VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-31233Critical· 9.8
4mo ago

Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism

Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism

▾ Midnightguardrails-ai · guardrails-aiEPSS 0.93%via OSV
CVE-2026-31240High· 7.5
4mo ago

mem0 server lacks authentication and authorization controls for its memory management API endpoints

mem0 server lacks authentication and authorization controls for its memory management API endpoints

▾ Twilightmem0ai · mem0aiEPSS 0.54%via OSV
CVE-2026-31241Medium· 6.5
4mo ago

mem0 server lacks authentication and authorization controls for its memory deletion API endpoint

mem0 server lacks authentication and authorization controls for its memory deletion API endpoint

▾ Sunlitmem0ai · mem0aiEPSS 0.55%via OSV
CVE-2026-31224High· 8.8
4mo ago

Snorkel MultitaskClassifier.load uses an unsafe torch.load

Snorkel MultitaskClassifier.load uses an unsafe torch.load

▾ Twilightsnorkel · snorkelEPSS 0.69%via OSV
CVE-2026-31223High· 8.8
4mo ago

Snorkel BaseLabeler.load uses an unsafe pickle.load

Snorkel BaseLabeler.load uses an unsafe pickle.load

▾ Twilightsnorkel · snorkelEPSS 0.69%via OSV
CVE-2026-31245Medium· 5.3
4mo ago

mem0 server lacks authentication and authorization controls for its memory creation API endpoint

mem0 server lacks authentication and authorization controls for its memory creation API endpoint

▾ Sunlitmem0ai · mem0aiEPSS 0.48%via OSV
CVE-2026-31222High· 8.8
4mo ago

Snorkel Trainer.load uses an unsafe torch.load

Snorkel Trainer.load uses an unsafe torch.load

▾ Twilightsnorkel · snorkelEPSS 0.69%via OSV
CVE-2026-31221High· 8.0
4mo ago

pytorch-lightning: PyTorch-Lightning: Arbitrary code execution via insecure deserialization of checkpoint files (CVE-2026-31221)

A flaw was found in PyTorch-Lightning. This vulnerability, categorized as insecure deserialization (CWE-502), exists in the checkpoint loading mechanism. A remote attacker can exploit this by providing a maliciously crafted checkpoint file…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI (RHEL AI) 3EPSS 0.55%via CSAF
CVE-2026-31225High· 8.8
4mo ago

Superduper: Remote code execution via unsafe eval in superduper query parsing

Superduper: Remote code execution via unsafe eval in superduper query parsing

▾ Twilightsuperduper-framework · superduper-frameworkEPSS 0.70%via OSV
CVE-2026-44223Medium· 6.5
4mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step,…

▾ SunlitRed Hat · Red Hat Enterprise Linux AI 3.4EPSS 0.43%via NVD
CVE-2026-7813Critical· 9.9
4mo ago

pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debu…

pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules

▾ Midnightpgadmin4 · pgadmin4EPSS 0.65%via OSV
CVE-2026-41018Medium· 6.5
4mo ago

Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL

Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL

▾ Sunlitapache-airflow-providers-elasticsearch · apache-airflow-providers-elasticsearchEPSS 0.66%via OSV
CVE-2026-45017High· 7.5
4mo ago

python-liquid: Absolute paths escape filesystem loader search path

python-liquid: Absolute paths escape filesystem loader search path

▾ Twilightpython-liquid · python-liquidEPSS 0.50%via OSV
CVE-2026-56400High· 8.3
4mo ago

Open WebUI has a CORS misconfiguration and session validation issue

Open WebUI has a CORS misconfiguration and session validation issue

▾ Twilightopen-webui · open-webuiEPSS 0.52%via OSV
CVE-2026-40217High· 8.8PoC
4mo ago

LiteLLM has a sandbox escape in custom-code guardrail

LiteLLM has a sandbox escape in custom-code guardrail

▾ Midnightlitellm · litellmEPSS 3.4%via OSV
CVE-2026-7817Medium· 6.5
4mo ago

pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities

pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities

▾ Sunlitpgadmin4 · pgadmin4EPSS 0.35%via OSV
CVE-2026-31246Medium· 6.5
4mo ago

GPT-Pilot contains a command injection vulnerability in the Executor.run() method

GPT-Pilot contains a command injection vulnerability in the Executor.run() method

▾ Sunlitgpt-pilot · gpt-pilotEPSS 1.1%via OSV
CVE-2026-44972Medium· 5.0
4mo ago

GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content

GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content

▾ Sunlitguarddog · guarddogEPSS 0.15%via OSV
CVE-2026-44569High· 7.1
4mo ago

Open WebUI's Insecure Message Access Breaks Authorization

Open WebUI's Insecure Message Access Breaks Authorization

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-44571Medium· 6.5
4mo ago

Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission

Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission

▾ Sunlitopen-webui · open-webuiEPSS 0.34%via OSV
CVE-2026-7816High· 8.8
4mo ago

pgAdmin 4: OS command injection vulnerability in Import/Export query export

pgAdmin 4: OS command injection vulnerability in Import/Export query export

▾ Twilightpgadmin4 · pgadmin4EPSS 2.2%via OSV
CVE-2026-44565High· 8.1
4mo ago

Open WebUI Arbitrary File Write, Delete via Path Traversal

Open WebUI Arbitrary File Write, Delete via Path Traversal

▾ Twilightopen-webui · open-webuiEPSS 0.54%via OSV
CVE-2026-7820Medium· 6.5
4mo ago

pgAdmin 4: Improper restriction of excessive authentication attempts

pgAdmin 4: Improper restriction of excessive authentication attempts

▾ Sunlitpgadmin4 · pgadmin4EPSS 0.33%via OSV
CVE-2026-7819High· 8.1
4mo ago

pgAdmin 4 File Manager has symbolic-link path traversal

pgAdmin 4 File Manager has symbolic-link path traversal

▾ Twilightpgadmin4 · pgadmin4EPSS 0.48%via OSV
CVE-2026-7815High· 8.8
4mo ago

SQL injection vulnerability in pgAdmin 4 Maintenance Tool

SQL injection vulnerability in pgAdmin 4 Maintenance Tool

▾ Twilightpgadmin4 · pgadmin4EPSS 0.64%via OSV
CVE-2026-44570High· 8.3
4mo ago

Open WebUI has inconsistent authorization controls within memories API

Open WebUI has inconsistent authorization controls within memories API

▾ Twilightopen-webui · open-webuiEPSS 0.42%via OSV
CVE-2026-44339High· 8.6
4mo ago

PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute

PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.43%via OSV
CVE-2026-43979Medium· 5.0
4mo ago

local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)

local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)

▾ Sunlitlocal-deep-research · local-deep-researchEPSS 0.36%via OSV
CVE-2026-31247High· 7.5
4mo ago

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks

▾ Twilightdocling · doclingEPSS 0.49%via OSV
CVE-2026-8319Medium· 5.3
4mo ago

aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function

aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function

▾ Sunlitai-agents · ai-agentsEPSS 0.64%via OSV
CVEs tagged “pip” — page 59 · VulnSea