VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-23528Medium
8mo ago

Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard

Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard

▾ Sunlitdistributed · distributedEPSS 0.24%via OSV
CVE-2026-23535High· 8.0
8mo ago

Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command

Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command

▾ Twilightwlc · wlcEPSS 0.39%via OSV
CVE-2026-23490High· 7.5PoC
8mo ago

pyasn1 is a generic ASN.1 library for Python

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

▾ Midnightpyasn1 · pyasn1EPSS 0.77%via NVD
CVE-2025-68492Medium· 4.2
8mo ago

Chainlit contains an authorization bypass vulnerability

Chainlit contains an authorization bypass vulnerability

▾ Sunlitchainlit · chainlitEPSS 0.23%via OSV
CVE-2026-22779Medium
8mo ago

BlackSheep's ClientSession is vulnerable to CRLF injection

BlackSheep's ClientSession is vulnerable to CRLF injection

▾ Sunlitblacksheep · blacksheepEPSS 0.36%via OSV
CVE-2026-21889Low
8mo ago

Weblate leaks information via screenshots

Weblate leaks information via screenshots

▾ Sunlitweblate · weblateEPSS 0.38%via OSV
CVE-2026-22871High
8mo ago

GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE

GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE

▾ Twilightguarddog · guarddogEPSS 1.1%via OSV
CVE-2026-21226High· 7.5
8mo ago

Azure Core is vulnerable to deserialization of untrusted data

Azure Core is vulnerable to deserialization of untrusted data

▾ Twilightazure-core · azure-coreEPSS 0.93%via OSV
CVE-2026-22798Medium· 5.9
8mo ago

hermes's raw options logging may disclose secrets passed in via subcommand options argument

hermes's raw options logging may disclose secrets passed in via subcommand options argument

▾ Sunlithermes · hermesEPSS 0.18%via OSV
CVE-2026-22870High
8mo ago

GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS

GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS

▾ Twilightguarddog · guarddogEPSS 0.52%via OSV
CVE-2026-22702Medium· 4.5
8mo ago

virtualenv Has TOCTOU Vulnerabilities in Directory Creation

virtualenv Has TOCTOU Vulnerabilities in Directory Creation

▾ Sunlitvirtualenv · virtualenvEPSS 0.10%via OSV
CVE-2026-23949High· 8.6
8mo ago

jaraco.context Has a Path Traversal Vulnerability

jaraco.context Has a Path Traversal Vulnerability

▾ Twilightjaraco-context · jaraco-contextEPSS 0.62%via OSV
CVE-2026-22777High· 7.5
8mo ago

ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler

ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler

▾ Twilightcomfy-cli · comfy-cliEPSS 0.35%via OSV
MAL-2026-237None
8mo ago

Malicious code in formater (PyPI)

Malicious code in formater (PyPI)

▾ Sunlitformater · formatervia OSV
MAL-2026-236None
8mo ago

Malicious code in graponater (PyPI)

Malicious code in graponater (PyPI)

▾ Sunlitgraponater · graponatervia OSV
CVE-2025-14279High· 8.1
8mo ago

MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation

MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation

▾ Twilightmlflow · mlflowEPSS 0.21%via OSV
CVE-2026-22251Medium· 5.3
8mo ago

Weblate wlc has insecure API key configuration

Weblate wlc has insecure API key configuration

▾ Sunlitwlc · wlcEPSS 0.19%via OSV
CVE-2026-22033High
8mo ago

Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field

Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field

▾ Twilightlabel-studio · label-studioEPSS 0.28%via OSV
CVE-2026-22250Low· 2.5
8mo ago

Weblate command-line client susceptible to SSL verification skip

Weblate command-line client susceptible to SSL verification skip

▾ Sunlitwlc · wlcEPSS 0.16%via OSV
CVE-2025-15506Low· 3.3
8mo ago

AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability

AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability

▾ Sunlitopencolorio · opencolorioEPSS 0.18%via OSV
CVE-2026-22701Medium· 5.3
8mo ago

filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock (CVE-2026-22701)

A Time-of-Check-Time-of-Use (TOCTOU) flaw has been discovered in the pypi filelock package. The TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access…

▾ SunlitRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.13%via CSAF
CVE-2025-15504Low· 3.3
8mo ago

LIEF is vulnerable to segmentation fault

LIEF is vulnerable to segmentation fault

▾ Sunlitlief · liefEPSS 0.27%via OSV
CVE-2026-22606High
8mo ago

Fickling has a bypass via runpy.run_path() and runpy.run_module()

Fickling has a bypass via runpy.run_path() and runpy.run_module()

▾ Twilightfickling · ficklingEPSS 0.49%via OSV
CVE-2026-22609High
8mo ago

Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist

Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist

▾ Twilightfickling · ficklingEPSS 0.64%via OSV
CVE-2026-22607High
8mo ago

Fickling Blocklist Bypass: cProfile.run()

Fickling Blocklist Bypass: cProfile.run()

▾ Twilightfickling · ficklingEPSS 0.53%via OSV
CVE-2026-22612High
8mo ago

Fickling vulnerable to detection bypass due to "builtins" blindness

Fickling vulnerable to detection bypass due to "builtins" blindness

▾ Twilightfickling · ficklingEPSS 0.31%via OSV
CVE-2026-22608High
8mo ago

Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection

Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection

▾ Twilightfickling · ficklingEPSS 0.40%via OSV
CVE-2026-22690Low
8mo ago

pypdf has possible long runtimes for missing /Root object with large /Size values

pypdf has possible long runtimes for missing /Root object with large /Size values

▾ Sunlitpypdf · pypdfEPSS 0.44%via OSV
CVE-2026-22691Low
8mo ago

pypdf has possible long runtimes for malformed startxref

pypdf has possible long runtimes for malformed startxref

▾ Sunlitpypdf · pypdfEPSS 0.44%via OSV
CVE-2023-7333Medium· 5.3
8mo ago

records-mover Injection vulnerability

records-mover Injection vulnerability

▾ Sunlitrecords-mover · records-moverEPSS 0.19%via OSV
CVEs tagged “pip” — page 81 · VulnSea