VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4624 CVEsRSS

MAL-2026-16269Critical⚠ Exploited
1w ago

Malicious code in requests-asetwe (PyPI)

Malicious code in requests-asetwe (PyPI)

▾ Abyssalrequests-asetwe · requests-asetwevia OSV
MAL-2026-16268Critical⚠ Exploited
1w ago

Malicious code in index-forum (PyPI)

Malicious code in index-forum (PyPI)

▾ Abyssalindex-forum · index-forumvia OSV
MAL-2026-16267Critical⚠ Exploited
1w ago

Malicious code in pyjstat-smooth (PyPI)

Malicious code in pyjstat-smooth (PyPI)

▾ Abyssalpyjstat-smooth · pyjstat-smoothvia OSV
MAL-2026-16264Critical⚠ Exploited
1w ago

Malicious code in aiosendletter (PyPI)

Malicious code in aiosendletter (PyPI)

▾ Abyssalaiosendletter · aiosendlettervia OSV
GHSA-xjw9-38cr-6372High
1w ago

djust: A template binding inherits a context safety grant it never earned (XSS)

djust: A template binding inherits a context safety grant it never earned (XSS)

▾ Twilightdjust · djustvia OSV
GHSA-9395-2g46-rj3fHigh
1w ago

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

▾ Twilightdjust · djustvia OSV
CVE-2026-86049High· 7.1
1w ago

Jupyter Server is the backend for Jupyter web applications

Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for t…

▾ Twilightjupyter-server · jupyter_serverEPSS 0.42%via NVD
CVE-2026-86000Medium· 5.3PoC
1w ago

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and V…

▾ Twilightfacelessuser · soupsieveEPSS 0.61%via NVD
CVE-2026-85999Medium· 5.3PoC
1w ago

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used …

▾ Twilightfacelessuser · soupsieveEPSS 0.61%via NVD
MAL-2026-16250Critical⚠ Exploited
1w ago

Malicious code in marketing-mcp (PyPI)

Malicious code in marketing-mcp (PyPI)

▾ Abyssalmarketing-mcp · marketing-mcpvia OSV
CVE-2026-85078Medium· 6.5
1w ago

Sanic is an opensource python web server/framework

Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer.…

▾ Sunlitsanic-org · sanicEPSS 0.51%via NVD
CVE-2026-54446High· 8.1PoC
1w ago

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-ne…

▾ MidnightLabs64 · NetLicensing-MCPEPSS 0.62%via NVD
CVE-2026-49292Low· 0.0
1w ago

Kiwi TCMS is an open source test management system

Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migra…

▾ Sunlitkiwitcms · KiwiEPSS 0.44%via NVD
MAL-2026-16242Critical⚠ Exploited
1w ago

Malicious code in trongappy (PyPI)

Malicious code in trongappy (PyPI)

▾ Abyssaltrongappy · trongappyvia OSV
MAL-2026-16241Critical⚠ Exploited
1w ago

Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)

Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)

▾ Abyssalrak-lab-yoav-orca-zrktd2cp5hjmo4x7 · rak-lab-yoav-orca-zrktd2cp5hjmo4x7via OSV
MAL-2026-16240Critical⚠ Exploited
1w ago

Malicious code in praetorian-mind-rce-test-2026 (PyPI)

Malicious code in praetorian-mind-rce-test-2026 (PyPI)

▾ Abyssalpraetorian-mind-rce-test-2026 · praetorian-mind-rce-test-2026via OSV
CVE-2026-61599High· 8.8
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling …

▾ Twilightdjust-org · djustEPSS 0.60%via NVD
CVE-2026-61589Medium· 6.3
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFac…

▾ Sunlitdjust-org · djustEPSS 0.18%via NVD
CVE-2026-61597Medium· 5.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/use…

▾ Sunlitdjust-org · djustEPSS 0.41%via NVD
CVE-2026-61592High· 7.4
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated us…

▾ Twilightdjust-org · djustEPSS 0.39%via NVD
CVE-2026-61594Critical· 9.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()…

▾ Midnightdjust-org · djustEPSS 0.48%via NVD
CVE-2026-61591High· 8.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was res…

▾ Twilightdjust-org · djustEPSS 0.22%via NVD
CVE-2026-61588Medium· 6.5
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the clie…

▾ Sunlitdjust-org · djustEPSS 0.39%via NVD
CVE-2026-61596High· 7.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the…

▾ Twilightdjust-org · djustEPSS 0.33%via NVD
CVE-2026-62949Medium· 6.5
1w ago

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in a…

▾ Sunlitronf · asyncsshEPSS 0.55%via NVD
CVE-2026-59823Medium· 5.3
1w ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can place api_base inside the user_config request body to bypass is_req…

▾ SunlitBerriAI · litellmEPSS 0.44%via NVD
CVE-2026-69147Medium· 6.5PoC
1w ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards …

▾ Twilightvllm-project · vllmEPSS 0.55%via NVD
CVE-2026-57173Medium· 6.5
1w ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without passing VLLM_MAX_AUDIO_DECODE_DURA…

▾ Sunlitvllm-project · vllmEPSS 0.69%via NVD
MAL-2026-16219Critical⚠ Exploited
1w ago

Malicious code in licloud (PyPI)

Malicious code in licloud (PyPI)

▾ Abyssallicloud · licloudvia OSV
MAL-2026-16212Critical⚠ Exploited
1w ago

Malicious code in cli-anything-ai-market (PyPI)

Malicious code in cli-anything-ai-market (PyPI)

▾ Abyssalcli-anything-ai-market · cli-anything-ai-marketvia OSV
CVEs tagged “pip” — page 4 · VulnSea