VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-5299None
3mo ago

Malicious code in pantheon-agents (PyPI)

Malicious code in pantheon-agents (PyPI)

▾ Sunlitpantheon-agents · pantheon-agentsvia OSV
MAL-2026-5285None
3mo ago

Malicious code in ufish (PyPI)

Malicious code in ufish (PyPI)

▾ Sunlitufish · ufishvia OSV
MAL-2026-5284None
3mo ago

Malicious code in synago (PyPI)

Malicious code in synago (PyPI)

▾ Sunlitsynago · synagovia OSV
MAL-2026-5283None
3mo ago

Malicious code in okite (PyPI)

Malicious code in okite (PyPI)

▾ Sunlitokite · okitevia OSV
MAL-2026-5279None
3mo ago

Malicious code in uprobe (PyPI)

Malicious code in uprobe (PyPI)

▾ Sunlituprobe · uprobevia OSV
MAL-2026-5277None
3mo ago

Malicious code in pantheon-toolsets (PyPI)

Malicious code in pantheon-toolsets (PyPI)

▾ Sunlitpantheon-toolsets · pantheon-toolsetsvia OSV
MAL-2026-5276None
3mo ago

Malicious code in nucbox (PyPI)

Malicious code in nucbox (PyPI)

▾ Sunlitnucbox · nucboxvia OSV
MAL-2026-5275None
3mo ago

Malicious code in napari-ufish (PyPI)

Malicious code in napari-ufish (PyPI)

▾ Sunlitnapari-ufish · napari-ufishvia OSV
CVE-2026-37737Medium· 6.5
3mo ago

sanic-cors contains an improper regular expression in the try_match() function

sanic-cors contains an improper regular expression in the try_match() function

▾ Sunlitsanic-cors · sanic-corsEPSS 0.24%via OSV
CVE-2026-50589Medium· 5.3
3mo ago

OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash

OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash

▾ Sunlitironic · ironicEPSS 0.74%via OSV
CVE-2026-11312Low· 3.3
3mo ago

bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV Map

bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV Map

▾ Sunlitinfinistore · infinistoreEPSS 0.11%via OSV
CVE-2026-47715Low· 3.1
3mo ago

Bugsink: Issue event views can show an event from another project if its UUID is known

Bugsink: Issue event views can show an event from another project if its UUID is known

▾ Sunlitbugsink · bugsinkEPSS 0.24%via OSV
CVE-2026-47716Low· 3.1
3mo ago

Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known

Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known

▾ Sunlitbugsink · bugsinkEPSS 0.23%via OSV
CVE-2026-47419High· 8.3
3mo ago

praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR

praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.39%via OSV
CVE-2024-24769Low
3mo ago

Vantage6: No limit on emails sent for password/MFA reset

Vantage6: No limit on emails sent for password/MFA reset

▾ Sunlitvantage6 · vantage6EPSS 0.28%via OSV
CVE-2026-47728Medium· 4.3
3mo ago

Bugsink: Project scoping missing in sourcemap and debug-file lookup

Bugsink: Project scoping missing in sourcemap and debug-file lookup

▾ Sunlitbugsink · bugsinkEPSS 0.28%via OSV
CVE-2024-27928Medium
3mo ago

Vantage6: 2FA can be circumvented with hacked email access

Vantage6: 2FA can be circumvented with hacked email access

▾ Sunlitvantage6 · vantage6EPSS 0.28%via OSV
CVE-2026-54533Medium
3mo ago

vantage6 node has an Improper Access Control issue

vantage6 node has an Improper Access Control issue

▾ Sunlitvantage6 · vantage6EPSS 0.50%via OSV
CVE-2026-54445Medium
3mo ago

Vantage6: Set admin user and password from environment or configuration

Vantage6: Set admin user and password from environment or configuration

▾ Sunlitvantage6 · vantage6EPSS 0.48%via OSV
MAL-2026-5273None
3mo ago

Malicious code in anthropy (PyPI)

Malicious code in anthropy (PyPI)

▾ Sunlitanthropy · anthropyvia OSV
CVE-2026-45409Medium· 5.3
3mo ago

python-idna: idna: Denial of Service via specially crafted long inputs (CVE-2026-45409)

A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications. A remote attacker could exploit this vulnerability by sending specially crafted, excessively long inputs to the library's encoding f…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.46%via CSAF
CVE-2026-10775Low· 3.6
3mo ago

SGLang is Vulnerable to DoS via the data_hash Function

SGLang is Vulnerable to DoS via the data_hash Function

▾ Sunlitsglang · sglangEPSS 0.12%via OSV
CVE-2026-44889Medium· 6.1
3mo ago

WebOb: Location header normalization during redirect leads to open redirect - again

WebOb: Location header normalization during redirect leads to open redirect - again

▾ Sunlitwebob · webobEPSS 0.27%via OSV
CVE-2026-10812Low· 3.6
3mo ago

GPTCache: File and image cache keys collide because BufferedReader.peek() only reads the buffered prefix

GPTCache: File and image cache keys collide because BufferedReader.peek() only reads the buffered prefix

▾ Sunlitgptcache · gptcacheEPSS 0.07%via OSV
CVE-2026-10804Low· 3.6
3mo ago

Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission

Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission

▾ Sunlitstreamlit · streamlitEPSS 0.08%via OSV
CVE-2026-50266Low· 2.2
3mo ago

OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks

OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks

▾ Sunlitneutron · neutronEPSS 0.38%via OSV
CVE-2026-44393High· 7.4
3mo ago

OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake

OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake

▾ Twilightoslo-messaging · oslo-messagingEPSS 0.28%via OSV
CVE-2026-10803Low· 2.5
3mo ago

mlflow: MLflow: Use of weak hash in Dataset Digest Computation (CVE-2026-10803)

A flaw was found in MLflow. This vulnerability stems from the use of a weak hash algorithm within the Dataset Digest Computation component. A local attacker could potentially exploit this weakness, which may impact the integrity or authent…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.10%via CSAF
CVE-2026-10813Low· 3.6
3mo ago

LMCache: 16-bit multimodal hash collision can poison KV cache entries

LMCache: 16-bit multimodal hash collision can poison KV cache entries

▾ Sunlitlmcache · lmcacheEPSS 0.07%via OSV
CVE-2026-10801Low· 3.6
3mo ago

ms-swift: Image Cache Hash Collision via Missing Dimension Metadata

ms-swift: Image Cache Hash Collision via Missing Dimension Metadata

▾ Sunlitms-swift · ms-swiftEPSS 0.07%via OSV
CVEs tagged “pip” — page 51 · VulnSea