Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
MAL-2025-192991NoneMalicious code in pyrogrem (PyPI)
Malicious code in pyrogrem (PyPI)
CVE-2025-34469High· 7.5Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl
Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl. In the default emulated shell configuration, these command emulations perform real outbound …
CVE-2025-71339MediumPicklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
CVE-2025-71321HighPicklescan vulnerable to Arbitrary File Writing
Picklescan vulnerable to Arbitrary File Writing
CVE-2025-71322High· 8.8Picklescan Bypasses Unsafe Globals Check using pty.spawn
Picklescan Bypasses Unsafe Globals Check using pty.spawn
CVE-2025-71320HighPicklescan has Incomplete List of Disallowed Inputs
Picklescan has Incomplete List of Disallowed Inputs
CVE-2025-71323Critical· 9.8Picklescan does not block ctypes
Picklescan does not block ctypes
CVE-2025-71365High· 8.1Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
MAL-2025-192943NoneMalicious code in telegrem (PyPI)
Malicious code in telegrem (PyPI)
MAL-2025-192942NoneMalicious code in telebot-bot (PyPI)
Malicious code in telebot-bot (PyPI)
CVE-2025-67729High· 8.8lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
CVE-2025-68664Critical· 9.3PoClangchain-core: LangChain: Arbitrary code execution via serialization injection (CVE-2025-68664)
A flaw was found in LangChain, a framework for building agents and LLM-powered applications. A remote attacker can exploit a serialization injection vulnerability in LangChain's `dumps()` and `dumpd()` functions. This occurs because the fu…
CVE-2025-65713MediumHome Assistant Core before is vulnerable to Directory Traversal
Home Assistant Core before is vulnerable to Directory Traversal
CVE-2025-67743Medium· 6.3Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service
Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service
CVE-2025-68480Medium· 5.3Marshmallow has DoS in Schema.load(many)
Marshmallow has DoS in Schema.load(many)
CVE-2025-14881Lowpretix has Broken Access Control Allowing Cross-User File Access via UUID
pretix has Broken Access Control Allowing Cross-User File Access via UUID
CVE-2025-14882Lowpretix has Broken Access Control Allowing Cross-User File Access via UUID
pretix has Broken Access Control Allowing Cross-User File Access via UUID
CVE-2025-14546Medium· 6.3FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation
FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation
CVE-2025-68481Medium· 5.9FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO
FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO
CVE-2025-68477High· 7.7Langflow vulnerable to Server-Side Request Forgery
Langflow vulnerable to Server-Side Request Forgery
CVE-2025-53000Highnbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows
nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows
CVE-2025-68463Medium· 4.9Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
CVE-2025-68279High· 7.7Weblate has an arbitrary file read via symbolic links
Weblate has an arbitrary file read via symbolic links
CVE-2025-68145Mediummcp-server-git has missing path validation when using --repository flag
mcp-server-git has missing path validation when using --repository flag
CVE-2025-68144Mediummcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
CVE-2025-68143Mediummcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
CVE-2025-68146Medium· 6.3filelock has a TOCTOU race condition which allows symlink attacks during lock file creation
filelock has a TOCTOU race condition which allows symlink attacks during lock file creation
CVE-2025-68142LowPyMdown Extensions has a ReDOS bug in its Figure Capture extension
PyMdown Extensions has a ReDOS bug in its Figure Capture extension
CVE-2025-64725LowWeblate has improper validation upon invitation acceptance
Weblate has improper validation upon invitation acceptance
CVE-2025-67747HighFickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list
Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list