VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2024-56373High· 8.4
7mo ago

Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table

Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table

▾ Twilightapache-airflow · apache-airflowEPSS 1.1%via OSV
CVE-2026-23984High
7mo ago

Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections

Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections

▾ Twilightapache-superset · apache-supersetEPSS 0.36%via OSV
CVE-2026-23983Low
7mo ago

Apache Superset allows authenticated users to view sensitive data without explicit permissions

Apache Superset allows authenticated users to view sensitive data without explicit permissions

▾ Sunlitapache-superset · apache-supersetEPSS 0.42%via OSV
CVE-2026-23980MediumPoC
7mo ago

Apache Superset allows privileged users to conduct error-based SQL Injection

Apache Superset allows privileged users to conduct error-based SQL Injection

▾ Twilightapache-superset · apache-supersetEPSS 0.65%via OSV
CVE-2026-27469Medium· 6.1
7mo ago

Isso affected by Stored XSS via comment website field

Isso affected by Stored XSS via comment website field

▾ Sunlitisso · issoEPSS 0.37%via OSV
CVE-2025-27555Medium· 6.5
7mo ago

Apache Airflow exposes sensitive information in its log files

Apache Airflow exposes sensitive information in its log files

▾ Sunlitapache-airflow · apache-airflowEPSS 0.37%via OSV
CVE-2026-27156Medium· 6.1
7mo ago

NiceGUI vulnerable to XSS via Code Injection during client-side element function execution

NiceGUI vulnerable to XSS via Code Injection during client-side element function execution

▾ Sunlitnicegui · niceguiEPSS 0.27%via OSV
CVE-2026-23969Medium
7mo ago

Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine

Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine

▾ Sunlitapache-superset · apache-supersetEPSS 0.62%via OSV
CVE-2026-27483High· 8.8PoC
7mo ago

MindsDB: Path Traversal in /api/files Leading to Remote Code Execution

MindsDB: Path Traversal in /api/files Leading to Remote Code Execution

▾ Midnightmindsdb · mindsdbEPSS 8.8%via OSV
CVE-2026-23982High
7mo ago

Apache Superset Improper Authorization allows low-privileged users to bypass access controls

Apache Superset Improper Authorization allows low-privileged users to bypass access controls

▾ Twilightapache-superset · apache-supersetEPSS 0.45%via OSV
CVE-2026-2969Medium· 4.7
7mo ago

datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler

datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler

▾ Sunlitdatapizza-ai-core · datapizza-ai-coreEPSS 0.79%via OSV
CVE-2026-2970Medium· 4.6
7mo ago

datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache

datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache

▾ Sunlitdatapizza-ai-core · datapizza-ai-coreEPSS 1.1%via OSV
CVE-2026-26331High· 8.8PoC
7mo ago

yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

▾ Midnightyt-dlp · yt-dlpEPSS 2.0%via OSV
CVE-2026-2033High· 8.10day
7mo ago

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

▾ Abyssalmlflow · mlflowEPSS 1.7%via OSV
CVE-2025-65995Medium· 6.5
7mo ago

Apache Airflow error reporting may expose full kwargs

Apache Airflow error reporting may expose full kwargs

▾ Sunlitapache-airflow · apache-airflowEPSS 0.81%via OSV
CVE-2026-2473High
7mo ago

Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming

Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming

▾ Twilightgoogle-cloud-aiplatform · google-cloud-aiplatformEPSS 0.46%via OSV
CVE-2026-2472HighPoC
7mo ago

Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)

Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)

▾ Midnightgoogle-cloud-aiplatform · google-cloud-aiplatformEPSS 0.54%via OSV
CVE-2026-27482Medium· 5.9
7mo ago

Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)

Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)

▾ Sunlitray · rayEPSS 0.40%via OSV
CVE-2026-25527Medium· 5.3PoC
7mo ago

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` ro…

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This…

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.89%via OSV
CVE-2026-27194High
7mo ago

D-Tale affected by Remote Code Execution through the /save-column-filter endpoint

D-Tale affected by Remote Code Execution through the /save-column-filter endpoint

▾ Twilightdtale · dtaleEPSS 0.96%via OSV
CVE-2026-27205Low
7mo ago

Flask session does not add `Vary: Cookie` header when accessed in some ways

Flask session does not add `Vary: Cookie` header when accessed in some ways

▾ Sunlitflask · flaskEPSS 0.42%via OSV
CVE-2026-27199MediumPoC
7mo ago

Werkzeug safe_join() allows Windows special device names

Werkzeug safe_join() allows Windows special device names

▾ Twilightwerkzeug · werkzeugEPSS 0.54%via OSV
MAL-2026-937None
7mo ago

Malicious code in telebot-infee (PyPI)

Malicious code in telebot-infee (PyPI)

▾ Sunlittelebot-infee · telebot-infeevia OSV
MAL-2026-935None
7mo ago

Malicious code in telebot-infoo (PyPI)

Malicious code in telebot-infoo (PyPI)

▾ Sunlittelebot-infoo · telebot-infoovia OSV
MAL-2026-934None
7mo ago

Malicious code in telebot-infoe (PyPI)

Malicious code in telebot-infoe (PyPI)

▾ Sunlittelebot-infoe · telebot-infoevia OSV
CVE-2026-27025Medium
7mo ago

pypdf has possible long runtimes/large memory usage for large /ToUnicode streams

pypdf has possible long runtimes/large memory usage for large /ToUnicode streams

▾ Sunlitpypdf · pypdfEPSS 0.18%via OSV
CVE-2026-2654Medium· 6.3
7mo ago

Hugging Face Smolagents has a Server-Side Request Forgery issue

Hugging Face Smolagents has a Server-Side Request Forgery issue

▾ Sunlitsmolagents · smolagentsEPSS 0.55%via OSV
CVE-2025-33253High· 7.8
7mo ago

NVIDIA NeMo Framework Deserializes Untrusted Data

NVIDIA NeMo Framework Deserializes Untrusted Data

▾ Twilightnemo-toolkit · nemo-toolkitEPSS 0.19%via OSV
CVE-2026-27026Medium
7mo ago

pypdf possibly has long runtimes for malformed FlateDecode streams

pypdf possibly has long runtimes for malformed FlateDecode streams

▾ Sunlitpypdf · pypdfEPSS 0.18%via OSV
CVE-2026-27024Medium
7mo ago

pypdf has a possible infinite loop when processing TreeObject

pypdf has a possible infinite loop when processing TreeObject

▾ Sunlitpypdf · pypdfEPSS 0.18%via OSV
CVEs tagged “pip” — page 77 · VulnSea