VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-33155High
6mo ago

DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT

DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT

▾ Twilightdeepdiff · deepdiffEPSS 0.52%via OSV
CVE-2026-33140Medium
6mo ago

Stored XSS in PySpector HTML Report Generation leads to Javascript Code Execution

Stored XSS in PySpector HTML Report Generation leads to Javascript Code Execution

▾ Sunlitpyspector · pyspectorEPSS 0.26%via OSV
CVE-2026-27459Critical· 9.8⚖ disputed
6mo ago

pyOpenSSL is a Python wrapper around the OpenSSL library

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL wou…

▾ Midnightpyopenssl · pyopensslEPSS 0.88%via NVD
CVE-2026-9769High
6mo ago

Uncontrolled recursion DoS in JustHTML() via deeply nested HTML

Uncontrolled recursion DoS in JustHTML() via deeply nested HTML

▾ Twilightjusthtml · justhtmlEPSS 0.49%via OSV
CVE-2026-4269High· 7.5
6mo ago

Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit

Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit

▾ Twilightbedrock-agentcore-starter-toolkit · bedrock-agentcore-starter-toolkitEPSS 0.42%via OSV
CVE-2026-28500High· 8.6
6mo ago

ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack

ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack

▾ Twilightonnx · onnxEPSS 0.31%via OSV
CVE-2025-14287High· 7.5
6mo ago

MLflow has a command injection in mlflow/sagemaker/__init__.py

MLflow has a command injection in mlflow/sagemaker/__init__.py

▾ Twilightmlflow · mlflowEPSS 1.5%via OSV
CVE-2026-32596HighPoC
6mo ago

Glances exposes the REST API without authentication

Glances exposes the REST API without authentication

▾ Midnightglances · glancesEPSS 1.7%via OSV
CVE-2026-32634High· 8.1
6mo ago

Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers

Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers

▾ Twilightglances · glancesEPSS 0.23%via OSV
CVE-2026-27448Low
6mo ago

pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback

pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback

▾ Sunlitpyopenssl · pyopensslEPSS 0.39%via OSV
CVE-2026-32608High· 7.0
6mo ago

Glances has a Command Injection via Process Names in Action Command Templates

Glances has a Command Injection via Process Names in Action Command Templates

▾ Twilightglances · glancesEPSS 0.20%via OSV
CVE-2026-32722Low· 3.6PoC
6mo ago

Stored XSS in Memray-generated HTML reports via unescaped command-line metadata

Stored XSS in Memray-generated HTML reports via unescaped command-line metadata

▾ Twilightmemray · memrayEPSS 0.35%via OSV
CVE-2026-32632Medium· 5.9
6mo ago

Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding

Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding

▾ Sunlitglances · glancesEPSS 0.18%via OSV
CVE-2026-32609High· 7.5
6mo ago

Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials

Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials

▾ Twilightglances · glancesEPSS 0.59%via OSV
CVE-2026-32610High· 8.1
6mo ago

Glances's Default CORS Configuration Allows Cross-Origin Credential Theft

Glances's Default CORS Configuration Allows Cross-Origin Credential Theft

▾ Twilightglances · glancesEPSS 0.49%via OSV
CVE-2026-28490High
6mo ago

Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle

Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle

▾ Twilightauthlib · authlibEPSS 0.16%via OSV
CVE-2026-4229High· 7.3
6mo ago

Vanna has a SQL injection in the remove_training_data function

Vanna has a SQL injection in the remove_training_data function

▾ Twilightvanna · vannaEPSS 0.41%via OSV
CVE-2026-32611High· 7.0
6mo ago

Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements

Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements

▾ Twilightglances · glancesEPSS 0.40%via OSV
CVE-2026-31899High· 7.5PoC
6mo ago

CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification

CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification

▾ Midnightcairosvg · cairosvgEPSS 0.52%via OSV
CVE-2026-32116High
6mo ago

Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite

Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite

▾ Twilightmagic-wormhole · magic-wormholeEPSS 0.51%via OSV
CVE-2026-32597High· 7.5PoC
6mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not …

▾ Midnightpyjwt_project · pyjwtEPSS 0.28%via NVD
CVE-2026-32112Medium· 6.8
6mo ago

ha-mcp has XSS via Unescaped HTML in OAuth Consent Form

ha-mcp has XSS via Unescaped HTML in OAuth Consent Form

▾ Sunlitha-mcp · ha-mcpEPSS 0.24%via OSV
CVE-2026-3989High· 7.8
6mo ago

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization

▾ Twilightsglang · sglangEPSS 0.43%via OSV
CVE-2026-32247High· 8.1PoC
6mo ago

Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters

Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters

▾ Midnightgraphiti-core · graphiti-coreEPSS 0.48%via OSV
CVE-2026-32111Medium· 5.3
6mo ago

ha-mcp OAuth 2.1 DCR mode enables network reconnaissance via an error oracle

ha-mcp OAuth 2.1 DCR mode enables network reconnaissance via an error oracle

▾ Sunlitha-mcp · ha-mcpEPSS 0.34%via OSV
CVE-2026-32274High· 7.5
6mo ago

Black: Arbitrary file writes from unsanitized user input in cache file name

Black: Arbitrary file writes from unsanitized user input in cache file name

▾ Twilightblack · blackEPSS 0.72%via OSV
CVE-2026-28356High· 7.5
6mo ago

multipart is a fast multipart/form-data parser for python

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential back…

▾ Twilightmultipart · multipartEPSS 1.0%via NVD
CVE-2026-31900Critical· 9.8PoC
6mo ago

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, us…

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A mal…

▾ Abyssalblack · blackEPSS 0.64%via OSV
CVE-2026-31826Medium
6mo ago

pypdf: manipulated stream length values can exhaust RAM

pypdf: manipulated stream length values can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.18%via OSV
CVE-2026-31815Medium· 5.3
6mo ago

django-unicorn affected by component state manipulation via unvalidated attribute access

django-unicorn affected by component state manipulation via unvalidated attribute access

▾ Sunlitdjango-unicorn · django-unicornEPSS 0.31%via OSV
CVEs tagged “pip” — page 74 · VulnSea