Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-30974Medium· 4.6copyparty: volflag `nohtml` did not block javascript in svg files
copyparty: volflag `nohtml` did not block javascript in svg files
CVE-2026-27826High· 8.2PoCMCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
CVE-2026-30930HighGlances has SQL Injection via Process Names in TimescaleDB Export
Glances has SQL Injection via Process Names in TimescaleDB Export
CVE-2026-25960Medium· 5.4vLLM has SSRF Protection Bypass
vLLM has SSRF Protection Bypass
CVE-2026-30928HighPoCGlances Exposes Unauthenticated Configuration Secrets
Glances Exposes Unauthenticated Configuration Secrets
CVE-2025-69219High· 8.8PoCApache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
CVE-2026-25604Medium· 5.4PoCIn AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access co…
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access co…
CVE-2026-33010High· 8.1mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
CVE-2026-28802Critical· 9.8⚖ disputedAuthlib is a Python library which builds OAuth and OpenID Connect servers
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature…
GHSA-5r2p-pjr8-7fh7HighSageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality
SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality
CVE-2025-69534High· 7.5Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception,…
CVE-2026-29790Lowdbt-common's commonprefix() doesn't protect against path traversal
dbt-common's commonprefix() doesn't protect against path traversal
CVE-2025-45691High· 7.5RAGAS has an Arbitrary File Read vulnerability
RAGAS has an Arbitrary File Read vulnerability
CVE-2026-25048Highxgrammar vulnerable to DoS via multi-layer nesting
xgrammar vulnerable to DoS via multi-layer nesting
CVE-2026-29787Medium· 5.3mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint
mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint
CVE-2026-29780Medium· 5.5PoCeml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write
eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write
CVE-2026-29038Medium· 6.1changedetection.io has Reflected XSS in its RSS Tag Error Response
changedetection.io has Reflected XSS in its RSS Tag Error Response
CVE-2026-29039Highchangedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()
changedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()
CVE-2026-29065Highchangedetection.io has Zip Slip vulnerability in the backup restore functionality
changedetection.io has Zip Slip vulnerability in the backup restore functionality
CVE-2026-28681High· 8.1IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email links
IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email links
CVE-2026-28518High· 7.8OpenViking contains a Path Traversal vulnerability
OpenViking contains a Path Traversal vulnerability
CVE-2026-28222Medium· 6.1Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes
Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes
CVE-2026-28223Medium· 6.1Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interface
Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interface
CVE-2026-25674Low· 3.7Django has a Race Condition vulnerability
Django has a Race Condition vulnerability
CVE-2026-27905HighBentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction
BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction
CVE-2026-27622High· 8.4OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned in…
CVE-2026-25673High· 7.5Django vulnerable to Uncontrolled Resource Consumption
Django vulnerable to Uncontrolled Resource Consumption
CVE-2026-56315Critical· 9.8PickleScan has multiple stdlib modules with direct RCE not in blocklist
PickleScan has multiple stdlib modules with direct RCE not in blocklist
CVE-2026-28350Medium· 6.1lxml-html-clean has <base> tag injection through default Cleaner configuration
lxml-html-clean has <base> tag injection through default Cleaner configuration
CVE-2026-27932High· 7.5joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)
joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)