VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-30974Medium· 4.6
6mo ago

copyparty: volflag `nohtml` did not block javascript in svg files

copyparty: volflag `nohtml` did not block javascript in svg files

▾ Sunlitcopyparty · copypartyEPSS 0.34%via OSV
CVE-2026-27826High· 8.2PoC
6mo ago

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

▾ Midnightmcp-atlassian · mcp-atlassianEPSS 1.0%via OSV
CVE-2026-30930High
6mo ago

Glances has SQL Injection via Process Names in TimescaleDB Export

Glances has SQL Injection via Process Names in TimescaleDB Export

▾ Twilightglances · glancesEPSS 0.41%via OSV
CVE-2026-25960Medium· 5.4
6mo ago

vLLM has SSRF Protection Bypass

vLLM has SSRF Protection Bypass

▾ Sunlitvllm · vllmEPSS 0.72%via OSV
CVE-2026-30928HighPoC
6mo ago

Glances Exposes Unauthenticated Configuration Secrets

Glances Exposes Unauthenticated Configuration Secrets

▾ Midnightglances · glancesEPSS 1.6%via OSV
CVE-2025-69219High· 8.8PoC
6mo ago

Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator

Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator

▾ Midnightapache-airflow-providers-http · apache-airflow-providers-httpEPSS 0.69%via OSV
CVE-2026-25604Medium· 5.4PoC
6mo ago

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access co…

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access co…

▾ Twilightapache · apache-airflow-providers-amazonEPSS 0.51%via NVD
CVE-2026-33010High· 8.1
6mo ago

mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft

mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft

▾ Twilightmcp-memory-service · mcp-memory-serviceEPSS 0.46%via OSV
CVE-2026-28802Critical· 9.8⚖ disputed
6mo ago

Authlib is a Python library which builds OAuth and OpenID Connect servers

Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature…

▾ Midnightauthlib · authlibEPSS 0.55%via NVD
GHSA-5r2p-pjr8-7fh7High
6mo ago

SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality

SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality

▾ Twilightsagemaker · sagemakervia OSV
CVE-2025-69534High· 7.5
6mo ago

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception,…

▾ Twilightpython-markdown · markdownEPSS 0.57%via NVD
CVE-2026-29790Low
6mo ago

dbt-common's commonprefix() doesn't protect against path traversal

dbt-common's commonprefix() doesn't protect against path traversal

▾ Sunlitdbt-common · dbt-commonEPSS 0.38%via OSV
CVE-2025-45691High· 7.5
6mo ago

RAGAS has an Arbitrary File Read vulnerability

RAGAS has an Arbitrary File Read vulnerability

▾ Twilightragas · ragasEPSS 0.53%via OSV
CVE-2026-25048High
6mo ago

xgrammar vulnerable to DoS via multi-layer nesting

xgrammar vulnerable to DoS via multi-layer nesting

▾ Twilightxgrammar · xgrammarEPSS 0.71%via OSV
CVE-2026-29787Medium· 5.3
6mo ago

mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint

mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint

▾ Sunlitmcp-memory-service · mcp-memory-serviceEPSS 0.41%via OSV
CVE-2026-29780Medium· 5.5PoC
6mo ago

eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write

eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write

▾ Twilighteml-parser · eml-parserEPSS 0.18%via OSV
CVE-2026-29038Medium· 6.1
6mo ago

changedetection.io has Reflected XSS in its RSS Tag Error Response

changedetection.io has Reflected XSS in its RSS Tag Error Response

▾ Sunlitchangedetection-io · changedetection-ioEPSS 0.34%via OSV
CVE-2026-29039High
6mo ago

changedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()

changedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.51%via OSV
CVE-2026-29065High
6mo ago

changedetection.io has Zip Slip vulnerability in the backup restore functionality

changedetection.io has Zip Slip vulnerability in the backup restore functionality

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.56%via OSV
CVE-2026-28681High· 8.1
6mo ago

IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email links

IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email links

▾ Twilightirrd · irrdEPSS 0.55%via OSV
CVE-2026-28518High· 7.8
7mo ago

OpenViking contains a Path Traversal vulnerability

OpenViking contains a Path Traversal vulnerability

▾ Twilightopenviking · openvikingEPSS 0.18%via OSV
CVE-2026-28222Medium· 6.1
7mo ago

Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes

Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes

▾ Sunlitwagtail · wagtailEPSS 0.59%via OSV
CVE-2026-28223Medium· 6.1
7mo ago

Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interface

Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interface

▾ Sunlitwagtail · wagtailEPSS 0.59%via OSV
CVE-2026-25674Low· 3.7
7mo ago

Django has a Race Condition vulnerability

Django has a Race Condition vulnerability

▾ Sunlitdjango · djangoEPSS 0.33%via OSV
CVE-2026-27905High
7mo ago

BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction

BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction

▾ Twilightbentoml · bentomlEPSS 0.21%via OSV
CVE-2026-27622High· 8.4
7mo ago

OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned in…

▾ TwilightAcademySoftwareFoundation · openexrEPSS 0.21%via CVEORG
CVE-2026-25673High· 7.5
7mo ago

Django vulnerable to Uncontrolled Resource Consumption

Django vulnerable to Uncontrolled Resource Consumption

▾ Twilightdjango · djangoEPSS 1.1%via OSV
CVE-2026-56315Critical· 9.8
7mo ago

PickleScan has multiple stdlib modules with direct RCE not in blocklist

PickleScan has multiple stdlib modules with direct RCE not in blocklist

▾ Midnightpicklescan · picklescanEPSS 1.1%via OSV
CVE-2026-28350Medium· 6.1
7mo ago

lxml-html-clean has <base> tag injection through default Cleaner configuration

lxml-html-clean has <base> tag injection through default Cleaner configuration

▾ Sunlitlxml-html-clean · lxml-html-cleanEPSS 0.27%via OSV
CVE-2026-27932High· 7.5
7mo ago

joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)

joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)

▾ Twilightjoserfc · joserfcEPSS 0.33%via OSV
CVEs tagged “pip” — page 75 · VulnSea