Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2024-56373High· 8.4Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
CVE-2026-23984HighApache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
CVE-2026-23983LowApache Superset allows authenticated users to view sensitive data without explicit permissions
Apache Superset allows authenticated users to view sensitive data without explicit permissions
CVE-2026-23980MediumPoCApache Superset allows privileged users to conduct error-based SQL Injection
Apache Superset allows privileged users to conduct error-based SQL Injection
CVE-2026-27469Medium· 6.1Isso affected by Stored XSS via comment website field
Isso affected by Stored XSS via comment website field
CVE-2025-27555Medium· 6.5Apache Airflow exposes sensitive information in its log files
Apache Airflow exposes sensitive information in its log files
CVE-2026-27156Medium· 6.1NiceGUI vulnerable to XSS via Code Injection during client-side element function execution
NiceGUI vulnerable to XSS via Code Injection during client-side element function execution
CVE-2026-23969MediumApache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
CVE-2026-27483High· 8.8PoCMindsDB: Path Traversal in /api/files Leading to Remote Code Execution
MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
CVE-2026-23982HighApache Superset Improper Authorization allows low-privileged users to bypass access controls
Apache Superset Improper Authorization allows low-privileged users to bypass access controls
CVE-2026-2969Medium· 4.7datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler
datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler
CVE-2026-2970Medium· 4.6datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache
datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache
CVE-2026-26331High· 8.8PoCyt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
CVE-2026-2033High· 8.10dayMLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
CVE-2025-65995Medium· 6.5Apache Airflow error reporting may expose full kwargs
Apache Airflow error reporting may expose full kwargs
CVE-2026-2473HighGoogle Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
CVE-2026-2472HighPoCGoogle Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
CVE-2026-27482Medium· 5.9Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
CVE-2026-25527Medium· 5.3PoCchangedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` ro…
changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This…
CVE-2026-27194HighD-Tale affected by Remote Code Execution through the /save-column-filter endpoint
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
CVE-2026-27205LowFlask session does not add `Vary: Cookie` header when accessed in some ways
Flask session does not add `Vary: Cookie` header when accessed in some ways
CVE-2026-27199MediumPoCWerkzeug safe_join() allows Windows special device names
Werkzeug safe_join() allows Windows special device names
MAL-2026-937NoneMalicious code in telebot-infee (PyPI)
Malicious code in telebot-infee (PyPI)
MAL-2026-935NoneMalicious code in telebot-infoo (PyPI)
Malicious code in telebot-infoo (PyPI)
MAL-2026-934NoneMalicious code in telebot-infoe (PyPI)
Malicious code in telebot-infoe (PyPI)
CVE-2026-27025Mediumpypdf has possible long runtimes/large memory usage for large /ToUnicode streams
pypdf has possible long runtimes/large memory usage for large /ToUnicode streams
CVE-2026-2654Medium· 6.3Hugging Face Smolagents has a Server-Side Request Forgery issue
Hugging Face Smolagents has a Server-Side Request Forgery issue
CVE-2025-33253High· 7.8NVIDIA NeMo Framework Deserializes Untrusted Data
NVIDIA NeMo Framework Deserializes Untrusted Data
CVE-2026-27026Mediumpypdf possibly has long runtimes for malformed FlateDecode streams
pypdf possibly has long runtimes for malformed FlateDecode streams
CVE-2026-27024Mediumpypdf has a possible infinite loop when processing TreeObject
pypdf has a possible infinite loop when processing TreeObject