VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-33699Medium
6mo ago

pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream

pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream

▾ Sunlitpypdf · pypdfEPSS 0.58%via OSV
CVE-2026-33682Medium· 4.7
6mo ago

Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)

Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)

▾ Sunlitstreamlit · streamlitEPSS 0.34%via OSV
CVE-2026-5389High
6mo ago

JustHTML is vulnerable to XSS via code fence breakout in <pre> content

JustHTML is vulnerable to XSS via code fence breakout in <pre> content

▾ Twilightjusthtml · justhtmlEPSS 0.26%via OSV
CVE-2026-24159High· 7.8
6mo ago

NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution

NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution

▾ Twilightnemo-toolkit · nemo-toolkitEPSS 0.64%via OSV
CVE-2026-24157High· 7.8
6mo ago

NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading

NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading

▾ Twilightnemo-toolkit · nemo-toolkitEPSS 0.65%via OSV
CVE-2026-33545Medium· 5.3
6mo ago

MobSF has SQL Injection in its SQLite Database Viewer Utils

MobSF has SQL Injection in its SQLite Database Viewer Utils

▾ Sunlitmobsf · mobsfEPSS 0.40%via OSV
CVE-2026-33046High
6mo ago

Indico discloses local files resulting in Remote Code Execution through LaTeX injection

Indico discloses local files resulting in Remote Code Execution through LaTeX injection

▾ Twilightindico · indicoEPSS 1.0%via OSV
CVE-2026-26209Medium· 5.5⚖ disputed
6mo ago

cbor2: cbor2: Denial of Service due to uncontrolled recursion via crafted CBOR payloads (CVE-2026-26209)

A flaw was found in cbor2, a library for encoding and decoding Concise Binary Object Representation (CBOR) data. A remote attacker can exploit this vulnerability by sending a specially crafted CBOR payload containing deeply nested structur…

▾ SunlitRed Hat · Red Hat Enterprise Linux AI (RHEL AI) 3EPSS 0.65%via CSAF
CVE-2026-4539Low· 3.3
6mo ago

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

▾ Sunlitpygments · pygmentsEPSS 0.16%via OSV
CVE-2026-4506Medium· 6.3
6mo ago

MindSQL is vulnerable to Code Injection through its ask_db function

MindSQL is vulnerable to Code Injection through its ask_db function

▾ Sunlitmindsql · mindsqlEPSS 0.39%via OSV
CVE-2026-32711High· 7.8
6mo ago

pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root

pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root

▾ Twilightpydicom · pydicomEPSS 0.22%via OSV
CVE-2026-33154High· 7.5PoC
6mo ago

dynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection (CVE-2026-33154)

A flaw was found in dynaconf, a Python configuration management tool. This Server-Side Template Injection (SSTI) vulnerability occurs due to unsafe template evaluation in the @Jinja resolver when the jinja2 package is installed. A remote a…

▾ MidnightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.57%via CSAF
CVE-2026-33236High· 8.1
6mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the…

▾ Twilightnltk · nltkEPSS 0.71%via NVD
CVE-2026-33231High· 7.5PoC
6mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthentic…

▾ Midnightnltk · nltkEPSS 1.5%via NVD
CVE-2026-33509High· 7.5
6mo ago

pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration

pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration

▾ Twilightpyload-ng · pyload-ngEPSS 0.58%via OSV
CVE-2026-33332Medium· 5.3
6mo ago

NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustion

NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustion

▾ Sunlitnicegui · niceguiEPSS 0.69%via OSV
CVE-2025-15031High· 8.1
6mo ago

Arbitrary file write via tar traversal in mlflow

Arbitrary file write via tar traversal in mlflow

▾ Twilightmlflow · mlflowEPSS 0.85%via OSV
CVE-2026-27953High· 7.1
6mo ago

ormar Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model Constructor

ormar Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model Constructor

▾ Twilightormar · ormarEPSS 0.91%via OSV
CVE-2026-32889Medium· 6.5
6mo ago

Denial of service via non-terminating SYLT frame parsing loop in tinytag

Denial of service via non-terminating SYLT frame parsing loop in tinytag

▾ Sunlittinytag · tinytagEPSS 0.49%via OSV
CVE-2026-3029Medium
6mo ago

PyMuPDF has a path traversal in _main_.py

PyMuPDF has a path traversal in _main_.py

▾ Sunlitpymupdf · pymupdfEPSS 0.41%via OSV
CVE-2026-33310High· 8.8PoC
6mo ago

Intake has a Command Injection via shell() Expansion in Parameter Defaults

Intake has a Command Injection via shell() Expansion in Parameter Defaults

▾ Midnightintake · intakeEPSS 0.49%via OSV
CVE-2026-8630Medium
6mo ago

JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)

JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)

▾ Sunlitjusthtml · justhtmlEPSS 0.26%via OSV
CVE-2026-8445Medium
6mo ago

JustHTML has a Sanitizer Bypass (in Markdown)

JustHTML has a Sanitizer Bypass (in Markdown)

▾ Sunlitjusthtml · justhtmlEPSS 0.64%via OSV
CVE-2026-32874High· 7.5
6mo ago

UltraJSON has a Memory Leak parsing large integers allows DoS

UltraJSON has a Memory Leak parsing large integers allows DoS

▾ Twilightujson · ujsonEPSS 0.68%via OSV
CVE-2026-33125High· 7.1
6mo ago

Frigte has broken access control viewer user can delete admin and other users account

Frigte has broken access control viewer user can delete admin and other users account

▾ Twilightfrigate · frigateEPSS 0.37%via OSV
CVE-2026-33139High
6mo ago

PySpector has a Plugin Sandbox Bypass leads to Arbitrary Code Execution

PySpector has a Plugin Sandbox Bypass leads to Arbitrary Code Execution

▾ Twilightpyspector · pyspectorEPSS 0.18%via OSV
CVE-2026-33123Medium
6mo ago

pypdf has inefficient decoding of array-based streams

pypdf has inefficient decoding of array-based streams

▾ Sunlitpypdf · pypdfEPSS 0.37%via OSV
CVE-2026-30922High· 7.5PoC
6mo ago

pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)

An unbounded recursion flaw has been discovered in the pypi pyasn1 library. This uncontrolled recursion occurs when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing nested SEQUENCE (0x3…

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.93%via CSAF
CVE-2026-33230Medium· 6.1
6mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk

▾ Sunlitnltk · nltkEPSS 0.39%via OSV
CVE-2026-32875High· 7.5
6mo ago

UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop

UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop

▾ Twilightujson · ujsonEPSS 0.77%via OSV
CVEs tagged “pip” — page 73 · VulnSea