Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-34400Mediumalerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API
alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API
CVE-2026-32727High· 8.1SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
CVE-2026-27489Highonnx Vulnerable to Path Traversal via Symlink
onnx Vulnerable to Path Traversal via Symlink
CVE-2026-34070High· 7.5PoCLangChain is a framework for building agents and LLM-powered applications
LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating again…
CVE-2025-15036Critical· 9.6MLFlow path traversal vulnerability
MLFlow path traversal vulnerability
CVE-2025-15379Critical· 10.0A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependen…
CVE-2026-34231Medium· 6.1Slippers Vulnerable to Cross-Site Scripting (XSS) in `attrs` Template Tag
Slippers Vulnerable to Cross-Site Scripting (XSS) in `attrs` Template Tag
CVE-2026-33641High· 7.8PoCGlances Vulnerable to Command Injection via Dynamic Configuration Values
Glances Vulnerable to Command Injection via Dynamic Configuration Values
CVE-2026-33533HighGlances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
CVE-2026-0560High· 7.5PoCA Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/exp…
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails …
CVE-2026-0558Critical· 9.8PoCA vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through t…
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other f…
CVE-2026-34073Medium· 5.3cryptography has incomplete DNS name constraint enforcement on peer names
cryptography has incomplete DNS name constraint enforcement on peer names
CVE-2026-29071Low· 3.1Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
CVE-2026-28786Medium· 4.3Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`
Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`
CVE-2026-33980High· 8.3PoCAzure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries
Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries
CVE-2026-33044LowHome Assistant has stored XSS in Map-card through malicious device name
Home Assistant has stored XSS in Map-card through malicious device name
CVE-2026-28788High· 7.1Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite
Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite
CVE-2025-15381High· 8.1MLFlow allows Tracing + Assessments Access
MLFlow allows Tracing + Assessments Access
CVE-2026-34172HighGiskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
CVE-2026-33936Medium· 5.3PoCpython-ecdsa: Denial of Service via improper DER length validation in crafted private keys
python-ecdsa: Denial of Service via improper DER length validation in crafted private keys
CVE-2026-34046HighLangflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CVE-2026-33981HighChangedetection.io Discloses Environment Variables via jq env Builtin in Include Filters
Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters
CVE-2026-4963Medium· 6.3Hugging Face Smolagents has an Injection issue
Hugging Face Smolagents has an Injection issue
CVE-2026-29070Medium· 5.4Open WebUI has unauthorized deletion of knowledge files
Open WebUI has unauthorized deletion of knowledge files
CVE-2026-33045LowHome Assistant has stored XSS in history-graphs
Home Assistant has stored XSS in history-graphs
CVE-2026-27893High· 8.8vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the…
GHSA-wcjx-v2wj-xg87High· 7.5C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)
C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)
CVE-2026-27602High· 7.2Modoboa has OS Command Injection
Modoboa has OS Command Injection
CVE-2025-70887HighSignify allows a remote attacker to escalate privileges via the signed_data.py and the context.py components
Signify allows a remote attacker to escalate privileges via the signed_data.py and the context.py components
CVE-2026-25645Medium· 4.4PoCRequests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function