VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2025-14542High· 7.5
9mo ago

Universal Tool Calling Protocol (UTCP) client library for Python vulnerable to Trust Boundary Violation through Manual JSON specification

Universal Tool Calling Protocol (UTCP) client library for Python vulnerable to Trust Boundary Violation through Manual JSON specification

▾ Twilightutcp · utcpEPSS 0.26%via OSV
CVE-2025-67726High· 7.5
9mo ago

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing…

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in httputil.…

▾ Twilighttornado · tornadoEPSS 0.53%via OSV
CVE-2025-67725High· 7.5
9mo ago

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP req…

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method.…

▾ Twilighttornado · tornadoEPSS 0.56%via OSV
CVE-2025-67724Medium· 5.4
9mo ago

tornado: Tornado Header Injection and XSS via reason argument (CVE-2025-67724)

An unescaped input flaw has been discovered in the Tornado networking library. In Tornado, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (whe…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.24%via CSAF
CVE-2025-67644High· 7.3PoC
9mo ago

LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method

LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method

▾ Midnightlanggraph-checkpoint-sqlite · langgraph-checkpoint-sqliteEPSS 2.3%via OSV
CVE-2025-67720Medium· 6.5
9mo ago

Pyrofork has a Path Traversal in download_media Method

Pyrofork has a Path Traversal in download_media Method

▾ Sunlitpyrofork · pyroforkEPSS 0.32%via OSV
CVE-2025-67485Medium· 5.3
9mo ago

HTTP/HTTPS Traffic Interception Bypass in mad-proxy

HTTP/HTTPS Traffic Interception Bypass in mad-proxy

▾ Sunlitmad-proxy · mad-proxyEPSS 0.24%via OSV
CVE-2025-66645High· 7.5
9mo ago

NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read

NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read

▾ Twilightnicegui · niceguiEPSS 1.1%via OSV
CVE-2025-67502Medium· 5.4
9mo ago

Open Redirect Vulnerability in Taguette

Open Redirect Vulnerability in Taguette

▾ Sunlittaguette · taguetteEPSS 0.26%via OSV
CVE-2025-66469Medium· 6.1
9mo ago

NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection

NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection

▾ Sunlitnicegui · niceguiEPSS 0.27%via OSV
CVE-2025-66470Medium· 6.1PoC
9mo ago

NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content

NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content

▾ Twilightnicegui · niceguiEPSS 0.25%via OSV
MAL-2025-192323None
9mo ago

Malicious code in rendom (PyPI)

Malicious code in rendom (PyPI)

▾ Sunlitrendom · rendomvia OSV
CVE-2025-66418High· 7.5
9mo ago

urllib3 is a user-friendly HTTP client library for Python

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of co…

▾ Twilightpython · urllib3EPSS 0.68%via NVD
CVE-2025-66471High· 7.5
9mo ago

urllib3 is a user-friendly HTTP client library for Python

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large H…

▾ Twilightpython · urllib3EPSS 0.68%via NVD
CVE-2025-63681Low
9mo ago

open-webui is Vulnerable to Incorrect Access Control

open-webui is Vulnerable to Incorrect Access Control

▾ Sunlitopen-webui · open-webuiEPSS 0.28%via OSV
CVE-2025-65958High· 8.5
9mo ago

Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web

Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web

▾ Twilightopen-webui · open-webuiEPSS 4.4%via OSV
CVE-2025-14010Medium· 5.5
9mo ago

Ansible Community General Collection is vulnerable to exposure of sensitive information

Ansible Community General Collection is vulnerable to exposure of sensitive information

▾ Sunlitansible · ansibleEPSS 0.14%via OSV
CVE-2025-56427High· 7.5
9mo ago

ComposioHQ has a directory traversal vulnerability

ComposioHQ has a directory traversal vulnerability

▾ Twilightcomposio · composioEPSS 0.89%via OSV
CVE-2025-64460Medium
10mo ago

Django is vulnerable to DoS via XML serializer text extraction

Django is vulnerable to DoS via XML serializer text extraction

▾ Sunlitdjango · djangoEPSS 2.1%via OSV
CVE-2025-13372Medium· 4.3
10mo ago

Django is vulnerable to SQL injection in column aliases

Django is vulnerable to SQL injection in column aliases

▾ Sunlitdjango · djangoEPSS 0.92%via OSV
CVE-2025-65896Critical· 9.8
10mo ago

asyncmy is vulnerable to SQL injection via crafted dict keys

asyncmy is vulnerable to SQL injection via crafted dict keys

▾ Midnightasyncmy · asyncmyEPSS 0.43%via OSV
CVE-2025-65858LowPoC
10mo ago

Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation

Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation

▾ Twilightcalibreweb · calibrewebEPSS 0.21%via OSV
CVE-2025-12060Critical· 9.8
10mo ago

Keras Directory Traversal Vulnerability

Keras Directory Traversal Vulnerability

▾ Midnightkeras · kerasEPSS 0.59%via OSV
CVE-2025-66221Medium
10mo ago

Werkzeug safe_join() allows Windows special device names

Werkzeug safe_join() allows Windows special device names

▾ Sunlitwerkzeug · werkzeugEPSS 0.51%via OSV
CVE-2025-66454Medium· 6.5
10mo ago

arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints

arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints

▾ Sunlitarcade-mcp-server · arcade-mcp-serverEPSS 0.31%via OSV
CVE-2025-66416High
10mo ago

Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default

Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default

▾ Twilightmcp · mcpEPSS 0.51%via OSV
CVE-2025-66040Low· 3.6
10mo ago

Spotipy has a XSS vulnerability in its OAuth callback server

Spotipy has a XSS vulnerability in its OAuth callback server

▾ Sunlitspotipy · spotipyEPSS 0.16%via OSV
CVE-2025-66448High· 7.5
10mo ago

vllm: vLLM: Remote Code Execution via malicious model configuration (CVE-2025-66448)

A remote code execution vulnerability has been identified in vLLM. An attacker can exploit a weakness in the model loading process to silently fetch and run unauthorized, malicious Python code on the host system. This happens because the e…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.3EPSS 0.66%via CSAF
CVE-2025-66034Medium· 6.3PoC
10mo ago

fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

▾ Twilightfonttools · fonttoolsEPSS 0.55%via OSV
CVE-2025-66423High· 7.1
10mo ago

trytond does not enforce access rights for the route of the HTML editor.

trytond does not enforce access rights for the route of the HTML editor.

▾ Twilighttrytond · trytondEPSS 0.23%via OSV
CVEs tagged “pip” — page 84 · VulnSea