VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-24486High· 8.6PoC
8mo ago

Python-Multipart is a streaming multipart parser for Python

Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write …

▾ Midnightfastapiexpert · python-multipartEPSS 2.2%via NVD
CVE-2026-24408None· 0.0
8mo ago

sigstore CSRF possibility in OIDC authentication during signing

sigstore CSRF possibility in OIDC authentication during signing

▾ Sunlitsigstore · sigstoreEPSS 0.18%via OSV
CVE-2026-24489Medium· 5.3
8mo ago

Gakido vulnerable to HTTP Header Injection (CRLF Injection)

Gakido vulnerable to HTTP Header Injection (CRLF Injection)

▾ Sunlitgakido · gakidoEPSS 0.40%via OSV
CVE-2026-24490High· 8.1
8mo ago

MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field

MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field

▾ Twilightmobsf · mobsfEPSS 0.35%via OSV
CVE-2026-24123High· 7.4
8mo ago

BentoML has a Path Traversal via Bentofile Configuration

BentoML has a Path Traversal via Bentofile Configuration

▾ Twilightbentoml · bentomlEPSS 0.50%via OSV
CVE-2025-11687Medium· 6.1
8mo ago

GI-DocGen vulnerable to Reflected XSS via unescaped query strings

GI-DocGen vulnerable to Reflected XSS via unescaped query strings

▾ Sunlitgi-docgen · gi-docgenEPSS 0.38%via OSV
CVE-2026-24688MediumPoC
8mo ago

pypdf has possible Infinite Loop when processing outlines/bookmarks

pypdf has possible Infinite Loop when processing outlines/bookmarks

▾ Twilightpypdf · pypdfEPSS 0.45%via OSV
CVE-2026-0770HighCISA KEV0dayPoC
8mo ago

Langflow affected by Remote Code Execution via validate_code() exec()

Langflow affected by Remote Code Execution via validate_code() exec()

▾ Abyssallangflow · langflowEPSS 64%via OSV
CVE-2026-0994High· 7.5PoC
8mo ago

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth ac…

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth ac…

▾ Midnightgoogle · protobufEPSS 0.72%via NVD
CVE-2025-67221HighPoC
8mo ago

orjson does not limit recursion for deeply nested JSON documents

orjson does not limit recursion for deeply nested JSON documents

▾ Midnightorjson · orjsonEPSS 0.64%via OSV
MAL-2026-470None
8mo ago

Malicious code in urlsssser (PyPI)

Malicious code in urlsssser (PyPI)

▾ Sunliturlsssser · urlsssservia OSV
MAL-2026-468None
8mo ago

Malicious code in urlsser (PyPI)

Malicious code in urlsser (PyPI)

▾ Sunliturlsser · urlsservia OSV
CVE-2026-24009High· 8.1PoC
8mo ago

docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage

docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage

▾ Midnightdocling-core · docling-coreEPSS 1.6%via OSV
CVE-2025-71176Medium· 6.8
8mo ago

pytest has vulnerable tmpdir handling

pytest has vulnerable tmpdir handling

▾ Sunlitpytest · pytestEPSS 0.16%via OSV
CVE-2026-24130Low
8mo ago

Moonraker affected by LDAP search filter injection

Moonraker affected by LDAP search filter injection

▾ Sunlitmoonraker · moonrakerEPSS 0.31%via OSV
CVE-2026-1260High· 7.8
8mo ago

Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.

Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.

▾ Twilightgoogle · sentencepieceEPSS 0.18%via NVD
CVE-2026-24049High· 7.1PoC
8mo ago

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after e…

▾ Midnightwheel_project · wheelEPSS 0.36%via NVD
CVE-2026-23968Medium· 5.5
8mo ago

Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false

Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false

▾ Sunlitcopier · copierEPSS 0.24%via OSV
CVE-2026-23877Medium
8mo ago

Swing Music has a Directory Traversal & Filesystem can be accessed by a non-admin user

Swing Music has a Directory Traversal & Filesystem can be accessed by a non-admin user

▾ Sunlitswingmusic · swingmusicEPSS 0.58%via OSV
CVE-2026-23996Low· 3.7
8mo ago

FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection

FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection

▾ Sunlitfastapi-api-key · fastapi-api-keyEPSS 0.30%via OSV
CVE-2026-23833Medium
8mo ago

ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component

ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component

▾ Sunlitesphome · esphomeEPSS 0.30%via OSV
CVE-2026-23986High· 7.1
8mo ago

Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true

Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true

▾ Twilightcopier · copierEPSS 0.26%via OSV
CVE-2026-23946Medium· 6.8
8mo ago

Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization

Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization

▾ Sunlittendenci · tendenciEPSS 0.85%via OSV
CVE-2026-22807High· 8.8PoC
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…

▾ Midnightvllm · vllmEPSS 0.83%via NVD
CVE-2026-23842High· 7.5PoC
8mo ago

ChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion

ChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion

▾ Midnightchatterbot · chatterbotEPSS 0.55%via OSV
CVE-2026-22219High· 7.7
8mo ago

Chainlit contain a server-side request forgery (SSRF) vulnerability

Chainlit contain a server-side request forgery (SSRF) vulnerability

▾ Twilightchainlit · chainlitEPSS 5.1%via OSV
MAL-2026-326None
8mo ago

Malicious code in urlssser (PyPI)

Malicious code in urlssser (PyPI)

▾ Sunliturlssser · urlssservia OSV
MAL-2026-325None
8mo ago

Malicious code in marshel (PyPI)

Malicious code in marshel (PyPI)

▾ Sunlitmarshel · marshelvia OSV
CVE-2025-68675High· 7.5
8mo ago

Apache Airflow proxy credentials for various providers might leak in task logs

Apache Airflow proxy credentials for various providers might leak in task logs

▾ Twilightapache-airflow · apache-airflowEPSS 2.0%via OSV
CVE-2025-68438High· 7.5
8mo ago

Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

▾ Twilightapache-airflow · apache-airflowEPSS 0.66%via OSV
CVEs tagged “pip” — page 80 · VulnSea