VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-6749None
2mo ago

Malicious code in ipa-user-collector (PyPI)

Malicious code in ipa-user-collector (PyPI)

▾ Sunlitipa-user-collector · ipa-user-collectorvia OSV
MAL-2026-6748None
2mo ago

Malicious code in haproxy-config-client (PyPI)

Malicious code in haproxy-config-client (PyPI)

▾ Sunlithaproxy-config-client · haproxy-config-clientvia OSV
CVE-2026-8147High· 8.1
2mo ago

MLflow: trace API endpoints lack proper authorization validators

MLflow: trace API endpoints lack proper authorization validators

▾ Twilightmlflow · mlflowEPSS 0.55%via OSV
MAL-2026-6736None
2mo ago

Malicious code in unreal-mladapter (PyPI)

Malicious code in unreal-mladapter (PyPI)

▾ Sunlitunreal-mladapter · unreal-mladaptervia OSV
MAL-2026-6735None
2mo ago

Malicious code in ue-python-tools (PyPI)

Malicious code in ue-python-tools (PyPI)

▾ Sunlitue-python-tools · ue-python-toolsvia OSV
MAL-2026-6734None
2mo ago

Malicious code in horde-python-client (PyPI)

Malicious code in horde-python-client (PyPI)

▾ Sunlithorde-python-client · horde-python-clientvia OSV
MAL-2026-6733None
2mo ago

Malicious code in epic-build-scripts (PyPI)

Malicious code in epic-build-scripts (PyPI)

▾ Sunlitepic-build-scripts · epic-build-scriptsvia OSV
MAL-2026-6728None
2mo ago

Malicious code in dt-validator (PyPI)

Malicious code in dt-validator (PyPI)

▾ Sunlitdt-validator · dt-validatorvia OSV
CVE-2026-52830Critical· 9.4
2mo ago

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

▾ Midnightfast-mcp-telegram · fast-mcp-telegramEPSS 0.65%via GHSA
CVE-2026-49852High
2mo ago

joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)

joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)

▾ Twilightjoserfc · joserfcEPSS 0.19%via OSV
CVE-2026-50180High
2mo ago

Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read

Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read

▾ Twilightlangroid · langroidEPSS 0.69%via GHSA
CVE-2026-50181High· 7.1PoC
2mo ago

Langroid: Path traversal in the file tools allows read/write outside configured current directory

Langroid: Path traversal in the file tools allows read/write outside configured current directory

▾ Midnightlangroid · langroidEPSS 0.18%via GHSA
CVE-2026-12480Medium· 5.5
2mo ago

Keras: HDF5 virtual datasets can disclose local files

Keras: HDF5 virtual datasets can disclose local files

▾ Sunlitkeras · kerasEPSS 0.18%via OSV
CVE-2026-57516High· 8.8PoC
2mo ago

Ray < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_dec…

▾ MidnightAnyscale, Inc · RayEPSS 0.86%via CVEORG
CVE-2026-49119None
2mo ago

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticat…

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory…

▾ Sunlitgradio · gradioEPSS 0.93%via OSV
MAL-2026-6724Critical⚠ Exploited
2mo ago

Malicious code in starlette-healthcheck (PyPI)

Malicious code in starlette-healthcheck (PyPI)

▾ Abyssalstarlette-healthcheck · starlette-healthcheckvia OSV
MAL-2026-6711None
2mo ago

Malicious code in twrap-tool (PyPI)

Malicious code in twrap-tool (PyPI)

▾ Sunlittwrap-tool · twrap-toolvia OSV
CVE-2025-10997High· 7.8
2mo ago

Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies

Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies

▾ Twilightopenbabel · openbabelEPSS 0.28%via GHSA
CVE-2025-10998Low· 5.5
2mo ago

Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines

Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines

▾ Sunlitopenbabel · openbabelEPSS 0.21%via GHSA
CVE-2025-10999Medium· 5.5
2mo ago

Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt

Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt

▾ Sunlitopenbabel · openbabelEPSS 0.25%via GHSA
CVE-2025-11000Medium· 4.4
2mo ago

Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)

Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)

▾ Sunlitopenbabel · openbabelEPSS 0.24%via GHSA
CVE-2022-37331High· 7.8
2mo ago

Open Babel has out-of-bounds write in Gaussian coords_type orientation parser

Open Babel has out-of-bounds write in Gaussian coords_type orientation parser

▾ Twilightopenbabel · openbabelEPSS 0.68%via GHSA
CVE-2022-41793High· 7.8
2mo ago

Open Babel has out-of-bounds write in CSR PadString (title field)

Open Babel has out-of-bounds write in CSR PadString (title field)

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-42885High· 7.8
2mo ago

Open Babel has uninitialized pointer dereference in GRO residue parser

Open Babel has uninitialized pointer dereference in GRO residue parser

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-43467High· 7.8
2mo ago

Open Babel has out-of-bounds write in PQS coord_file parser

Open Babel has out-of-bounds write in PQS coord_file parser

▾ Twilightopenbabel · openbabelEPSS 0.83%via GHSA
CVE-2022-43607High· 7.8
2mo ago

Open Babel has out-of-bounds write in MOL2 attribute/value parser

Open Babel has out-of-bounds write in MOL2 attribute/value parser

▾ Twilightopenbabel · openbabelEPSS 0.78%via GHSA
CVE-2022-44451High· 7.8
2mo ago

Open Babel has uninitialized pointer dereference in MSI atom parser

Open Babel has uninitialized pointer dereference in MSI atom parser

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-46280High· 7.8
2mo ago

Open Babel has uninitialized pointer dereference in PQS pFormat

Open Babel has uninitialized pointer dereference in PQS pFormat

▾ Twilightopenbabel · openbabelEPSS 0.83%via GHSA
CVE-2022-46289High· 7.8
2mo ago

Open Babel has out-of-bounds write in ORCA nAtoms parser

Open Babel has out-of-bounds write in ORCA nAtoms parser

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-46290High· 7.8
2mo ago

Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)

Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVEs tagged “pip” — page 38 · VulnSea