VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-34400Medium
6mo ago

alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API

alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API

▾ Sunlitalerta-server · alerta-serverEPSS 0.59%via OSV
CVE-2026-32727High· 8.1
6mo ago

SciTokens has an Authorization Bypass via Path Traversal in Scope Validation

SciTokens has an Authorization Bypass via Path Traversal in Scope Validation

▾ Twilightscitokens · scitokensEPSS 0.53%via OSV
CVE-2026-27489High
6mo ago

onnx Vulnerable to Path Traversal via Symlink

onnx Vulnerable to Path Traversal via Symlink

▾ Twilightonnx · onnxEPSS 0.62%via OSV
CVE-2026-34070High· 7.5PoC
6mo ago

LangChain is a framework for building agents and LLM-powered applications

LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating again…

▾ Midnightlangchain · langchain_coreEPSS 1.2%via NVD
CVE-2025-15036Critical· 9.6
6mo ago

MLFlow path traversal vulnerability

MLFlow path traversal vulnerability

▾ Midnightmlflow · mlflowEPSS 0.58%via OSV
CVE-2025-15379Critical· 10.0
6mo ago

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependen…

▾ Midnightlfprojects · mlflowEPSS 2.4%via NVD
CVE-2026-34231Medium· 6.1
6mo ago

Slippers Vulnerable to Cross-Site Scripting (XSS) in `attrs` Template Tag

Slippers Vulnerable to Cross-Site Scripting (XSS) in `attrs` Template Tag

▾ Sunlitslippers · slippersEPSS 0.34%via OSV
CVE-2026-33641High· 7.8PoC
6mo ago

Glances Vulnerable to Command Injection via Dynamic Configuration Values

Glances Vulnerable to Command Injection via Dynamic Configuration Values

▾ Midnightglances · glancesEPSS 0.78%via OSV
CVE-2026-33533High
6mo ago

Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard

Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard

▾ Twilightglances · glancesEPSS 0.47%via OSV
CVE-2026-0560High· 7.5PoC
6mo ago

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/exp…

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails …

▾ Midnightlollms · lollmsEPSS 1.8%via OSV
CVE-2026-0558Critical· 9.8PoC
6mo ago

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through t…

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other f…

▾ Abyssallollms · lollmsEPSS 2.0%via OSV
CVE-2026-34073Medium· 5.3
6mo ago

cryptography has incomplete DNS name constraint enforcement on peer names

cryptography has incomplete DNS name constraint enforcement on peer names

▾ Sunlitcryptography · cryptographyEPSS 0.17%via OSV
CVE-2026-29071Low· 3.1
6mo ago

Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories

Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories

▾ Sunlitopen-webui · open-webuiEPSS 0.27%via OSV
CVE-2026-28786Medium· 4.3
6mo ago

Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`

Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`

▾ Sunlitopen-webui · open-webuiEPSS 0.42%via OSV
CVE-2026-33980High· 8.3PoC
6mo ago

Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries

Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries

▾ Midnightadx-mcp-server · adx-mcp-serverEPSS 0.43%via OSV
CVE-2026-33044Low
6mo ago

Home Assistant has stored XSS in Map-card through malicious device name

Home Assistant has stored XSS in Map-card through malicious device name

▾ Sunlithomeassistant · homeassistantEPSS 0.28%via OSV
CVE-2026-28788High· 7.1
6mo ago

Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite

Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite

▾ Twilightopen-webui · open-webuiEPSS 0.38%via OSV
CVE-2025-15381High· 8.1
6mo ago

MLFlow allows Tracing + Assessments Access

MLFlow allows Tracing + Assessments Access

▾ Twilightmlflow · mlflowEPSS 0.33%via OSV
CVE-2026-34172High
6mo ago

Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment

Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment

▾ Twilightgiskard-agents · giskard-agentsEPSS 0.84%via OSV
CVE-2026-33936Medium· 5.3PoC
6mo ago

python-ecdsa: Denial of Service via improper DER length validation in crafted private keys

python-ecdsa: Denial of Service via improper DER length validation in crafted private keys

▾ Twilightecdsa · ecdsaEPSS 0.52%via OSV
CVE-2026-34046High
6mo ago

Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

▾ Twilightlangflow · langflowEPSS 0.68%via OSV
CVE-2026-33981High
6mo ago

Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters

Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.48%via OSV
CVE-2026-4963Medium· 6.3
6mo ago

Hugging Face Smolagents has an Injection issue

Hugging Face Smolagents has an Injection issue

▾ Sunlitsmolagents · smolagentsEPSS 0.73%via OSV
CVE-2026-29070Medium· 5.4
6mo ago

Open WebUI has unauthorized deletion of knowledge files

Open WebUI has unauthorized deletion of knowledge files

▾ Sunlitopen-webui · open-webuiEPSS 0.38%via OSV
CVE-2026-33045Low
6mo ago

Home Assistant has stored XSS in history-graphs

Home Assistant has stored XSS in history-graphs

▾ Sunlithomeassistant · homeassistantEPSS 0.25%via OSV
CVE-2026-27893High· 8.8
6mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the…

▾ Twilightvllm · vllmEPSS 1.8%via NVD
GHSA-wcjx-v2wj-xg87High· 7.5
6mo ago

C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)

C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)

▾ Twilightc2cciutils · c2cciutilsvia OSV
CVE-2026-27602High· 7.2
6mo ago

Modoboa has OS Command Injection

Modoboa has OS Command Injection

▾ Twilightmodoboa · modoboaEPSS 0.69%via OSV
CVE-2025-70887High
6mo ago

Signify allows a remote attacker to escalate privileges via the signed_data.py and the context.py components

Signify allows a remote attacker to escalate privileges via the signed_data.py and the context.py components

▾ Twilightsignify · signifyEPSS 0.34%via OSV
CVE-2026-25645Medium· 4.4PoC
6mo ago

Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function

Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function

▾ Twilightrequests · requestsEPSS 0.18%via OSV
CVEs tagged “pip” — page 72 · VulnSea