VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-28795High
7mo ago

OpenChatBI has a Path Traversal Vulnerability in save_report Tool

OpenChatBI has a Path Traversal Vulnerability in save_report Tool

▾ Twilightopenchatbi · openchatbiEPSS 0.68%via OSV
CVE-2026-28348Medium· 6.1
7mo ago

lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes

lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes

▾ Sunlitlxml-html-clean · lxml-html-cleanEPSS 0.28%via OSV
CVE-2026-28804Medium
7mo ago

pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams

pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams

▾ Sunlitpypdf · pypdfEPSS 0.52%via OSV
CVE-2026-28438High
7mo ago

CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements

CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements

▾ Twilightcocoindex · cocoindexEPSS 0.50%via OSV
CVE-2026-2256Medium· 6.5PoC
7mo ago

MS-Agent vulnerable to Command Injection

MS-Agent vulnerable to Command Injection

▾ Twilightms-agent · ms-agentEPSS 1.6%via OSV
CVE-2026-28352Medium· 6.5
7mo ago

Indico has a missing access check in the event series management API

Indico has a missing access check in the event series management API

▾ Sunlitindico · indicoEPSS 0.36%via OSV
CVE-2026-28351Medium
7mo ago

pypdf: Manipulated RunLengthDecode streams can exhaust RAM

pypdf: Manipulated RunLengthDecode streams can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.53%via OSV
GHSA-747p-wmpv-9c78Medium· 5.9
7mo ago

AWS CLI: cli_history database does not restrict file permissions on Unix systems

AWS CLI: cli_history database does not restrict file permissions on Unix systems

▾ Sunlitawscli · awsclivia OSV
CVE-2026-28231Critical· 9.1
7mo ago

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the en…

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by provid…

▾ Midnightpi-heif · pi-heifEPSS 0.71%via OSV
CVE-2026-27941Critical· 9.9PoC
7mo ago

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repo…

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from fork…

▾ Abyssalopenlit · openlitEPSS 0.57%via OSV
CVE-2026-27835Medium· 4.3
7mo ago

wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data

wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data

▾ Sunlitwger · wgerEPSS 0.30%via OSV
CVE-2026-27888Medium
7mo ago

pypdf: Manipulated FlateDecode XFA streams can exhaust RAM

pypdf: Manipulated FlateDecode XFA streams can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.64%via OSV
CVE-2026-27457Medium· 4.3
7mo ago

Weblate: Missing access control for the AddonViewSet API exposes all addon configurations

Weblate: Missing access control for the AddonViewSet API exposes all addon configurations

▾ Sunlitweblate · weblateEPSS 0.42%via OSV
CVE-2026-27735Medium
7mo ago

mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries

mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries

▾ Sunlitmcp-server-git · mcp-server-gitEPSS 0.45%via OSV
CVE-2026-27839Medium· 4.3
7mo ago

wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup

wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup

▾ Sunlitwger · wgerEPSS 0.31%via OSV
CVE-2026-27948Medium· 5.4
7mo ago

Copyparty vulnerable to reflected XSS via setck parameter

Copyparty vulnerable to reflected XSS via setck parameter

▾ Sunlitcopyparty · copypartyEPSS 0.27%via OSV
CVE-2026-27838Low· 3.1
7mo ago

wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

▾ Sunlitwger · wgerEPSS 0.25%via OSV
CVE-2026-27809Medium
7mo ago

psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps

psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps

▾ Sunlitpsd-tools · psd-toolsEPSS 0.69%via OSV
CVE-2026-26717Medium· 4.8PoC
7mo ago

OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function

OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function

▾ Twilightrichie · richieEPSS 0.51%via OSV
CVE-2026-25733High· 7.3
7mo ago

Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function

Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function

▾ Twilightrucio-webui · rucio-webuiEPSS 0.41%via OSV
CVE-2026-27645Medium· 6.1PoC
7mo ago

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.49%via OSV
CVE-2026-27794Medium· 6.6
7mo ago

LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution

LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution

▾ Sunlitlanggraph-checkpoint · langgraph-checkpointEPSS 0.96%via OSV
CVE-2026-25734Medium· 6.1
7mo ago

Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata

Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata

▾ Sunlitrucio-webui · rucio-webuiEPSS 0.46%via OSV
CVE-2026-25136High· 8.1
7mo ago

Rucio WebUI has a Reflected Cross-site Scripting Vulnerability

Rucio WebUI has a Reflected Cross-site Scripting Vulnerability

▾ Twilightrucio-webui · rucio-webuiEPSS 0.27%via OSV
CVE-2026-25736Medium· 6.1
7mo ago

Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute

Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute

▾ Sunlitrucio-webui · rucio-webuiEPSS 0.46%via OSV
CVE-2026-25735Medium· 6.1
7mo ago

Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name

Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name

▾ Sunlitrucio-webui · rucio-webuiEPSS 0.46%via OSV
CVE-2026-27695Medium· 4.3
7mo ago

zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service

zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service

▾ Sunlitzae-limiter · zae-limiterEPSS 0.40%via OSV
CVE-2026-27696High· 8.6
7mo ago

changedetection.io is Vulnerable to SSRF via Watch URLs

changedetection.io is Vulnerable to SSRF via Watch URLs

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.48%via OSV
CVE-2026-25138Medium· 5.3
7mo ago

Rucio WebUI has Username Enumeration via Login Error Message

Rucio WebUI has Username Enumeration via Login Error Message

▾ Sunlitrucio-webui · rucio-webuiEPSS 0.33%via OSV
CVE-2026-27628High· 7.5
7mo ago

pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams (CVE-2026-27628)

A flaw was found in pypdf. Processing a specially crafted PDF document, specifically with circular /Prev references in the cross-reference (xref) chain, can cause an infinite loop and a high consumption of CPU, resulting in a denial of ser…

▾ TwilightRed Hat · Red Hat Quay 3.16EPSS 0.61%via CSAF
CVEs tagged “pip” — page 76 · VulnSea