Tagged “pip”
CVEs tagged pip, newest first.
4636 CVEsRSS
CVE-2022-46291High· 7.8Open Babel has out-of-bounds write in Gaussian translationVectors[]
Open Babel has out-of-bounds write in Gaussian translationVectors[]
CVE-2022-46293High· 7.8Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)
Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)
CVE-2022-46294High· 7.8Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)
Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)
CVE-2022-46295High· 7.8Open Babel has out-of-bounds write in MSI translationVectors[]
Open Babel has out-of-bounds write in MSI translationVectors[]
CVE-2026-12243High· 7.5PoCnltk: NLTK: Information disclosure via path traversal vulnerability (CVE-2026-12243)
A flaw was found in NLTK. An attacker can exploit a path traversal vulnerability by providing specially crafted input to `nltk.data.load()` or `nltk.data.find()`. This allows the attacker to read arbitrary files accessible to the Python pr…
CVE-2026-57585High· 7.5msgpack: MessagePack for Python: Denial of Service via Unpacker reuse after error (CVE-2026-57585)
A flaw was found in MessagePack for Python, a serializer implementation. This vulnerability, categorized as a Use-After-Free (CWE-416), occurs when the Unpacker component is reused after an error. A remote attacker could exploit this by re…
CVE-2025-10995Low· 7.8Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow
Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow
CVE-2025-10996High· 7.8Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles
Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles
CVE-2026-2704Low· 4.4Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString
Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString
CVE-2026-2705Low· 5.5Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
CVE-2026-3408Low· 5.5Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence
Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence
CVE-2025-10994Low· 7.8Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule
Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule
CVE-2026-27197Critical· 9.1Sentry: Improper authentication on SAML SSO process allows user identity linking
Sentry: Improper authentication on SAML SSO process allows user identity linking
CVE-2020-7941Critical· 9.8Plone Unauthenticated Write Vulnerability
Plone Unauthenticated Write Vulnerability
MAL-2026-6593NoneMalicious code in django-bkvision (PyPI)
Malicious code in django-bkvision (PyPI)
MAL-2026-6561NoneMalicious code in skillspector (PyPI)
Malicious code in skillspector (PyPI)
CVE-2026-49486High· 7.5The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext
The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment u…
MAL-2026-6515NoneMalicious code in sqligen (PyPI)
Malicious code in sqligen (PyPI)
CVE-2026-48782Medium· 6.8pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
GHSA-72w7-mf9g-733pMedium· 6.4nono-py has proxy-only network fallback bypass on older Linux kernels
nono-py has proxy-only network fallback bypass on older Linux kernels
CVE-2026-48797CriticalBackpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
GHSA-9j7f-3r4p-pwh6Medium· 5.2nono-py vulnerable to authorization bypass / policy confusion
nono-py vulnerable to authorization bypass / policy confusion
GHSA-m8j6-rc5x-wv36Medium· 5.2nono-py's policy JSON accepts unknown security fields
nono-py's policy JSON accepts unknown security fields
GHSA-98x5-vq43-vc5pCriticalsemantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin
semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin
CVE-2026-48990Medium· 5.3joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
GHSA-75mw-h36v-2jv7Medium· 6.1Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
CVE-2026-49291High· 8.1mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call
mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call
CVE-2026-49257Critical· 10.0mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
CVE-2026-77088Medium· 6.1justhtml: to_markdown() code-span blank-line breakout enables XSS
justhtml: to_markdown() code-span blank-line breakout enables XSS
GHSA-jf6w-2mvx-633jMedium· 6.1justhtml: to_markdown() code-span blank-line breakout enables XSS
justhtml: to_markdown() code-span blank-line breakout enables XSS