VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-46447Medium· 5.8
3mo ago

OpenStack Ironic allows Boot Script Injection

OpenStack Ironic allows Boot Script Injection

▾ Sunlitironic · ironicEPSS 0.43%via OSV
CVE-2026-48681Medium· 5.9
3mo ago

OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image

OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image

▾ Sunlitironic · ironicEPSS 0.85%via OSV
CVE-2026-41283Critical· 9.9
3mo ago

OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed

OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed

▾ Midnightmistral · mistralEPSS 0.92%via OSV
CVE-2026-10783Low· 2.5
3mo ago

Gradio: Audio cache key ignores metadata when saving numpy audio outputs

Gradio: Audio cache key ignores metadata when saving numpy audio outputs

▾ Sunlitgradio · gradioEPSS 0.11%via OSV
CVE-2026-47706Medium· 5.3
3mo ago

Strawberry GraphQL has a Circular Fragment Reference DOS

Strawberry GraphQL has a Circular Fragment Reference DOS

▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.43%via OSV
CVE-2026-47707Medium· 5.3
3mo ago

Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification

Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification

▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.69%via OSV
CVE-2026-35193Low· 3.1
3mo ago

Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary

Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary

▾ Sunlitdjango · djangoEPSS 0.43%via OSV
CVE-2026-6873Low· 3.1
3mo ago

Django: signed cookies are vulnerable to salt namespace collisions

Django: signed cookies are vulnerable to salt namespace collisions

▾ Sunlitdjango · djangoEPSS 0.28%via OSV
CVE-2026-48587Low· 3.1
3mo ago

Django: has_vary_header may expose cached responses when Vary values contain whitespace

Django: has_vary_header may expose cached responses when Vary values contain whitespace

▾ Sunlitdjango · djangoEPSS 0.43%via OSV
CVE-2026-8404Low· 3.1
3mo ago

Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

▾ Sunlitdjango · djangoEPSS 0.43%via OSV
MAL-2026-5173None
3mo ago

Malicious code in spadata (PyPI)

Malicious code in spadata (PyPI)

▾ Sunlitspadata · spadatavia OSV
CVE-2026-44020High· 7.5
3mo ago

Docling: Unsafe XML Entity Expansion in USPTO Patent Backend

Docling: Unsafe XML Entity Expansion in USPTO Patent Backend

▾ Twilightdocling · doclingEPSS 0.60%via OSV
CVE-2026-10766Low· 3.6
3mo ago

mlrun: DataFrame hash collisions can cause dataset artifact path conflicts and silent data corruption

mlrun: DataFrame hash collisions can cause dataset artifact path conflicts and silent data corruption

▾ Sunlitmlrun · mlrunEPSS 0.07%via OSV
CVE-2026-44018Medium· 5.5
3mo ago

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend

▾ Sunlitdocling · doclingEPSS 0.16%via OSV
CVE-2026-44016High· 8.2
3mo ago

Docling: Unsafe Playwright-based HTML Rendering

Docling: Unsafe Playwright-based HTML Rendering

▾ Twilightdocling · doclingEPSS 0.59%via OSV
CVE-2026-7666Low· 3.1
3mo ago

Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake

Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake

▾ Sunlitdjango · djangoEPSS 0.21%via OSV
CVE-2026-44023High· 8.6
3mo ago

Docling Core: Unsafe remote filename resolution

Docling Core: Unsafe remote filename resolution

▾ Twilightdocling-core · docling-coreEPSS 0.43%via OSV
CVE-2026-44019High· 8.1
3mo ago

Docling Core: Insufficient validation of image reference URIs

Docling Core: Insufficient validation of image reference URIs

▾ Twilightdocling-core · docling-coreEPSS 0.42%via OSV
CVE-2026-47265Medium
3mo ago

AIOHTTP is vulnerable to cross-origin redirect with per-request cookies

AIOHTTP is vulnerable to cross-origin redirect with per-request cookies

▾ Sunlitaiohttp · aiohttpEPSS 0.21%via OSV
CVE-2026-5241High· 7.7
3mo ago

python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting (CVE-2026-5241)

A flaw was found in python-transformers. An attacker can exploit this vulnerability by providing a malicious model repository. During model initialization, the `trust_remote_code` parameter, intended to prevent remote code execution, is ov…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.94%via CSAF
CVE-2026-44017High· 7.5
3mo ago

Docling: Unsafe Zip Extraction in EasyOCR Model Download

Docling: Unsafe Zip Extraction in EasyOCR Model Download

▾ Twilightdocling · doclingEPSS 0.71%via OSV
CVE-2026-44022Medium· 5.5
3mo ago

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

▾ Sunlitdocling · doclingEPSS 0.21%via OSV
CVE-2026-44546Low· 3.7
3mo ago

daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators

daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators

▾ Sunlitdaphne · daphneEPSS 0.29%via OSV
CVE-2026-44545Medium· 5.3
3mo ago

daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames

daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames

▾ Sunlitdaphne · daphneEPSS 0.57%via OSV
CVE-2026-4035Critical· 9.1
3mo ago

MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration

MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration

▾ Midnightmlflow · mlflowEPSS 0.66%via OSV
CVE-2026-10692Medium· 4.3
3mo ago

Code Index MCP is vulnerable to Uncontrolled Resource Consumption

Code Index MCP is vulnerable to Uncontrolled Resource Consumption

▾ Sunlitcode-index-mcp · code-index-mcpEPSS 0.31%via OSV
MAL-2026-5171None
3mo ago

Malicious code in spaysdata (PyPI)

Malicious code in spaysdata (PyPI)

▾ Sunlitspaysdata · spaysdatavia OSV
MAL-2026-5170None
3mo ago

Malicious code in spaysrbdata (PyPI)

Malicious code in spaysrbdata (PyPI)

▾ Sunlitspaysrbdata · spaysrbdatavia OSV
CVE-2026-47117Critical· 9.8PoC
3mo ago

OpenMed vulnerable to remote code injection through privacy-filter model loading path

OpenMed vulnerable to remote code injection through privacy-filter model loading path

▾ Abyssalopenmed · openmedEPSS 1.3%via OSV
CVE-2026-34993High· 7.2
3mo ago

aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993)

A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework for asyncio and Python. An attacker could exploit this vulnerability by providing untrusted input to the `CookieJar.load()` function. This could potentially lead to …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.50%via CSAF
CVEs tagged “pip” — page 52 · VulnSea