VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-21874Medium· 5.3
8mo ago

NiceGUI has Redis connection leak via tab storage causes service degradation

NiceGUI has Redis connection leak via tab storage causes service degradation

▾ Sunlitnicegui · niceguiEPSS 0.56%via OSV
CVE-2026-21873High· 7.2
8mo ago

NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS

NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS

▾ Twilightnicegui · niceguiEPSS 0.26%via OSV
CVE-2026-21872Medium· 6.1
8mo ago

NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links

NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links

▾ Sunlitnicegui · niceguiEPSS 0.27%via OSV
CVE-2025-68158Medium· 5.7
8mo ago

Authlib has 1-click Account Takeover vulnerability

Authlib has 1-click Account Takeover vulnerability

▾ Sunlitauthlib · authlibEPSS 0.28%via OSV
CVE-2026-53872High· 7.5
8mo ago

picklescan has Arbitrary file read using `io.FileIO`

picklescan has Arbitrary file read using `io.FileIO`

▾ Twilightpicklescan · picklescanEPSS 0.69%via OSV
CVE-2026-21860Medium· 5.3
8mo ago

Werkzeug safe_join() allows Windows special device names with compound extensions

Werkzeug safe_join() allows Windows special device names with compound extensions

▾ Sunlitwerkzeug · werkzeugEPSS 0.48%via OSV
CVE-2026-21871Medium· 6.1
8mo ago

NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()

NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()

▾ Sunlitnicegui · niceguiEPSS 0.28%via OSV
CVE-2025-61782Medium· 6.1
8mo ago

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redi…

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redirect vulnerability exists in the OpenCTI platform's SAML authentication endpoint (/auth/saml/callbac…

▾ Sunlitpycti · pyctiEPSS 0.26%via OSV
CVE-2026-22041Low
8mo ago

loggingredactor converts non-string types to string types in logs

loggingredactor converts non-string types to string types in logs

▾ Sunlitloggingredactor · loggingredactorEPSS 0.27%via OSV
CVE-2026-21441High· 7.5
8mo ago

urllib3 is an HTTP client library for Python

urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urll…

▾ Twilightpython · urllib3EPSS 3.0%via NVD
MAL-2026-96None
8mo ago

Malicious code in pycolorom (PyPI)

Malicious code in pycolorom (PyPI)

▾ Sunlitpycolorom · pycoloromvia OSV
CVE-2025-69230Medium· 5.3
8mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an a…

▾ Sunlitaiohttp · aiohttpEPSS 0.37%via NVD
CVE-2026-21892Medium· 5.3
8mo ago

Parsl Monitoring Visualization Vulnerable to SQL Injection

Parsl Monitoring Visualization Vulnerable to SQL Injection

▾ Sunlitparsl · parslEPSS 0.27%via OSV
CVE-2026-21851Medium· 5.3
8mo ago

MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download

MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download

▾ Sunlitmonai · monaiEPSS 0.36%via OSV
CVE-2026-21883Medium
8mo ago

Bokeh server applications have Incomplete Origin Validation in WebSockets

Bokeh server applications have Incomplete Origin Validation in WebSockets

▾ Sunlitbokeh · bokehEPSS 0.18%via OSV
MAL-2026-42None
8mo ago

Malicious code in pyrogrom (PyPI)

Malicious code in pyrogrom (PyPI)

▾ Sunlitpyrogrom · pyrogromvia OSV
CVE-2026-21439Low
8mo ago

badkeys vulnerable to ASCII control character injection on console via malformed input

badkeys vulnerable to ASCII control character injection on console via malformed input

▾ Sunlitbadkeys · badkeysEPSS 0.34%via OSV
CVE-2025-69225Low
8mo ago

AIOHTTP has unicode match groups in regexes for ASCII protocol elements

AIOHTTP has unicode match groups in regexes for ASCII protocol elements

▾ Sunlitaiohttp · aiohttpEPSS 0.28%via OSV
CVE-2025-69227High· 7.5
8mo ago

aiohttp: aiohttp: Denial of Service via specially crafted POST request (CVE-2025-69227)

A flaw was found in aiohttp, an asynchronous HTTP client/server framework for Python. A remote attacker could exploit this vulnerability by sending a specially crafted POST request to an application using the Request.post() method, provide…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.39%via CSAF
CVE-2025-69229Medium
8mo ago

AIOHTTP vulnerable to DoS through chunked messages

AIOHTTP vulnerable to DoS through chunked messages

▾ Sunlitaiohttp · aiohttpEPSS 0.40%via OSV
CVE-2025-69228Medium· 6.8
8mo ago

aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request (CVE-2025-69228)

A flaw was found in aiohttp. A remote attacker can craft a malicious request that, when processed by an aiohttp server using the `Request.post()` method, causes the server's memory to fill uncontrollably. This can lead to a Denial of Servi…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.40%via CSAF
CVE-2025-69224Low
8mo ago

AIOHTTP's unicode processing of header values could cause parsing discrepancies

AIOHTTP's unicode processing of header values could cause parsing discrepancies

▾ Sunlitaiohttp · aiohttpEPSS 0.24%via OSV
CVE-2025-69226Low
8mo ago

AIOHTTP vulnerable to brute-force leak of internal static file path components

AIOHTTP vulnerable to brute-force leak of internal static file path components

▾ Sunlitaiohttp · aiohttpEPSS 0.36%via OSV
CVE-2025-69223High· 7.5
8mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that …

▾ Twilightaiohttp · aiohttpEPSS 0.57%via NVD
CVE-2026-21445HighPoC
9mo ago

Langflow Missing Authentication on Critical API Endpoints

Langflow Missing Authentication on Critical API Endpoints

▾ Midnightlangflow-base · langflow-baseEPSS 34%via OSV
CVE-2025-68131Medium
9mo ago

CBORDecoder reuse can leak shareable values across decode calls

CBORDecoder reuse can leak shareable values across decode calls

▾ Sunlitcbor2 · cbor2EPSS 0.46%via OSV
MAL-2025-193011None
9mo ago

Malicious code in requeses (PyPI)

Malicious code in requeses (PyPI)

▾ Sunlitrequeses · requesesvia OSV
MAL-2025-193010None
9mo ago

Malicious code in pyrogrqm (PyPI)

Malicious code in pyrogrqm (PyPI)

▾ Sunlitpyrogrqm · pyrogrqmvia OSV
MAL-2025-193008None
9mo ago

Malicious code in telegreph (PyPI)

Malicious code in telegreph (PyPI)

▾ Sunlittelegreph · telegrephvia OSV
MAL-2025-193007None
9mo ago

Malicious code in aiogrem (PyPI)

Malicious code in aiogrem (PyPI)

▾ Sunlitaiogrem · aiogremvia OSV
CVEs tagged “pip” — page 82 · VulnSea