VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2025-64712Critical· 9.8
7mo ago

Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write

Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write

▾ Midnightunstructured · unstructuredEPSS 0.64%via OSV
CVE-2026-1285Low
7mo ago

Django has Inefficient Algorithmic Complexity

Django has Inefficient Algorithmic Complexity

▾ Sunlitdjango · djangoEPSS 1.1%via OSV
CVE-2025-14550Low
7mo ago

Django has Inefficient Algorithmic Complexity

Django has Inefficient Algorithmic Complexity

▾ Sunlitdjango · djangoEPSS 1.1%via OSV
CVE-2025-13473Low
7mo ago

Django has Observable Timing Discrepancy

Django has Observable Timing Discrepancy

▾ Sunlitdjango · djangoEPSS 0.76%via OSV
CVE-2025-70560High· 8.4
7mo ago

Boltz contains an insecure deserialization vulnerability in its molecule loading functionality

Boltz contains an insecure deserialization vulnerability in its molecule loading functionality

▾ Twilightboltz · boltzEPSS 0.15%via OSV
CVE-2026-25517Medium
7mo ago

Wagtail has improper permission handling on admin preview endpoints

Wagtail has improper permission handling on admin preview endpoints

▾ Sunlitwagtail · wagtailEPSS 0.45%via OSV
CVE-2026-1312Medium· 5.4PoC
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…

▾ Twilightdjangoproject · djangoEPSS 0.85%via NVD
CVE-2026-1287Medium· 5.4
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansio…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansio…

▾ Sunlitdjangoproject · djangoEPSS 0.80%via NVD
CVE-2026-1207Medium· 5.4PoC
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…

▾ Twilightdjangoproject · djangoEPSS 13%via NVD
CVE-2026-56304Medium
7mo ago

picklescan vulnerable to arbitrary file create using logging.FileHandler

picklescan vulnerable to arbitrary file create using logging.FileHandler

▾ Sunlitpicklescan · picklescanEPSS 0.44%via OSV
CVE-2025-70960Medium· 5.4
7mo ago

A stored cross-site scripting (XSS) vulnerability in the Forums module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web …

A stored cross-site scripting (XSS) vulnerability in the Forums module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

▾ Sunlittendenci · tendenciEPSS 0.25%via OSV
CVE-2026-25481Critical
7mo ago

Langroid has WAF Bypass Leading to RCE in TableChatAgent

Langroid has WAF Bypass Leading to RCE in TableChatAgent

▾ Midnightlangroid · langroidEPSS 0.73%via OSV
CVE-2026-1777High· 7.2
7mo ago

SageMaker Python SDK has Exposed HMAC

SageMaker Python SDK has Exposed HMAC

▾ Twilightsagemaker · sagemakerEPSS 0.48%via OSV
CVE-2026-0599High· 7.5
7mo ago

Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption

Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption

▾ Twilighttext-generation · text-generationEPSS 28%via OSV
CVE-2026-53874High
7mo ago

picklescan missing detection by simple obfuscation of a `builtins.eval` call

picklescan missing detection by simple obfuscation of a `builtins.eval` call

▾ Twilightpicklescan · picklescanEPSS 0.76%via OSV
CVE-2026-1117High· 8.2
7mo ago

Lollms has an Improper Access Control vulnerability

Lollms has an Improper Access Control vulnerability

▾ Twilightlollms · lollmsEPSS 0.56%via OSV
CVE-2025-69207Medium· 5.4
7mo ago

Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning

Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning

▾ Sunlitkhoj · khojEPSS 0.38%via OSV
CVE-2026-1703Low
7mo ago

pip Path Traversal vulnerability

pip Path Traversal vulnerability

▾ Sunlitpip · pipEPSS 0.41%via OSV
CVE-2026-1778Medium· 5.9
7mo ago

SageMaker Python SDK has Insecure TLS Configuration

SageMaker Python SDK has Insecure TLS Configuration

▾ Sunlitsagemaker · sagemakerEPSS 0.25%via OSV
CVE-2025-10279High· 7.0
7mo ago

mlflow Creates of Temporary File in Directory with Insecure Permissions

mlflow Creates of Temporary File in Directory with Insecure Permissions

▾ Twilightmlflow · mlflowEPSS 0.23%via OSV
CVE-2025-6208Medium· 5.3
7mo ago

llama-index-core vulnerable to Uncontrolled Resource Consumption

llama-index-core vulnerable to Uncontrolled Resource Consumption

▾ Sunlitllama-index-core · llama-index-coreEPSS 0.39%via OSV
CVE-2026-22778Critical· 9.8PoC
7mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…

▾ Abyssalvllm · vllmEPSS 10%via NVD
MAL-2026-623None
8mo ago

Malicious code in marshl (PyPI)

Malicious code in marshl (PyPI)

▾ Sunlitmarshl · marshlvia OSV
CVE-2026-25211Low· 3.2PoC
8mo ago

Llama Stack exposes secret in initialization log

Llama Stack exposes secret in initialization log

▾ Twilightllama-stack · llama-stackEPSS 0.24%via OSV
CVE-2025-62349Medium· 6.2
8mo ago

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

▾ Sunlitsalt · saltEPSS 0.46%via OSV
CVE-2025-62348High· 7.8
8mo ago

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

▾ Twilightsalt · saltEPSS 0.20%via OSV
CVE-2026-24780High
8mo ago

AutoGPT is Vulnerable to RCE via Disabled Block Execution

AutoGPT is Vulnerable to RCE via Disabled Block Execution

▾ Twilightagpt · agptEPSS 1.3%via OSV
CVE-2026-23892Medium· 5.9
8mo ago

OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication

OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication

▾ Sunlitoctoprint · octoprintEPSS 0.44%via OSV
CVE-2026-1213Medium
8mo ago

askbot inexhaustive permissions check allows any user to modify a different user's profile picture

askbot inexhaustive permissions check allows any user to modify a different user's profile picture

▾ Sunlitaskbot · askbotEPSS 0.36%via OSV
CVE-2026-24779High· 7.1
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.14.1, a Server-Side Request Forgery (SSRF) vulnerability exists in the `MediaConnector` class within the vLLM project's multimodal feature set. …

▾ Twilightvllm · vllmEPSS 0.59%via NVD
CVEs tagged “pip” — page 79 · VulnSea