VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-7597Medium· 6.3
5mo ago

mem0ai mem0 has an Improper Input Validation Issue

mem0ai mem0 has an Improper Input Validation Issue

▾ Sunlitmem0ai · mem0aiEPSS 0.43%via OSV
CVE-2026-43003High· 8.0
5mo ago

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a mal…

▾ Twilightopenstack · ironic_python_agentEPSS 1.1%via NVD
CVE-2026-7579High· 7.3
5mo ago

AstrBot Makes Use of Hard-coded Password

AstrBot Makes Use of Hard-coded Password

▾ Twilightastrbot · astrbotEPSS 0.50%via OSV
CVE-2026-43001High· 8.0
5mo ago

OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation (CVE-2026-4…

A flaw was found in OpenStack Keystone. An attacker holding an unrestricted application credential could exploit a vulnerability in the POST /v3/credentials endpoint where the caller-supplied project_id for an EC2-type credential was not v…

▾ TwilightRed Hat · Red Hat OpenStack Platform 17.1EPSS 0.59%via CSAF
CVE-2026-41016Medium· 5.9
5mo ago

apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider

apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider

▾ Sunlitapache-airflow-providers-smtp · apache-airflow-providers-smtpEPSS 0.27%via OSV
CVE-2026-7246High· 7.2
5mo ago

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pa…

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

▾ Twilightclick · clickEPSS 0.92%via OSV
CVE-2025-13030High· 7.1
5mo ago

django-mdeditor is Missing Authentication for Critical Function

django-mdeditor is Missing Authentication for Critical Function

▾ Twilightdjango-mdeditor · django-mdeditorEPSS 0.31%via OSV
CVE-2026-41654Medium
5mo ago

Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url

Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url

▾ Sunlitweblate · weblateEPSS 0.50%via OSV
CVE-2026-42032Medium
5mo ago

CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`

CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`

▾ Sunlitckan · ckanEPSS 0.41%via OSV
CVE-2026-41519Medium· 4.2
5mo ago

Weblate Doesn't Invalidate API Token on Password Change

Weblate Doesn't Invalidate API Token on Password Change

▾ Sunlitweblate · weblateEPSS 0.37%via OSV
CVE-2026-41132Medium
5mo ago

CKAN has no certificate validation on STMP connection

CKAN has no certificate validation on STMP connection

▾ Sunlitckan · ckanEPSS 0.21%via OSV
CVE-2026-41255Medium· 6.1
5mo ago

CKAN has CSRF exemption primed by anonymous requests

CKAN has CSRF exemption primed by anonymous requests

▾ Sunlitckan · ckanEPSS 0.14%via OSV
CVE-2026-42352High· 8.6
5mo ago

pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber

pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber

▾ Twilightpygeoapi · pygeoapiEPSS 0.56%via OSV
CVE-2026-42031HighPoC
5mo ago

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

▾ Midnightckan · ckanEPSS 2.2%via OSV
CVE-2026-42351High· 7.5
5mo ago

pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider

pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider

▾ Twilightpygeoapi · pygeoapiEPSS 0.61%via OSV
CVE-2026-7404High· 7.3
5mo ago

mcpo-simple-server has a Path Traversal issue

mcpo-simple-server has a Path Traversal issue

▾ Twilightmcpo-simple-server · mcpo-simple-serverEPSS 0.59%via OSV
CVE-2026-7159High· 7.3
5mo ago

mkdocs-mcp-plugin has a Path Traversal issue

mkdocs-mcp-plugin has a Path Traversal issue

▾ Twilightmkdocs-mcp-plugin · mkdocs-mcp-pluginEPSS 0.61%via OSV
CVE-2026-7212High· 7.3
5mo ago

notes-mcp has a Path Traversal issue

notes-mcp has a Path Traversal issue

▾ Twilightnotes-mcp · notes-mcpEPSS 0.59%via OSV
CVE-2026-7206High· 7.3
5mo ago

sqlite-mcp has an Injection issue

sqlite-mcp has an Injection issue

▾ Twilightsqlite-mcp · sqlite-mcpEPSS 0.43%via OSV
CVE-2026-42510Medium· 6.6
5mo ago

OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

▾ Sunlitironic · ironicEPSS 0.74%via OSV
CVE-2026-7141Medium· 5.6
5mo ago

vLLM makes Use of Uninitialized Resource

vLLM makes Use of Uninitialized Resource

▾ Sunlitvllm · vllmEPSS 0.48%via OSV
CVE-2026-7142Medium· 6.3
5mo ago

Wooey has an Incorrect Privilege Assignment issue

Wooey has an Incorrect Privilege Assignment issue

▾ Sunlitwooey · wooeyEPSS 0.37%via OSV
CVE-2026-7150Medium· 6.3
5mo ago

auto-favicon has a Server-Side Request Forgery issue

auto-favicon has a Server-Side Request Forgery issue

▾ Sunlitauto-favicon · auto-faviconEPSS 0.35%via OSV
CVE-2026-7149High· 7.3
5mo ago

kaggle-mcp has a Path Traversal issue

kaggle-mcp has a Path Traversal issue

▾ Twilightkaggle-mcp · kaggle-mcpEPSS 0.59%via OSV
CVE-2026-6357Medium· 5.8
5mo ago

pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation (CVE-2026-6357)

A flaw was found in pip. Prior to version 26.1, pip's self-update check functionality would execute after installing wheel packages. This process involved importing newly installed Python modules. A malicious actor could craft a specially …

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.17%via CSAF
CVE-2026-7158High· 7.3
5mo ago

mcp-url-downloader has a Server-Side Request Forgery issue

mcp-url-downloader has a Server-Side Request Forgery issue

▾ Twilightmcp-url-downloader · mcp-url-downloaderEPSS 0.47%via OSV
CVE-2026-6984Medium· 4.7
5mo ago

AstrBot has Incomplete Filtering of Special Elements

AstrBot has Incomplete Filtering of Special Elements

▾ Sunlitastrbot · astrbotEPSS 0.41%via OSV
CVE-2026-42203HighPoC
5mo ago

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

LiteLLM: Server-Side Template Injection in /prompts/test endpoint

▾ Midnightlitellm · litellmEPSS 0.66%via OSV
CVE-2026-40690Medium· 4.3
5mo ago

Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions

Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions

▾ Sunlitapache-airflow · apache-airflowEPSS 0.57%via OSV
CVE-2026-6550Medium· 4.7
5mo ago

AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache

AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache

▾ Sunlitaws-encryption-sdk · aws-encryption-sdkEPSS 0.10%via OSV
CVEs tagged “pip” — page 64 · VulnSea