VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-53875High
7mo ago

Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

▾ Twilightpicklescan · picklescanEPSS 0.69%via OSV
CVE-2025-33245High· 8.0
7mo ago

NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution

NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution

▾ Twilightnemo-toolkit · nemo-toolkitEPSS 0.54%via OSV
CVE-2025-14009High· 8.8
7mo ago

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This a…

▾ Twilightnltk · nltkEPSS 0.95%via NVD
CVE-2026-25087High· 7.0
7mo ago

Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering

Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering

▾ Twilightpyarrow · pyarrowEPSS 0.82%via OSV
MAL-2026-931None
7mo ago

Malicious code in telebot-infe (PyPI)

Malicious code in telebot-infe (PyPI)

▾ Sunlittelebot-infe · telebot-infevia OSV
MAL-2026-930None
7mo ago

Malicious code in telebot-info (PyPI)

Malicious code in telebot-info (PyPI)

▾ Sunlittelebot-info · telebot-infovia OSV
CVE-2026-26057Medium· 6.5
7mo ago

Skill-scanner Unsecured Network Binding Vulnerability

Skill-scanner Unsecured Network Binding Vulnerability

▾ Sunlitcisco-ai-skill-scanner · cisco-ai-skill-scannerEPSS 0.45%via OSV
CVE-2026-25739Medium· 5.4
7mo ago

Indico Affected by Cross-Site-Scripting via material uploads

Indico Affected by Cross-Site-Scripting via material uploads

▾ Sunlitindico · indicoEPSS 0.29%via OSV
CVE-2026-25738Medium
7mo ago

Indico has Server-Side Request Forgery (SSRF) in multiple places

Indico has Server-Side Request Forgery (SSRF) in multiple places

▾ Sunlitindico · indicoEPSS 0.33%via OSV
CVE-2026-24126Medium· 6.6PoC
7mo ago

Weblate has an argument injection in management console

Weblate has an argument injection in management console

▾ Twilightweblate · weblateEPSS 0.47%via OSV
GHSA-27jp-wm6q-gp25Medium
7mo ago

sqlparse: formatting list of tuples leads to denial of service

sqlparse: formatting list of tuples leads to denial of service

▾ Sunlitsqlparse · sqlparsevia OSV
CVE-2026-26013Low· 3.7
7mo ago

LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

▾ Sunlitlangchain-core · langchain-coreEPSS 0.42%via OSV
CVE-2026-1669High· 7.5
7mo ago

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras …

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras …

▾ Twilightkeras · kerasEPSS 0.31%via NVD
CVE-2025-69872Critical· 9.8
7mo ago

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

▾ Midnightdiskcache · diskcacheEPSS 0.53%via NVD
CVE-2026-25990High· 7.5
7mo ago

Pillow is a Python imaging library

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

▾ Twilightpython · pillowEPSS 0.44%via NVD
CVE-2026-25577High· 7.5
7mo ago

Emmett-Core: Unhandled CookieError Exception Causing Denial of Service

Emmett-Core: Unhandled CookieError Exception Causing Denial of Service

▾ Twilightemmett-core · emmett-coreEPSS 0.48%via OSV
CVE-2026-26007Medium· 6.5
7mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), l…

▾ Sunlitcryptography.io · cryptographyEPSS 0.34%via NVD
CVE-2026-22922Medium· 6.5
7mo ago

Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access

Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access

▾ Sunlitapache-airflow · apache-airflowEPSS 0.39%via OSV
CVE-2026-24098Medium· 6.5
7mo ago

Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users

Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users

▾ Sunlitapache-airflow · apache-airflowEPSS 0.75%via OSV
CVE-2026-25480Medium· 6.5
7mo ago

Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)

Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)

▾ Sunlitlitestar · litestarEPSS 0.51%via OSV
CVE-2026-25528Medium· 5.8
7mo ago

LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

▾ Sunlitlangsmith · langsmithEPSS 0.33%via OSV
CVE-2026-25905Medium· 5.8
7mo ago

MCP Run Python has a Sandbox Escape & Server Takeover Vulnerability

MCP Run Python has a Sandbox Escape & Server Takeover Vulnerability

▾ Sunlitmcp-run-python · mcp-run-pythonEPSS 0.21%via OSV
CVE-2026-25479Medium· 6.5
7mo ago

Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns

Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns

▾ Sunlitlitestar · litestarEPSS 0.41%via OSV
CVE-2026-25904Medium· 5.8
7mo ago

MCP Run Python Deno Sandbox Misconfiguration Allows SSRF Attacks via Localhost Access

MCP Run Python Deno Sandbox Misconfiguration Allows SSRF Attacks via Localhost Access

▾ Sunlitmcp-run-python · mcp-run-pythonEPSS 0.20%via OSV
CVE-2026-25478High· 7.4
7mo ago

Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins

Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins

▾ Twilightlitestar · litestarEPSS 0.47%via OSV
GHSA-4f84-67cv-qrv3Critical
7mo ago

A single post-release of dydx-v4-client contained obfuscated multi-stage loader

A single post-release of dydx-v4-client contained obfuscated multi-stage loader

▾ Midnightdydx-v4-client · dydx-v4-clientvia OSV
CVE-2026-25650High
7mo ago

MCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token

MCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token

▾ Twilightmcp-salesforce-connector · mcp-salesforce-connectorEPSS 0.53%via OSV
CVE-2026-25516Medium· 6.1
7mo ago

NiceGUI's XSS vulnerability in ui.markdown() allows arbitrary JavaScript execution through unsanitized HTML content

NiceGUI's XSS vulnerability in ui.markdown() allows arbitrary JavaScript execution through unsanitized HTML content

▾ Sunlitnicegui · niceguiEPSS 0.29%via OSV
CVE-2026-25198Medium· 4.7
7mo ago

web2py has an Open Redirect Vulnerability

web2py has an Open Redirect Vulnerability

▾ Sunlitweb2py · web2pyEPSS 0.31%via OSV
CVE-2026-1707High· 7.4
7mo ago

pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability

pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability

▾ Twilightpgadmin4 · pgadmin4EPSS 0.42%via OSV
CVEs tagged “pip” — page 78 · VulnSea