VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-43977High· 7.5
4mo ago

wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API

wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API

▾ Twilightwger · wgerEPSS 0.39%via OSV
CVE-2026-44899Medium· 4.7
4mo ago

Mistune Image Directive CSS Injection Vulnerability

Mistune Image Directive CSS Injection Vulnerability

▾ Sunlitmistune · mistuneEPSS 0.27%via OSV
CVE-2026-43978High· 8.1
4mo ago

wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager

wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager

▾ Twilightwger · wgerEPSS 0.37%via OSV
CVE-2026-45400High· 8.5
4mo ago

Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`

Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`

▾ Twilightopen-webui · open-webuiEPSS 0.33%via OSV
CVE-2026-45399High· 7.1
4mo ago

Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption

Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-44969Low· 2.5
4mo ago

dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled

dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled

▾ Sunlitdbt-mcp · dbt-mcpEPSS 0.17%via OSV
CVE-2026-45299Medium· 5.4
4mo ago

Open WebUI has Stored Cross-Site Scripting In Profile Picture

Open WebUI has Stored Cross-Site Scripting In Profile Picture

▾ Sunlitopen-webui · open-webuiEPSS 0.23%via OSV
CVE-2026-45397Medium· 5.3PoC
4mo ago

Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure

Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure

▾ Twilightopen-webui · open-webuiEPSS 0.81%via OSV
CVE-2026-44898Medium· 6.1
4mo ago

Mistune TOC Anchor Injection XSS

Mistune TOC Anchor Injection XSS

▾ Sunlitmistune · mistuneEPSS 0.27%via OSV
CVE-2026-45370High· 7.7
4mo ago

python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection

python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection

▾ Twilightutcp-cli · utcp-cliEPSS 0.37%via OSV
CVE-2026-44541High
4mo ago

ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override

ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.52%via OSV
CVE-2026-45386Medium· 4.3
4mo ago

Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint

Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint

▾ Sunlitopen-webui · open-webuiEPSS 0.29%via OSV
CVE-2026-45303High· 7.7
4mo ago

Open WebUI has stored XSS via the HTML renedering view

Open WebUI has stored XSS via the HTML renedering view

▾ Twilightopen-webui · open-webuiEPSS 0.30%via OSV
CVE-2026-45331High· 8.5
4mo ago

Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature

Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature

▾ Twilightopen-webui · open-webuiEPSS 0.33%via OSV
CVE-2026-45350High· 7.1
4mo ago

Open WebUI's chat completion API allows tool restrictions to be bypassed

Open WebUI's chat completion API allows tool restrictions to be bypassed

▾ Twilightopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2026-44919Medium· 4.3
4mo ago

OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices

OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices

▾ Sunlitironic · ironicEPSS 0.56%via OSV
CVE-2026-45398High· 7.5
4mo ago

Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls

Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls

▾ Twilightopen-webui · open-webuiEPSS 0.49%via OSV
CVE-2026-45672High· 8.8
4mo ago

Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed

Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed

▾ Twilightopen-webui · open-webuiEPSS 0.59%via OSV
CVE-2026-45314Medium· 6.1
4mo ago

Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image

Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image

▾ Sunlitopen-webui · open-webuiEPSS 0.24%via OSV
CVE-2026-45671High· 8.0
4mo ago

Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion

Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-45338High· 7.7
4mo ago

Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)

Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)

▾ Twilightopen-webui · open-webuiEPSS 0.38%via OSV
CVE-2026-44681Medium· 6.1
4mo ago

Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect

Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect

▾ Sunlitauthlib · authlibEPSS 0.29%via OSV
CVE-2026-44794Medium· 5.4
4mo ago

Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference

Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference

▾ Sunlitnautobot · nautobotEPSS 0.30%via OSV
CVE-2026-44796Medium· 6.5
4mo ago

Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)

Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)

▾ Sunlitnautobot · nautobotEPSS 0.56%via OSV
CVE-2026-44798High· 7.1
4mo ago

Nautobot: GitRepository.current_head field should not be writable through REST API

Nautobot: GitRepository.current_head field should not be writable through REST API

▾ Twilightnautobot · nautobotEPSS 0.50%via OSV
CVE-2026-44797High· 8.5
4mo ago

Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)

Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)

▾ Twilightnautobot · nautobotEPSS 0.40%via OSV
CVE-2026-45134High· 7.1
4mo ago

LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

▾ Twilightlangsmith · langsmithEPSS 0.34%via OSV
CVE-2026-42266High· 8.8
4mo ago

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_…

▾ Twilightjupyter · jupyterlabEPSS 0.85%via NVD
CVE-2026-44432High· 7.5
4mo ago

urllib3 is an HTTP client library for Python

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed…

▾ Twilightpython · urllib3EPSS 0.88%via NVD
CVE-2026-44431Medium· 5.3PoC
4mo ago

urllib3 is an HTTP client library for Python

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive hea…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.34%via NVD
CVEs tagged “pip” — page 58 · VulnSea