Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-28795HighOpenChatBI has a Path Traversal Vulnerability in save_report Tool
OpenChatBI has a Path Traversal Vulnerability in save_report Tool
CVE-2026-28348Medium· 6.1lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes
lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes
CVE-2026-28804Mediumpypdf vulnerable to inefficient decoding of ASCIIHexDecode streams
pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams
CVE-2026-28438HighCocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements
CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements
CVE-2026-2256Medium· 6.5PoCMS-Agent vulnerable to Command Injection
MS-Agent vulnerable to Command Injection
CVE-2026-28352Medium· 6.5Indico has a missing access check in the event series management API
Indico has a missing access check in the event series management API
CVE-2026-28351Mediumpypdf: Manipulated RunLengthDecode streams can exhaust RAM
pypdf: Manipulated RunLengthDecode streams can exhaust RAM
GHSA-747p-wmpv-9c78Medium· 5.9AWS CLI: cli_history database does not restrict file permissions on Unix systems
AWS CLI: cli_history database does not restrict file permissions on Unix systems
CVE-2026-28231Critical· 9.1pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the en…
pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by provid…
CVE-2026-27941Critical· 9.9PoCOpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repo…
OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from fork…
CVE-2026-27835Medium· 4.3wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
CVE-2026-27888Mediumpypdf: Manipulated FlateDecode XFA streams can exhaust RAM
pypdf: Manipulated FlateDecode XFA streams can exhaust RAM
CVE-2026-27457Medium· 4.3Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
CVE-2026-27735Mediummcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
CVE-2026-27839Medium· 4.3wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup
wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup
CVE-2026-27948Medium· 5.4Copyparty vulnerable to reflected XSS via setck parameter
Copyparty vulnerable to reflected XSS via setck parameter
CVE-2026-27838Low· 3.1wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
CVE-2026-27809Mediumpsd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
CVE-2026-26717Medium· 4.8PoCOpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
CVE-2026-25733High· 7.3Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
CVE-2026-27645Medium· 6.1PoCchangedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
CVE-2026-27794Medium· 6.6LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution
LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution
CVE-2026-25734Medium· 6.1Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
CVE-2026-25136High· 8.1Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
CVE-2026-25736Medium· 6.1Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
CVE-2026-25735Medium· 6.1Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
CVE-2026-27695Medium· 4.3zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service
zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service
CVE-2026-27696High· 8.6changedetection.io is Vulnerable to SSRF via Watch URLs
changedetection.io is Vulnerable to SSRF via Watch URLs
CVE-2026-25138Medium· 5.3Rucio WebUI has Username Enumeration via Login Error Message
Rucio WebUI has Username Enumeration via Login Error Message
CVE-2026-27628High· 7.5pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams (CVE-2026-27628)
A flaw was found in pypdf. Processing a specially crafted PDF document, specifically with circular /Prev references in the cross-reference (xref) chain, can cause an infinite loop and a high consumption of CPU, resulting in a denial of ser…