VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2025-192991None
9mo ago

Malicious code in pyrogrem (PyPI)

Malicious code in pyrogrem (PyPI)

▾ Sunlitpyrogrem · pyrogremvia OSV
CVE-2025-34469High· 7.5
9mo ago

Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl

Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl. In the default emulated shell configuration, these command emulations perform real outbound …

▾ Twilightcowrie · cowrieEPSS 0.68%via NVD
CVE-2025-71339Medium
9mo ago

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length

▾ Sunlitpicklescan · picklescanEPSS 0.52%via OSV
CVE-2025-71321High
9mo ago

Picklescan vulnerable to Arbitrary File Writing

Picklescan vulnerable to Arbitrary File Writing

▾ Twilightpicklescan · picklescanEPSS 0.62%via OSV
CVE-2025-71322High· 8.8
9mo ago

Picklescan Bypasses Unsafe Globals Check using pty.spawn

Picklescan Bypasses Unsafe Globals Check using pty.spawn

▾ Twilightpicklescan · picklescanEPSS 0.38%via OSV
CVE-2025-71320High
9mo ago

Picklescan has Incomplete List of Disallowed Inputs

Picklescan has Incomplete List of Disallowed Inputs

▾ Twilightpicklescan · picklescanEPSS 0.62%via OSV
CVE-2025-71323Critical· 9.8
9mo ago

Picklescan does not block ctypes

Picklescan does not block ctypes

▾ Midnightpicklescan · picklescanEPSS 0.76%via OSV
CVE-2025-71365High· 8.1
9mo ago

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

▾ Twilightpicklescan · picklescanEPSS 0.43%via OSV
MAL-2025-192943None
9mo ago

Malicious code in telegrem (PyPI)

Malicious code in telegrem (PyPI)

▾ Sunlittelegrem · telegremvia OSV
MAL-2025-192942None
9mo ago

Malicious code in telebot-bot (PyPI)

Malicious code in telebot-bot (PyPI)

▾ Sunlittelebot-bot · telebot-botvia OSV
CVE-2025-67729High· 8.8
9mo ago

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

▾ Twilightlmdeploy · lmdeployEPSS 0.60%via OSV
CVE-2025-68664Critical· 9.3PoC
9mo ago

langchain-core: LangChain: Arbitrary code execution via serialization injection (CVE-2025-68664)

A flaw was found in LangChain, a framework for building agents and LLM-powered applications. A remote attacker can exploit a serialization injection vulnerability in LangChain's `dumps()` and `dumpd()` functions. This occurs because the fu…

▾ AbyssalRed Hat · Red Hat Ansible Automation Platform 2.5EPSS 43%via CSAF
CVE-2025-65713Medium
9mo ago

Home Assistant Core before is vulnerable to Directory Traversal

Home Assistant Core before is vulnerable to Directory Traversal

▾ Sunlithomeassistant · homeassistantEPSS 0.40%via OSV
CVE-2025-67743Medium· 6.3
9mo ago

Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service

Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service

▾ Sunlitlocal-deep-research · local-deep-researchEPSS 0.32%via OSV
CVE-2025-68480Medium· 5.3
9mo ago

Marshmallow has DoS in Schema.load(many)

Marshmallow has DoS in Schema.load(many)

▾ Sunlitmarshmallow · marshmallowEPSS 0.30%via OSV
CVE-2025-14881Low
9mo ago

pretix has Broken Access Control Allowing Cross-User File Access via UUID

pretix has Broken Access Control Allowing Cross-User File Access via UUID

▾ Sunlitpretix · pretixEPSS 0.25%via OSV
CVE-2025-14882Low
9mo ago

pretix has Broken Access Control Allowing Cross-User File Access via UUID

pretix has Broken Access Control Allowing Cross-User File Access via UUID

▾ Sunlitpretix · pretixEPSS 0.25%via OSV
CVE-2025-14546Medium· 6.3
9mo ago

FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation

FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation

▾ Sunlitfastapi-sso · fastapi-ssoEPSS 0.36%via OSV
CVE-2025-68481Medium· 5.9
9mo ago

FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO

FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO

▾ Sunlitfastapi-users · fastapi-usersEPSS 0.26%via OSV
CVE-2025-68477High· 7.7
9mo ago

Langflow vulnerable to Server-Side Request Forgery

Langflow vulnerable to Server-Side Request Forgery

▾ Twilightlangflow · langflowEPSS 6.3%via OSV
CVE-2025-53000High
9mo ago

nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows

nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows

▾ Twilightnbconvert · nbconvertEPSS 0.26%via OSV
CVE-2025-68463Medium· 4.9
9mo ago

Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez

Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez

▾ Sunlitbiopython · biopythonEPSS 0.32%via OSV
CVE-2025-68279High· 7.7
9mo ago

Weblate has an arbitrary file read via symbolic links

Weblate has an arbitrary file read via symbolic links

▾ Twilightweblate · weblateEPSS 0.41%via OSV
CVE-2025-68145Medium
9mo ago

mcp-server-git has missing path validation when using --repository flag

mcp-server-git has missing path validation when using --repository flag

▾ Sunlitmcp-server-git · mcp-server-gitEPSS 7.0%via OSV
CVE-2025-68144Medium
9mo ago

mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files

mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files

▾ Sunlitmcp-server-git · mcp-server-gitEPSS 7.2%via OSV
CVE-2025-68143Medium
9mo ago

mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations

mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations

▾ Sunlitmcp-server-git · mcp-server-gitEPSS 8.1%via OSV
CVE-2025-68146Medium· 6.3
9mo ago

filelock has a TOCTOU race condition which allows symlink attacks during lock file creation

filelock has a TOCTOU race condition which allows symlink attacks during lock file creation

▾ Sunlitfilelock · filelockEPSS 0.20%via OSV
CVE-2025-68142Low
9mo ago

PyMdown Extensions has a ReDOS bug in its Figure Capture extension

PyMdown Extensions has a ReDOS bug in its Figure Capture extension

▾ Sunlitpymdown-extensions · pymdown-extensionsEPSS 0.48%via OSV
CVE-2025-64725Low
9mo ago

Weblate has improper validation upon invitation acceptance

Weblate has improper validation upon invitation acceptance

▾ Sunlitweblate · weblateEPSS 0.35%via OSV
CVE-2025-67747High
9mo ago

Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list

Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list

▾ Twilightfickling · ficklingEPSS 0.28%via OSV
CVEs tagged “pip” — page 83 · VulnSea