VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-44264Medium· 4.3
4mo ago

Weblate vulnerable to XSS via crafted Markdown

Weblate vulnerable to XSS via crafted Markdown

▾ Sunlitweblate · weblateEPSS 0.37%via OSV
CVE-2026-44661Medium· 4.7
4mo ago

utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol

utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol

▾ Sunlitutcp-http · utcp-httpEPSS 0.20%via OSV
MAL-2026-3370None
4mo ago

Malicious code in sufiagent (PyPI)

Malicious code in sufiagent (PyPI)

▾ Sunlitsufiagent · sufiagentvia OSV
CVE-2026-44334High· 8.4
4mo ago

PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)

PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)

▾ Twilightpraisonai · praisonaiEPSS 0.23%via OSV
CVE-2026-42544High· 7.5
4mo ago

Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic

Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic

▾ Twilightgranian · granianEPSS 0.46%via OSV
CVE-2026-44305Medium· 6.8
4mo ago

Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled

Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled

▾ Sunlitlemur · lemurEPSS 0.14%via OSV
CVE-2026-44405Low· 3.4
4mo ago

Paramiko rsakey.py allows the SHA-1 algorithm

Paramiko rsakey.py allows the SHA-1 algorithm

▾ Sunlitparamiko · paramikoEPSS 0.13%via OSV
CVE-2026-44335Critical· 9.8
4mo ago

PraisonAI has an SSRF bypass

PraisonAI has an SSRF bypass

▾ Midnightpraisonaiagents · praisonaiagentsEPSS 0.57%via OSV
CVE-2026-42561High· 7.5
4mo ago

python-multipart has Denial of Service via unbounded multipart part headers

python-multipart has Denial of Service via unbounded multipart part headers

▾ Twilightpython-multipart · python-multipartEPSS 0.85%via OSV
CVE-2026-42557Critical· 9.6
4mo ago

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

▾ Midnightjupyterlab · jupyterlabEPSS 0.71%via OSV
CVE-2026-44363Medium
4mo ago

misp-modules has nsafe remote resource fetching in expansion

misp-modules has nsafe remote resource fetching in expansion

▾ Sunlitmisp-modules · misp-modulesEPSS 0.13%via OSV
CVE-2026-42545Medium· 5.9
4mo ago

Granian vulnerable to DoS via WSGI response header panic

Granian vulnerable to DoS via WSGI response header panic

▾ Sunlitgranian · granianEPSS 0.37%via OSV
CVE-2026-42448Low· 3.5
4mo ago

Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed

Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed

▾ Sunlitmagic-wormhole · magic-wormholeEPSS 0.29%via OSV
CVE-2026-44226Medium· 5.3
4mo ago

PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI

PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI

▾ Sunlitpyload-ng · pyload-ngEPSS 0.41%via OSV
CVE-2026-44368Medium
4mo ago

pyquorum: Timing side‑channel in mul_mod

pyquorum: Timing side‑channel in mul_mod

▾ Sunlitpyquorum · pyquorumEPSS 0.53%via OSV
CVE-2026-44243High· 7.1
4mo ago

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

▾ Twilightgitpython · gitpythonEPSS 0.44%via OSV
CVE-2026-44439High· 7.5
4mo ago

Playwright Capture permits access to local files and internal network resources during page capture

Playwright Capture permits access to local files and internal network resources during page capture

▾ Twilightplaywrightcapture · playwrightcaptureEPSS 0.54%via OSV
CVE-2026-44304High· 8.1
4mo ago

Lemur: LDAP Filter Injection enables post-authentication privilege escalation

Lemur: LDAP Filter Injection enables post-authentication privilege escalation

▾ Twilightlemur · lemurEPSS 0.29%via OSV
CVE-2026-44307High
4mo ago

Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup

Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup

▾ Twilightmako · makoEPSS 0.89%via OSV
CVE-2026-33079High· 7.5
4mo ago

In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service

In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular ex…

▾ Twilightmistune · mistuneEPSS 0.70%via NVD
CVE-2026-5766Medium· 5.3
4mo ago

Django has an Improper Handling of Length Parameter Inconsistency

Django has an Improper Handling of Length Parameter Inconsistency

▾ Sunlitdjango · djangoEPSS 0.52%via OSV
CVE-2025-61669Medium
4mo ago

Jupyter Server has an open redirection vulnerability in `next` query parameter

Jupyter Server has an open redirection vulnerability in `next` query parameter

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.27%via OSV
CVE-2026-42304High· 7.5
4mo ago

Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains

Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains

▾ Twilighttwisted · twistedEPSS 0.95%via OSV
CVE-2026-40934Medium· 6.8
4mo ago

Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart

Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.38%via OSV
CVE-2026-6907Medium· 4.3
4mo ago

Django Uses Cache Containing Sensitive Information

Django Uses Cache Containing Sensitive Information

▾ Sunlitdjango · djangoEPSS 0.44%via OSV
CVE-2026-35397High· 8.8PoC
4mo ago

Jupyter Server is the backend for Jupyter web applications

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whos…

▾ Midnightjupyter · jupyter_serverEPSS 0.67%via NVD
CVE-2026-44219Low· 3.7
4mo ago

ciguard: SCA HTTP client reads response body without size cap

ciguard: SCA HTTP client reads response body without size cap

▾ Sunlitciguard · ciguardEPSS 0.31%via OSV
CVE-2026-7846Low· 2.6
4mo ago

Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API

Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API

▾ Sunlitlangchain-chatchat · langchain-chatchatEPSS 0.23%via OSV
CVE-2026-7845Low· 2.6
4mo ago

Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm

Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm

▾ Sunlitlangchain-chatchat · langchain-chatchatEPSS 0.20%via OSV
CVE-2026-43002Medium· 5.3
4mo ago

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression…

▾ Sunlitopenstack · horizonEPSS 0.60%via NVD
CVEs tagged “pip” — page 62 · VulnSea