VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-2945None
5mo ago

Malicious code in moonbit-locale-compat (PyPI)

Malicious code in moonbit-locale-compat (PyPI)

▾ Sunlitmoonbit-locale-compat · moonbit-locale-compatvia OSV
CVE-2026-32690Low· 3.7
5mo ago

Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries

Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries

▾ Sunlitapache-airflow-core · apache-airflow-coreEPSS 0.66%via OSV
CVE-2026-30912Medium· 5.3
5mo ago

Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false

Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false

▾ Sunlitapache-airflow-core · apache-airflow-coreEPSS 0.76%via OSV
CVE-2026-41490High· 8.3PoC
5mo ago

Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations

Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations

▾ Midnightdagster-duckdb · dagster-duckdbEPSS 0.45%via OSV
CVE-2026-32228High· 7.5
5mo ago

Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions

Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions

▾ Twilightapache-airflow-core · apache-airflow-coreEPSS 0.72%via OSV
CVE-2026-25917High· 7.2
5mo ago

Apache Airflow allows code execution through crafted XCom payloads

Apache Airflow allows code execution through crafted XCom payloads

▾ Twilightapache-airflow-core · apache-airflow-coreEPSS 1.1%via OSV
CVE-2026-40948Medium· 5.4
5mo ago

apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation

apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation

▾ Sunlitapache-airflow-providers-keycloak · apache-airflow-providers-keycloakEPSS 0.36%via OSV
CVE-2026-40525Critical· 9.1
5mo ago

OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes

OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes

▾ Midnightopenviking · openvikingEPSS 0.76%via OSV
CVE-2026-35402Low
5mo ago

Neo4j Labs MCP Servers: SSRF and Data Modification via read_only Mode Bypass Through CALL Procedures

Neo4j Labs MCP Servers: SSRF and Data Modification via read_only Mode Bypass Through CALL Procedures

▾ Sunlitmcp-neo4j-cypher · mcp-neo4j-cypherEPSS 0.39%via OSV
CVE-2026-41496High· 8.1
5mo ago

PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)

PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)

▾ Twilightpraisonai · praisonaiEPSS 0.41%via OSV
CVE-2026-41205High· 7.5
5mo ago

Mako: Path traversal via double-slash URI prefix in TemplateLookup

Mako: Path traversal via double-slash URI prefix in TemplateLookup

▾ Twilightmako · makoEPSS 0.53%via OSV
CVE-2026-41425Medium· 5.4
5mo ago

Authlib: Cross-site request forging when using cache

Authlib: Cross-site request forging when using cache

▾ Sunlitauthlib · authlibEPSS 0.14%via OSV
CVE-2026-41481Medium· 6.5
5mo ago

LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass

LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass

▾ Sunlitlangchain-text-splitters · langchain-text-splittersEPSS 0.44%via OSV
CVE-2026-34244Medium· 5.0
5mo ago

Weblate: SSRF via Project-Level Machinery Configuration

Weblate: SSRF via Project-Level Machinery Configuration

▾ Sunlitweblate · weblateEPSS 0.33%via OSV
CVE-2026-40474High· 7.6
5mo ago

wger has Broken Access Control in Global Gym Configuration Update Endpoint

wger has Broken Access Control in Global Gym Configuration Update Endpoint

▾ Twilightwger · wgerEPSS 0.40%via OSV
CVE-2026-41314Medium· 6.5
5mo ago

pypdf: Manipulated FlateDecode image dimensions can exhaust RAM

pypdf: Manipulated FlateDecode image dimensions can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.41%via OSV
CVE-2026-41206Medium
5mo ago

PySpector has a Plugin Code Execution Bypass via Incomplete Static Analysis in PluginSecurity.validate_plugin_code

PySpector has a Plugin Code Execution Bypass via Incomplete Static Analysis in PluginSecurity.validate_plugin_code

▾ Sunlitpyspector · pyspectorEPSS 0.19%via OSV
CVE-2026-33212Low· 3.1
5mo ago

Weblate: Improper access control for pending tasks in API

Weblate: Improper access control for pending tasks in API

▾ Sunlitweblate · weblateEPSS 0.26%via OSV
CVE-2025-54550High· 8.1
5mo ago

Apache Airflow: RCE by race condition in example_xcom dag

Apache Airflow: RCE by race condition in example_xcom dag

▾ Twilightapache-airflow · apache-airflowEPSS 0.58%via OSV
CVE-2026-31987High· 7.5
5mo ago

Apache Airflow: JWT token appearing in logs

Apache Airflow: JWT token appearing in logs

▾ Twilightapache-airflow · apache-airflowEPSS 0.83%via OSV
CVE-2026-34242High· 7.7
5mo ago

Weblate: Arbitrary File Read via Symlink

Weblate: Arbitrary File Read via Symlink

▾ Twilightweblate · weblateEPSS 0.53%via OSV
CVE-2026-40256Medium· 5.0
5mo ago

Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision

Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision

▾ Sunlitweblate · weblateEPSS 0.37%via OSV
CVE-2026-41312Medium· 6.5
5mo ago

pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM

pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.41%via OSV
CVE-2026-40353Medium· 5.4
5mo ago

wger has Stored XSS via Unescaped License Attribution Fields

wger has Stored XSS via Unescaped License Attribution Fields

▾ Sunlitwger · wgerEPSS 0.25%via OSV
CVE-2026-33440Medium· 5.0
5mo ago

Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads

Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads

▾ Sunlitweblate · weblateEPSS 0.31%via OSV
CVE-2026-41313Medium· 6.5
5mo ago

pypdf: Possible long runtimes for wrong size values in incremental mode

pypdf: Possible long runtimes for wrong size values in incremental mode

▾ Sunlitpypdf · pypdfEPSS 0.38%via OSV
CVE-2026-40602Medium· 5.6
5mo ago

Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates

Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates

▾ Sunlithomeassistant-cli · homeassistant-cliEPSS 0.14%via OSV
CVE-2026-6855High· 7.1
5mo ago

instructlab: InstructLab: Path traversal allows arbitrary directory creation and file write (CVE-2026-6855)

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbi…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI (RHEL AI) 3EPSS 0.22%via CSAF
CVE-2026-40347Medium· 5.3
5mo ago

python-multipart affected by Denial of Service via large multipart preamble or epilogue data

python-multipart affected by Denial of Service via large multipart preamble or epilogue data

▾ Sunlitpython-multipart · python-multipartEPSS 0.42%via OSV
CVE-2026-41168Medium· 5.3
5mo ago

pypdf has long runtimes for wrong size values in cross-reference and object streams

pypdf has long runtimes for wrong size values in cross-reference and object streams

▾ Sunlitpypdf · pypdfEPSS 0.52%via OSV
CVEs tagged “pip” — page 66 · VulnSea