Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2025-64712Critical· 9.8Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
CVE-2026-1285LowDjango has Inefficient Algorithmic Complexity
Django has Inefficient Algorithmic Complexity
CVE-2025-14550LowDjango has Inefficient Algorithmic Complexity
Django has Inefficient Algorithmic Complexity
CVE-2025-13473LowDjango has Observable Timing Discrepancy
Django has Observable Timing Discrepancy
CVE-2025-70560High· 8.4Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
CVE-2026-25517MediumWagtail has improper permission handling on admin preview endpoints
Wagtail has improper permission handling on admin preview endpoints
CVE-2026-1312Medium· 5.4PoCAn issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…
CVE-2026-1287Medium· 5.4An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansio…
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansio…
CVE-2026-1207Medium· 5.4PoCAn issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…
CVE-2026-56304Mediumpicklescan vulnerable to arbitrary file create using logging.FileHandler
picklescan vulnerable to arbitrary file create using logging.FileHandler
CVE-2025-70960Medium· 5.4A stored cross-site scripting (XSS) vulnerability in the Forums module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web …
A stored cross-site scripting (XSS) vulnerability in the Forums module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
CVE-2026-25481CriticalLangroid has WAF Bypass Leading to RCE in TableChatAgent
Langroid has WAF Bypass Leading to RCE in TableChatAgent
CVE-2026-1777High· 7.2SageMaker Python SDK has Exposed HMAC
SageMaker Python SDK has Exposed HMAC
CVE-2026-0599High· 7.5Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption
Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption
CVE-2026-53874Highpicklescan missing detection by simple obfuscation of a `builtins.eval` call
picklescan missing detection by simple obfuscation of a `builtins.eval` call
CVE-2026-1117High· 8.2Lollms has an Improper Access Control vulnerability
Lollms has an Improper Access Control vulnerability
CVE-2025-69207Medium· 5.4Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning
Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning
CVE-2026-1703Lowpip Path Traversal vulnerability
pip Path Traversal vulnerability
CVE-2026-1778Medium· 5.9SageMaker Python SDK has Insecure TLS Configuration
SageMaker Python SDK has Insecure TLS Configuration
CVE-2025-10279High· 7.0mlflow Creates of Temporary File in Directory with Insecure Permissions
mlflow Creates of Temporary File in Directory with Insecure Permissions
CVE-2025-6208Medium· 5.3llama-index-core vulnerable to Uncontrolled Resource Consumption
llama-index-core vulnerable to Uncontrolled Resource Consumption
CVE-2026-22778Critical· 9.8PoCvLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…
MAL-2026-623NoneMalicious code in marshl (PyPI)
Malicious code in marshl (PyPI)
CVE-2026-25211Low· 3.2PoCLlama Stack exposes secret in initialization log
Llama Stack exposes secret in initialization log
CVE-2025-62349Medium· 6.2Salt Authentication Protocol Version Downgrade Allows Minion Impersonation
Salt Authentication Protocol Version Downgrade Allows Minion Impersonation
CVE-2025-62348High· 7.8Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
CVE-2026-24780HighAutoGPT is Vulnerable to RCE via Disabled Block Execution
AutoGPT is Vulnerable to RCE via Disabled Block Execution
CVE-2026-23892Medium· 5.9OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication
OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication
CVE-2026-1213Mediumaskbot inexhaustive permissions check allows any user to modify a different user's profile picture
askbot inexhaustive permissions check allows any user to modify a different user's profile picture
CVE-2026-24779High· 7.1vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the vLLM project's multimodal feature set. …