Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-33699Mediumpypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream
pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream
CVE-2026-33682Medium· 4.7Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)
Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)
CVE-2026-5389HighJustHTML is vulnerable to XSS via code fence breakout in <pre> content
JustHTML is vulnerable to XSS via code fence breakout in <pre> content
CVE-2026-24159High· 7.8NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution
NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution
CVE-2026-24157High· 7.8NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading
NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading
CVE-2026-33545Medium· 5.3MobSF has SQL Injection in its SQLite Database Viewer Utils
MobSF has SQL Injection in its SQLite Database Viewer Utils
CVE-2026-33046HighIndico discloses local files resulting in Remote Code Execution through LaTeX injection
Indico discloses local files resulting in Remote Code Execution through LaTeX injection
CVE-2026-26209Medium· 5.5⚖ disputedcbor2: cbor2: Denial of Service due to uncontrolled recursion via crafted CBOR payloads (CVE-2026-26209)
A flaw was found in cbor2, a library for encoding and decoding Concise Binary Object Representation (CBOR) data. A remote attacker can exploit this vulnerability by sending a specially crafted CBOR payload containing deeply nested structur…
CVE-2026-4539Low· 3.3Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
CVE-2026-4506Medium· 6.3MindSQL is vulnerable to Code Injection through its ask_db function
MindSQL is vulnerable to Code Injection through its ask_db function
CVE-2026-32711High· 7.8pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root
pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root
CVE-2026-33154High· 7.5PoCdynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection (CVE-2026-33154)
A flaw was found in dynaconf, a Python configuration management tool. This Server-Side Template Injection (SSTI) vulnerability occurs due to unsafe template evaluation in the @Jinja resolver when the jinja2 package is installed. A remote a…
CVE-2026-33236High· 8.1NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the…
CVE-2026-33231High· 7.5PoCNLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthentic…
CVE-2026-33509High· 7.5pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration
pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration
CVE-2026-33332Medium· 5.3NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustion
NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustion
CVE-2025-15031High· 8.1Arbitrary file write via tar traversal in mlflow
Arbitrary file write via tar traversal in mlflow
CVE-2026-27953High· 7.1ormar Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model Constructor
ormar Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model Constructor
CVE-2026-32889Medium· 6.5Denial of service via non-terminating SYLT frame parsing loop in tinytag
Denial of service via non-terminating SYLT frame parsing loop in tinytag
CVE-2026-3029MediumPyMuPDF has a path traversal in _main_.py
PyMuPDF has a path traversal in _main_.py
CVE-2026-33310High· 8.8PoCIntake has a Command Injection via shell() Expansion in Parameter Defaults
Intake has a Command Injection via shell() Expansion in Parameter Defaults
CVE-2026-8630MediumJustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)
JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)
CVE-2026-8445MediumJustHTML has a Sanitizer Bypass (in Markdown)
JustHTML has a Sanitizer Bypass (in Markdown)
CVE-2026-32874High· 7.5UltraJSON has a Memory Leak parsing large integers allows DoS
UltraJSON has a Memory Leak parsing large integers allows DoS
CVE-2026-33125High· 7.1Frigte has broken access control viewer user can delete admin and other users account
Frigte has broken access control viewer user can delete admin and other users account
CVE-2026-33139HighPySpector has a Plugin Sandbox Bypass leads to Arbitrary Code Execution
PySpector has a Plugin Sandbox Bypass leads to Arbitrary Code Execution
CVE-2026-33123Mediumpypdf has inefficient decoding of array-based streams
pypdf has inefficient decoding of array-based streams
CVE-2026-30922High· 7.5PoCpyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)
An unbounded recursion flaw has been discovered in the pypi pyasn1 library. This uncontrolled recursion occurs when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing nested SEQUENCE (0x3…
CVE-2026-33230Medium· 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk
CVE-2026-32875High· 7.5UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop