VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-16136Critical⚠ Exploited
2w ago

Malicious code in transfomers (PyPI)

Malicious code in transfomers (PyPI)

▾ Abyssaltransfomers · transfomersvia OSV
MAL-2026-16135Critical⚠ Exploited
2w ago

Malicious code in openaii (PyPI)

Malicious code in openaii (PyPI)

▾ Abyssalopenaii · openaiivia OSV
MAL-2026-16134Critical⚠ Exploited
2w ago

Malicious code in ollamaa (PyPI)

Malicious code in ollamaa (PyPI)

▾ Abyssalollamaa · ollamaavia OSV
MAL-2026-16133Critical⚠ Exploited
2w ago

Malicious code in langgrap (PyPI)

Malicious code in langgrap (PyPI)

▾ Abyssallanggrap · langgrapvia OSV
MAL-2026-16131Critical⚠ Exploited
2w ago

Malicious code in aitextutils-py (PyPI)

Malicious code in aitextutils-py (PyPI)

▾ Abyssalaitextutils-py · aitextutils-pyvia OSV
MAL-2026-16130Critical⚠ Exploited
2w ago

Malicious code in aitextkit-py (PyPI)

Malicious code in aitextkit-py (PyPI)

▾ Abyssalaitextkit-py · aitextkit-pyvia OSV
MAL-2026-16129Critical⚠ Exploited
2w ago

Malicious code in web3-eth-account (PyPI)

Malicious code in web3-eth-account (PyPI)

▾ Abyssalweb3-eth-account · web3-eth-accountvia OSV
MAL-2026-16128Critical⚠ Exploited
2w ago

Malicious code in pymem-win (PyPI)

Malicious code in pymem-win (PyPI)

▾ Abyssalpymem-win · pymem-winvia OSV
MAL-2026-16127Critical⚠ Exploited
2w ago

Malicious code in eth-account-web3 (PyPI)

Malicious code in eth-account-web3 (PyPI)

▾ Abyssaleth-account-web3 · eth-account-web3via OSV
CVE-2026-59151Critical· 9.6
2w ago

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

▾ Midnightprowler-cloud · prowler-cloudEPSS 0.53%via OSV
MAL-2026-16125Critical⚠ Exploited
2w ago

Malicious code in lucy-python-script-2030 (PyPI)

Malicious code in lucy-python-script-2030 (PyPI)

▾ Abyssallucy-python-script-2030 · lucy-python-script-2030via OSV
MAL-2026-16122Critical⚠ Exploited
2w ago

Malicious code in pylever (PyPI)

Malicious code in pylever (PyPI)

▾ Abyssalpylever · pylevervia OSV
CVE-2026-49836Medium· 4.6PoC
2w ago

psd-tools: arbitrary file write via smart-object filename

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled …

▾ Twilightpsd-tools · psd-toolsEPSS 0.19%via CVEORG
MAL-2026-16121Critical⚠ Exploited
2w ago

Malicious code in websetup (PyPI)

Malicious code in websetup (PyPI)

▾ Abyssalwebsetup · websetupvia OSV
CVE-2026-59177High· 8.8PoC
2w ago

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

▾ Midnightesphome-device-builder · esphome-device-buildervia OSV
CVE-2026-87012Medium· 4.3
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the share…

▾ Sunlitopenwebui · open_webuiEPSS 0.48%via NVD
CVE-2026-87014Medium· 6.5PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's d…

▾ Twilightopenwebui · open_webuiEPSS 0.51%via NVD
CVE-2026-87818Medium· 6.5PoC
2w ago

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create…

▾ Twilightgitpython_project · gitpythonEPSS 0.41%via NVD
MAL-2026-16099Critical⚠ Exploited
2w ago

Malicious code in bq-sdist-probe-vrp (PyPI)

Malicious code in bq-sdist-probe-vrp (PyPI)

▾ Abyssalbq-sdist-probe-vrp · bq-sdist-probe-vrpvia OSV
MAL-2026-16098Critical⚠ Exploited
2w ago

Malicious code in bq-build-probe-vrp-2026 (PyPI)

Malicious code in bq-build-probe-vrp-2026 (PyPI)

▾ Abyssalbq-build-probe-vrp-2026 · bq-build-probe-vrp-2026via OSV
MAL-2026-16080Critical⚠ Exploited
2w ago

Malicious code in databricks-webapp-navigation-homepage (PyPI)

Malicious code in databricks-webapp-navigation-homepage (PyPI)

▾ Abyssaldatabricks-webapp-navigation-homepage · databricks-webapp-navigation-homepagevia OSV
CVE-2026-87996High· 7.7
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then l…

▾ Twilightopenwebui · open_webuiEPSS 0.35%via NVD
CVE-2026-87817High· 8.8
2w ago

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a ma…

▾ Twilightgitpython_project · gitpythonEPSS 0.40%via NVD
CVE-2026-87819High· 7.5
2w ago

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containi…

▾ Twilightgitpython_project · gitpythonEPSS 0.52%via NVD
CVE-2026-12259Medium· 5.3
2w ago

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

▾ Sunlitnltk · nltkEPSS 0.14%via OSV
CVE-2026-78675High· 8.4⚖ disputed
2w ago

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables…

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

▾ Twilightgitpython · gitpythonEPSS 0.18%via OSV
CVE-2026-80206High
2w ago

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

▾ Twilightnltk · nltkEPSS 0.44%via OSV
CVE-2026-78681High
2w ago

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

▾ Twilightnltk · nltkEPSS 0.52%via OSV
CVE-2026-79676High
2w ago

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

▾ Twilightnltk · nltkEPSS 0.45%via OSV
CVE-2026-79657Critical
2w ago

NLTK: Allowlisted pickle loaders still permit code execution in current source

NLTK: Allowlisted pickle loaders still permit code execution in current source

▾ Midnightnltk · nltkEPSS 1.3%via OSV
CVEs tagged “pip” — page 8 · VulnSea