Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-42175Medium· 6.5requests-hardened is Vulnerable to Server-Side Request Forgery
requests-hardened is Vulnerable to Server-Side Request Forgery
CVE-2026-42303MediumEthyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
CVE-2026-42080Medium· 4.6PPTAgent: Arbitrary File Write via `save_generated_slides`
PPTAgent: Arbitrary File Write via `save_generated_slides`
CVE-2026-40864Medium· 5.4PoCJupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)
JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)
CVE-2026-7847Low· 2.6Langchain-Chatchat Uses Insufficiently Random Values
Langchain-Chatchat Uses Insufficiently Random Values
CVE-2026-44218Low· 3.0ciguard: Container image runs as root (no USER directive)
ciguard: Container image runs as root (no USER directive)
CVE-2026-42078Medium· 4.6PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image
PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image
CVE-2026-44222Medium· 6.5vLLM Vulnerable to Remote DoS via Special-Token Placeholders
vLLM Vulnerable to Remote DoS via Special-Token Placeholders
CVE-2026-44220None· 0.0ciguard: discover_pipeline_files follows symlinks out of scan root
ciguard: discover_pipeline_files follows symlinks out of scan root
CVE-2026-42079High· 8.6PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope
PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope
CVE-2026-42874Low· 3.7Microdot has HTTP response splitting in Response.set_cookie()
Microdot has HTTP response splitting in Response.set_cookie()
CVE-2026-43901Medium· 6.8wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configured
wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configured
CVE-2026-40110HighJupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
CVE-2026-43891High· 7.5changedetection.io has an Arbitrary Local File Read via a crafted backup restore
changedetection.io has an Arbitrary Local File Read via a crafted backup restore
CVE-2026-42997High· 7.7An issue was discovered in idrac in OpenStack Ironic before 35.0.1
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides…
CVE-2026-42088High· 8.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version …
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from th…
CVE-2026-42087Critical· 9.6OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.…
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSD…
CVE-2026-42085Medium· 4.3OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions…
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that …
CVE-2026-42084High· 8.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions…
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their passwo…
CVE-2025-67796High· 8.1IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
CVE-2026-42310Medium· 5.5Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
CVE-2026-7724Medium· 5.0Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url
Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url
CVE-2026-7723High· 7.3Prefect Unauthenticated Event Injection via /api/events/in WebSocket
Prefect Unauthenticated Event Injection via /api/events/in WebSocket
CVE-2026-7711High· 7.3MindsDB has an Improper Access Control Issue
MindsDB has an Improper Access Control Issue
CVE-2026-7722Medium· 5.3Prefect Auth Bypass via endswith() Health Check Exemption
Prefect Auth Bypass via endswith() Health Check Exemption
CVE-2026-7725Medium· 6.3Prefect Git Argument Injection in GitRepository Pull Steps
Prefect Git Argument Injection in GitRepository Pull Steps
CVE-2026-42309Medium· 5.5Pillow has a heap buffer overflow with nested list coordinates
Pillow has a heap buffer overflow with nested list coordinates
CVE-2026-42601Critical· 9.8ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
CVE-2026-7669Medium· 5.6PoCSGLang has an Improper Input Validation/Injection Issue
SGLang has an Improper Input Validation/Injection Issue
MAL-2026-3248NoneMalicious code in pwn-control (PyPI)
Malicious code in pwn-control (PyPI)