-2022-43467High· 7.8Open Babel has out-of-bounds write in PQS coord_file parser
Open Babel has out-of-bounds write in PQS coord_file parser
CVE-2022-43607High· 7.8Open Babel has out-of-bounds write in MOL2 attribute/value parser
Open Babel has out-of-bounds write in MOL2 attribute/value parser
CVE-2022-44451High· 7.8Open Babel has uninitialized pointer dereference in MSI atom parser
Open Babel has uninitialized pointer dereference in MSI atom parser
CVE-2022-46280High· 7.8Open Babel has uninitialized pointer dereference in PQS pFormat
Open Babel has uninitialized pointer dereference in PQS pFormat
CVE-2022-46289High· 7.8Open Babel has out-of-bounds write in ORCA nAtoms parser
Open Babel has out-of-bounds write in ORCA nAtoms parser
CVE-2022-46290High· 7.8Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)
Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)