VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-42175Medium· 6.5
4mo ago

requests-hardened is Vulnerable to Server-Side Request Forgery

requests-hardened is Vulnerable to Server-Side Request Forgery

▾ Sunlitrequests-hardened · requests-hardenedEPSS 0.39%via OSV
CVE-2026-42303Medium
4mo ago

Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection

Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.55%via OSV
CVE-2026-42080Medium· 4.6
4mo ago

PPTAgent: Arbitrary File Write via `save_generated_slides`

PPTAgent: Arbitrary File Write via `save_generated_slides`

▾ Sunlitpptagent · pptagentEPSS 0.30%via OSV
CVE-2026-40864Medium· 5.4PoC
4mo ago

JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)

JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)

▾ Twilightjupyterhub · jupyterhubEPSS 0.18%via OSV
CVE-2026-7847Low· 2.6
4mo ago

Langchain-Chatchat Uses Insufficiently Random Values

Langchain-Chatchat Uses Insufficiently Random Values

▾ Sunlitlangchain-chatchat · langchain-chatchatEPSS 0.29%via OSV
CVE-2026-44218Low· 3.0
4mo ago

ciguard: Container image runs as root (no USER directive)

ciguard: Container image runs as root (no USER directive)

▾ Sunlitciguard · ciguardEPSS 0.12%via OSV
CVE-2026-42078Medium· 4.6
4mo ago

PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image

PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image

▾ Sunlitpptagent · pptagentEPSS 0.30%via OSV
CVE-2026-44222Medium· 6.5
4mo ago

vLLM Vulnerable to Remote DoS via Special-Token Placeholders

vLLM Vulnerable to Remote DoS via Special-Token Placeholders

▾ Sunlitvllm · vllmEPSS 0.46%via OSV
CVE-2026-44220None· 0.0
4mo ago

ciguard: discover_pipeline_files follows symlinks out of scan root

ciguard: discover_pipeline_files follows symlinks out of scan root

▾ Sunlitciguard · ciguardEPSS 0.15%via OSV
CVE-2026-42079High· 8.6
4mo ago

PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope

PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope

▾ Twilightpptagent · pptagentEPSS 0.21%via OSV
CVE-2026-42874Low· 3.7
4mo ago

Microdot has HTTP response splitting in Response.set_cookie()

Microdot has HTTP response splitting in Response.set_cookie()

▾ Sunlitmicrodot · microdotEPSS 0.34%via OSV
CVE-2026-43901Medium· 6.8
4mo ago

wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configured

wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configured

▾ Sunlitwireshark-mcp · wireshark-mcpEPSS 0.36%via OSV
CVE-2026-40110High
4mo ago

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

▾ Twilightjupyter-server · jupyter-serverEPSS 0.47%via OSV
CVE-2026-43891High· 7.5
4mo ago

changedetection.io has an Arbitrary Local File Read via a crafted backup restore

changedetection.io has an Arbitrary Local File Read via a crafted backup restore

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.50%via OSV
CVE-2026-42997High· 7.7
4mo ago

An issue was discovered in idrac in OpenStack Ironic before 35.0.1

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides…

▾ Twilightopenstack · ironicEPSS 0.54%via NVD
CVE-2026-42088High· 8.1
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version …

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from th…

▾ Twilightopenc3 · openc3EPSS 0.49%via OSV
CVE-2026-42087Critical· 9.6
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.…

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSD…

▾ Midnightopenc3 · openc3EPSS 0.45%via OSV
CVE-2026-42085Medium· 4.3
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions…

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that …

▾ Sunlitopenc3 · openc3EPSS 0.41%via OSV
CVE-2026-42084High· 8.1
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions…

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their passwo…

▾ Twilightopenc3 · openc3EPSS 0.44%via OSV
CVE-2025-67796High· 8.1
4mo ago

IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users

IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users

▾ Twilightrdiffweb · rdiffwebEPSS 0.24%via OSV
CVE-2026-42310Medium· 5.5
4mo ago

Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

▾ Sunlitpillow · pillowEPSS 0.18%via OSV
CVE-2026-7724Medium· 5.0
4mo ago

Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url

Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url

▾ Sunlitprefect · prefectEPSS 0.31%via OSV
CVE-2026-7723High· 7.3
4mo ago

Prefect Unauthenticated Event Injection via /api/events/in WebSocket

Prefect Unauthenticated Event Injection via /api/events/in WebSocket

▾ Twilightprefect · prefectEPSS 0.71%via OSV
CVE-2026-7711High· 7.3
4mo ago

MindsDB has an Improper Access Control Issue

MindsDB has an Improper Access Control Issue

▾ Twilightmindsdb · mindsdbEPSS 0.47%via OSV
CVE-2026-7722Medium· 5.3
4mo ago

Prefect Auth Bypass via endswith() Health Check Exemption

Prefect Auth Bypass via endswith() Health Check Exemption

▾ Sunlitprefect · prefectEPSS 0.77%via OSV
CVE-2026-7725Medium· 6.3
4mo ago

Prefect Git Argument Injection in GitRepository Pull Steps

Prefect Git Argument Injection in GitRepository Pull Steps

▾ Sunlitprefect · prefectEPSS 0.42%via OSV
CVE-2026-42309Medium· 5.5
4mo ago

Pillow has a heap buffer overflow with nested list coordinates

Pillow has a heap buffer overflow with nested list coordinates

▾ Sunlitpillow · pillowEPSS 0.18%via OSV
CVE-2026-42601Critical· 9.8
4mo ago

ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView

ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView

▾ Midnightarchivebox · archiveboxEPSS 0.60%via OSV
CVE-2026-7669Medium· 5.6PoC
4mo ago

SGLang has an Improper Input Validation/Injection Issue

SGLang has an Improper Input Validation/Injection Issue

▾ Twilightsglang · sglangEPSS 0.42%via OSV
MAL-2026-3248None
4mo ago

Malicious code in pwn-control (PyPI)

Malicious code in pwn-control (PyPI)

▾ Sunlitpwn-control · pwn-controlvia OSV
CVEs tagged “pip” — page 63 · VulnSea