VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4636 CVEsRSS

CVE-2022-46291High· 7.8
2mo ago

Open Babel has out-of-bounds write in Gaussian translationVectors[]

Open Babel has out-of-bounds write in Gaussian translationVectors[]

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-46293High· 7.8
2mo ago

Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)

Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)

▾ Twilightopenbabel · openbabelEPSS 0.85%via GHSA
CVE-2022-46294High· 7.8
2mo ago

Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)

Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)

▾ Twilightopenbabel · openbabelEPSS 0.85%via GHSA
CVE-2022-46295High· 7.8
2mo ago

Open Babel has out-of-bounds write in MSI translationVectors[]

Open Babel has out-of-bounds write in MSI translationVectors[]

▾ Twilightopenbabel · openbabelEPSS 0.85%via GHSA
CVE-2026-12243High· 7.5PoC
3mo ago

nltk: NLTK: Information disclosure via path traversal vulnerability (CVE-2026-12243)

A flaw was found in NLTK. An attacker can exploit a path traversal vulnerability by providing specially crafted input to `nltk.data.load()` or `nltk.data.find()`. This allows the attacker to read arbitrary files accessible to the Python pr…

▾ MidnightRed Hat · Red Hat OpenShift AI 3.4via CSAF
CVE-2026-57585High· 7.5
3mo ago

msgpack: MessagePack for Python: Denial of Service via Unpacker reuse after error (CVE-2026-57585)

A flaw was found in MessagePack for Python, a serializer implementation. This vulnerability, categorized as a Use-After-Free (CWE-416), occurs when the Unpacker component is reused after an error. A remote attacker could exploit this by re…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.49%via CSAF
CVE-2025-10995Low· 7.8
3mo ago

Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow

Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow

▾ Sunlitopenbabel · openbabelEPSS 0.25%via GHSA
CVE-2025-10996High· 7.8
3mo ago

Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles

Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles

▾ Twilightopenbabel · openbabelEPSS 0.28%via GHSA
CVE-2026-2704Low· 4.4
3mo ago

Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString

Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString

▾ Sunlitopenbabel · openbabelEPSS 0.84%via GHSA
CVE-2026-2705Low· 5.5
3mo ago

Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge

Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge

▾ Sunlitopenbabel · openbabelEPSS 0.77%via GHSA
CVE-2026-3408Low· 5.5
3mo ago

Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence

Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence

▾ Sunlitopenbabel · openbabelEPSS 0.68%via GHSA
CVE-2025-10994Low· 7.8
3mo ago

Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule

Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule

▾ Sunlitopenbabel · openbabelEPSS 0.24%via GHSA
CVE-2026-27197Critical· 9.1
3mo ago

Sentry: Improper authentication on SAML SSO process allows user identity linking

Sentry: Improper authentication on SAML SSO process allows user identity linking

▾ Midnightsentry · sentryEPSS 0.58%via OSV
CVE-2020-7941Critical· 9.8
3mo ago

Plone Unauthenticated Write Vulnerability

Plone Unauthenticated Write Vulnerability

▾ Midnightplone-app-contenttypes · plone-app-contenttypesEPSS 2.3%via OSV
MAL-2026-6593None
3mo ago

Malicious code in django-bkvision (PyPI)

Malicious code in django-bkvision (PyPI)

▾ Sunlitdjango-bkvision · django-bkvisionvia OSV
MAL-2026-6561None
3mo ago

Malicious code in skillspector (PyPI)

Malicious code in skillspector (PyPI)

▾ Sunlitskillspector · skillspectorvia OSV
CVE-2026-49486High· 7.5
3mo ago

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment u…

▾ Twilightapache · apache-airflow-providers-ftpEPSS 0.44%via NVD
MAL-2026-6515None
3mo ago

Malicious code in sqligen (PyPI)

Malicious code in sqligen (PyPI)

▾ Sunlitsqligen · sqligenvia OSV
CVE-2026-48782Medium· 6.8
3mo ago

pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)

pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)

▾ Sunlitpydantic-ai-slim · pydantic-ai-slimEPSS 0.42%via GHSA
GHSA-72w7-mf9g-733pMedium· 6.4
3mo ago

nono-py has proxy-only network fallback bypass on older Linux kernels

nono-py has proxy-only network fallback bypass on older Linux kernels

▾ Sunlitnono-py · nono-pyvia GHSA
CVE-2026-48797Critical
3mo ago

Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

▾ Midnightbackpropagate · backpropagateEPSS 0.57%via OSV
GHSA-9j7f-3r4p-pwh6Medium· 5.2
3mo ago

nono-py vulnerable to authorization bypass / policy confusion

nono-py vulnerable to authorization bypass / policy confusion

▾ Sunlitnono-py · nono-pyvia GHSA
GHSA-m8j6-rc5x-wv36Medium· 5.2
3mo ago

nono-py's policy JSON accepts unknown security fields

nono-py's policy JSON accepts unknown security fields

▾ Sunlitnono-py · nono-pyvia GHSA
GHSA-98x5-vq43-vc5pCritical
3mo ago

semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin

semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin

▾ Midnightsemantic-router · semantic-routervia GHSA
CVE-2026-48990Medium· 5.3
3mo ago

joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization

joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization

▾ Sunlitjoserfc · joserfcEPSS 0.27%via OSV
GHSA-75mw-h36v-2jv7Medium· 6.1
3mo ago

Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers

Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers

▾ Sunlitdosage · dosagevia GHSA
CVE-2026-49291High· 8.1
3mo ago

mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call

mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call

▾ Twilightmcp-memory-service · mcp-memory-serviceEPSS 0.49%via GHSA
CVE-2026-49257Critical· 10.0
3mo ago

mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind

mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind

▾ Midnightmcp-pinot-server · mcp-pinot-serverEPSS 0.93%via GHSA
CVE-2026-77088Medium· 6.1
3mo ago

justhtml: to_markdown() code-span blank-line breakout enables XSS

justhtml: to_markdown() code-span blank-line breakout enables XSS

▾ Sunlitjusthtml · justhtmlEPSS 0.26%via OSV
GHSA-jf6w-2mvx-633jMedium· 6.1
3mo ago

justhtml: to_markdown() code-span blank-line breakout enables XSS

justhtml: to_markdown() code-span blank-line breakout enables XSS

▾ Sunlitjusthtml · justhtmlvia GHSA
CVEs tagged “pip” — page 39 · VulnSea