Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-7597Medium· 6.3mem0ai mem0 has an Improper Input Validation Issue
mem0ai mem0 has an Improper Input Validation Issue
CVE-2026-43003High· 8.0An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a mal…
CVE-2026-7579High· 7.3AstrBot Makes Use of Hard-coded Password
AstrBot Makes Use of Hard-coded Password
CVE-2026-43001High· 8.0OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation (CVE-2026-4…
A flaw was found in OpenStack Keystone. An attacker holding an unrestricted application credential could exploit a vulnerability in the POST /v3/credentials endpoint where the caller-supplied project_id for an EC2-type credential was not v…
CVE-2026-41016Medium· 5.9apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider
apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider
CVE-2026-7246High· 7.2Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pa…
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
CVE-2025-13030High· 7.1django-mdeditor is Missing Authentication for Critical Function
django-mdeditor is Missing Authentication for Critical Function
CVE-2026-41654MediumWeblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
CVE-2026-42032MediumCKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CVE-2026-41519Medium· 4.2Weblate Doesn't Invalidate API Token on Password Change
Weblate Doesn't Invalidate API Token on Password Change
CVE-2026-41132MediumCKAN has no certificate validation on STMP connection
CKAN has no certificate validation on STMP connection
CVE-2026-41255Medium· 6.1CKAN has CSRF exemption primed by anonymous requests
CKAN has CSRF exemption primed by anonymous requests
CVE-2026-42352High· 8.6pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
CVE-2026-42031HighPoCCKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CVE-2026-42351High· 7.5pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
CVE-2026-7404High· 7.3mcpo-simple-server has a Path Traversal issue
mcpo-simple-server has a Path Traversal issue
CVE-2026-7159High· 7.3mkdocs-mcp-plugin has a Path Traversal issue
mkdocs-mcp-plugin has a Path Traversal issue
CVE-2026-7212High· 7.3notes-mcp has a Path Traversal issue
notes-mcp has a Path Traversal issue
CVE-2026-7206High· 7.3sqlite-mcp has an Injection issue
sqlite-mcp has an Injection issue
CVE-2026-42510Medium· 6.6OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-7141Medium· 5.6vLLM makes Use of Uninitialized Resource
vLLM makes Use of Uninitialized Resource
CVE-2026-7142Medium· 6.3Wooey has an Incorrect Privilege Assignment issue
Wooey has an Incorrect Privilege Assignment issue
CVE-2026-7150Medium· 6.3auto-favicon has a Server-Side Request Forgery issue
auto-favicon has a Server-Side Request Forgery issue
CVE-2026-7149High· 7.3kaggle-mcp has a Path Traversal issue
kaggle-mcp has a Path Traversal issue
CVE-2026-6357Medium· 5.8pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation (CVE-2026-6357)
A flaw was found in pip. Prior to version 26.1, pip's self-update check functionality would execute after installing wheel packages. This process involved importing newly installed Python modules. A malicious actor could craft a specially …
CVE-2026-7158High· 7.3mcp-url-downloader has a Server-Side Request Forgery issue
mcp-url-downloader has a Server-Side Request Forgery issue
CVE-2026-6984Medium· 4.7AstrBot has Incomplete Filtering of Special Elements
AstrBot has Incomplete Filtering of Special Elements
CVE-2026-42203HighPoCLiteLLM: Server-Side Template Injection in /prompts/test endpoint
LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVE-2026-40690Medium· 4.3Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
CVE-2026-6550Medium· 4.7AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache
AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache