VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-56078Medium· 6.5
5mo ago

PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

▾ Sunlitpraisonaiagents · praisonaiagentsEPSS 0.92%via OSV
CVE-2026-39981High· 8.8
5mo ago

AGiXT Vulnerable to Path Traversal in safe_join()

AGiXT Vulnerable to Path Traversal in safe_join()

▾ Twilightagixt · agixtEPSS 1.4%via OSV
CVE-2026-33753Medium· 6.2
5mo ago

rfc3161-client Has Improper Certificate Validation

rfc3161-client Has Improper Certificate Validation

▾ Sunlitrfc3161-client · rfc3161-clientEPSS 0.21%via OSV
CVE-2026-40035Critical· 9.1PoC
5mo ago

Unfurl - Werkzeug Debugger Exposure via String Config Parsing

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-em…

▾ Abyssalobsidianforensics · dfir-unfurlEPSS 0.72%via CVEORG
CVE-2026-40036High· 7.5PoC
5mo ago

Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression

Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/…

▾ Midnightobsidianforensics · dfir-unfurlEPSS 0.79%via CVEORG
CVE-2026-39892Critical· 9.8⚖ disputed
5mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this …

▾ Midnightcryptography.io · cryptographyEPSS 0.76%via NVD
CVE-2026-4292Low· 2.7
5mo ago

Django vulnerable to privilege abuse in ModelAdmin.list_editable

Django vulnerable to privilege abuse in ModelAdmin.list_editable

▾ Sunlitdjango · djangoEPSS 0.36%via OSV
CVE-2026-39373High· 7.5⚖ disputed
5mo ago

JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373)

A flaw was found in JWCrypto, a Python library for JSON Web Key (JWK), JSON Web Signature (JWS), and JSON Web Encryption (JWE) specifications. An unauthenticated attacker can exploit this vulnerability by sending specially crafted JWE toke…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2.5 for RHEL 8EPSS 0.43%via CSAF
CVE-2026-33034High· 7.5
5mo ago

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit

▾ Twilightdjango · djangoEPSS 0.85%via OSV
CVE-2026-33033Medium· 6.5PoC
5mo ago

Django has potential DoS via MultiPartParser through crafted multipart uploads

Django has potential DoS via MultiPartParser through crafted multipart uploads

▾ Twilightdjango · djangoEPSS 0.88%via OSV
CVE-2026-33866Medium· 4.3
5mo ago

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint

▾ Sunlitmlflow · mlflowEPSS 0.37%via OSV
GHSA-89gg-p5r5-q6r4High· 7.6
5mo ago

MONAI: Unsafe functions lead to pickle deserialization rce

MONAI: Unsafe functions lead to pickle deserialization rce

▾ Twilightmonai · monaivia OSV
CVE-2026-22680Medium· 5.3
5mo ago

OpenViking contains a missing authorization vulnerability in the task polling endpoints

OpenViking contains a missing authorization vulnerability in the task polling endpoints

▾ Sunlitopenviking · openvikingEPSS 0.38%via OSV
CVE-2026-1839Medium· 6.5
5mo ago

HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class

HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class

▾ Sunlittransformers · transformersEPSS 0.38%via OSV
CVE-2026-34444Critical· 10.0PoC
5mo ago

Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr

Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr

▾ Abyssallupa · lupaEPSS 0.80%via OSV
CVE-2026-1114Critical· 9.8
5mo ago

LoLLMs is vulnerable to Improper Access Control through weak secret key

LoLLMs is vulnerable to Improper Access Control through weak secret key

▾ Midnightlollms · lollmsEPSS 0.54%via OSV
CVE-2025-64182High· 7.8
5mo ago

OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()

OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()

▾ Twilightopenexr · openexrEPSS 0.24%via OSV
CVE-2026-39308High· 7.1
5mo ago

PraisonAI recipe registry publish path traversal allows out-of-root file write

PraisonAI recipe registry publish path traversal allows out-of-root file write

▾ Twilightpraisonai · praisonaiEPSS 0.46%via OSV
CVE-2026-26981Medium· 6.5
5mo ago

OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp

OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp

▾ Sunlitopenexr · openexrEPSS 0.50%via OSV
CVE-2026-35492Medium· 6.5PoC
5mo ago

kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write

kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write

▾ Twilightkedro-datasets · kedro-datasetsEPSS 0.45%via OSV
CVE-2026-34588High· 8.6
5mo ago

OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working w…

▾ TwilightAcademySoftwareFoundation · openexrEPSS 0.57%via CVEORG
CVE-2025-64183High· 7.5
5mo ago

OpenEXR has use after free in PyObject_StealAttrString

OpenEXR has use after free in PyObject_StealAttrString

▾ Twilightopenexr · openexrEPSS 0.30%via OSV
CVE-2026-39306High· 7.3
5mo ago

PraisonAI recipe registry pull path traversal writes files outside the chosen output directory

PraisonAI recipe registry pull path traversal writes files outside the chosen output directory

▾ Twilightpraisonai · praisonaiEPSS 0.43%via OSV
CVE-2026-39307High· 8.1
5mo ago

PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction

PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction

▾ Twilightpraisonai · praisonaiEPSS 0.46%via OSV
CVE-2025-64181High· 7.5
5mo ago

OpenEXR Makes Use of Uninitialized Memory

OpenEXR Makes Use of Uninitialized Memory

▾ Twilightopenexr · openexrEPSS 0.38%via OSV
CVE-2026-34756Medium· 6.5
5mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the…

▾ Sunlitvllm · vllmEPSS 0.77%via NVD
CVE-2026-34755Medium· 6.5
5mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/multimodal/media/video.py splits video/jpeg data URLs by comma to extract individual JPE…

▾ Sunlitvllm · vllmEPSS 0.84%via NVD
CVE-2026-5559Medium· 6.3
5mo ago

PyBlade: SSTI/RCE via Bypassed AST Validation in sandbox.py

PyBlade: SSTI/RCE via Bypassed AST Validation in sandbox.py

▾ Sunlitpyblade · pybladeEPSS 0.41%via OSV
CVE-2026-35463High· 8.8
5mo ago

pyLoad: Improper Neutralization of Special Elements used in an OS Command

pyLoad: Improper Neutralization of Special Elements used in an OS Command

▾ Twilightpyload-ng · pyload-ngEPSS 0.91%via OSV
CVE-2026-30762High· 7.5
5mo ago

LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass

LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass

▾ Twilightlightrag-hku · lightrag-hkuvia OSV
CVEs tagged “pip” — page 69 · VulnSea