VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-38743Medium· 4.3
5mo ago

Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInst…

Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record

▾ Sunlitapache-airflow · apache-airflowEPSS 0.57%via OSV
CVE-2026-41486High
5mo ago

Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization

Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization

▾ Twilightray · rayEPSS 0.70%via OSV
CVE-2026-42150Medium· 5.1
5mo ago

wlc: print_html outputs API data without HTML escaping

wlc: print_html outputs API data without HTML escaping

▾ Sunlitwlc · wlcEPSS 0.30%via OSV
CVE-2026-41140High· 8.7
5mo ago

poetry: Poetry: Path traversal vulnerability allows arbitrary file write via malicious package extraction (CVE-2026-41140)

A flaw was found in Poetry, a dependency manager for Python. This vulnerability allows a remote attacker to perform a path traversal attack. By crafting a malicious software package, the `extractall()` function in Poetry can be tricked int…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2.6EPSS 0.47%via CSAF
CVE-2026-3960Critical· 9.8
5mo ago

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0…

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blackl…

▾ Midnighth2o · h2oEPSS 1.0%via OSV
CVE-2026-6878Medium· 5.6
5mo ago

verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()

verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()

▾ Sunlitverl · verlEPSS 0.42%via OSV
CVE-2026-6827Medium
5mo ago

justhtml has sanitization bypass in custom policies and programmatic DOM

justhtml has sanitization bypass in custom policies and programmatic DOM

▾ Sunlitjusthtml · justhtmlEPSS 0.26%via OSV
CVE-2026-6859High· 8.8
5mo ago

InstructLab Includes Functionality from Untrusted Control Sphere

InstructLab Includes Functionality from Untrusted Control Sphere

▾ Twilightinstructlab · instructlabEPSS 0.77%via OSV
CVE-2026-41066High· 7.5
5mo ago

lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

▾ Twilightlxml · lxmlEPSS 0.41%via OSV
CVE-2026-28684Medium· 6.6
5mo ago

python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback

python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback

▾ Sunlitpython-dotenv · python-dotenvEPSS 0.19%via OSV
CVE-2026-35588Medium· 6.3
5mo ago

Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values

Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values

▾ Sunlitglances · glancesEPSS 0.19%via OSV
CVE-2026-34839Medium· 6.5
5mo ago

Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS

Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS

▾ Sunlitglances · glancesEPSS 0.47%via OSV
CVE-2026-35587High· 8.8
5mo ago

Glances has SSRF in IP Plugin via public_api leading to credential leakage

Glances has SSRF in IP Plugin via public_api leading to credential leakage

▾ Twilightglances · glancesEPSS 0.47%via OSV
CVE-2026-39378Medium· 6.5
5mo ago

nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding

nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding

▾ Sunlitnbconvert · nbconvertEPSS 0.46%via OSV
CVE-2026-33626High· 7.5PoC
5mo ago

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

▾ Midnightlmdeploy · lmdeployEPSS 1.5%via GHSA
CVE-2026-39377Medium· 6.5
5mo ago

nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames

nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames

▾ Sunlitnbconvert · nbconvertEPSS 0.40%via OSV
CVE-2026-6596High· 7.3
5mo ago

Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API

Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API

▾ Twilightlangflow-base · langflow-baseEPSS 0.47%via OSV
CVE-2026-6599Medium· 6.3
5mo ago

Langflow vulnerable to injection

Langflow vulnerable to injection

▾ Sunlitlangflow · langflowEPSS 0.39%via OSV
CVE-2025-66335Medium· 5.3
5mo ago

Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization

Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization

▾ Sunlitdoris-mcp-server · doris-mcp-serverEPSS 0.66%via OSV
CVE-2026-6608Medium· 5.3
5mo ago

FastChat has a Content Moderation Bypass via Arena Side-by-Side Views

FastChat has a Content Moderation Bypass via Arena Side-by-Side Views

▾ Sunlitfschat · fschatEPSS 0.51%via OSV
CVE-2026-6606High· 7.3
5mo ago

AgentScope vulnerable to Server-Side Request Forgery

AgentScope vulnerable to Server-Side Request Forgery

▾ Twilightagentscope · agentscopeEPSS 0.47%via OSV
CVE-2026-6603High· 7.3
5mo ago

AgentScope Vulnerable to Remote Code Injection

AgentScope Vulnerable to Remote Code Injection

▾ Twilightagentscope · agentscopeEPSS 0.52%via OSV
CVE-2026-6598Medium· 4.3
5mo ago

Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint

Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint

▾ Sunlitlangflow · langflowEPSS 0.24%via OSV
CVE-2026-6605High· 7.3
5mo ago

AgentScope vulnerable to Server-Side Request Forgery

AgentScope vulnerable to Server-Side Request Forgery

▾ Twilightagentscope · agentscopeEPSS 0.51%via OSV
CVE-2026-6604High· 7.3
5mo ago

AgentScope vulnerable to Server-Side Request Forgery

AgentScope vulnerable to Server-Side Request Forgery

▾ Twilightagentscope · agentscopeEPSS 0.47%via OSV
CVE-2026-6597Low· 2.7
5mo ago

Langflow has an Information Leak through Incomplete API Key Redaction

Langflow has an Information Leak through Incomplete API Key Redaction

▾ Sunlitlangflow · langflowEPSS 0.38%via OSV
CVE-2026-6607Medium· 5.3
5mo ago

FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)

FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)

▾ Sunlitfschat · fschatEPSS 0.74%via OSV
CVE-2026-3219Medium
5mo ago

pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files

pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files

▾ Sunlitpip · pipEPSS 0.18%via OSV
MAL-2026-2947None
5mo ago

Malicious code in moonbit-schema-utils (PyPI)

Malicious code in moonbit-schema-utils (PyPI)

▾ Sunlitmoonbit-schema-utils · moonbit-schema-utilsvia OSV
MAL-2026-2946None
5mo ago

Malicious code in moonbit-metrics-validator (PyPI)

Malicious code in moonbit-metrics-validator (PyPI)

▾ Sunlitmoonbit-metrics-validator · moonbit-metrics-validatorvia OSV
CVEs tagged “pip” — page 65 · VulnSea