Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2025-14542High· 7.5Universal Tool Calling Protocol (UTCP) client library for Python vulnerable to Trust Boundary Violation through Manual JSON specification
Universal Tool Calling Protocol (UTCP) client library for Python vulnerable to Trust Boundary Violation through Manual JSON specification
CVE-2025-67726High· 7.5Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing…
Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in httputil.…
CVE-2025-67725High· 7.5Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP req…
Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method.…
CVE-2025-67724Medium· 5.4tornado: Tornado Header Injection and XSS via reason argument (CVE-2025-67724)
An unescaped input flaw has been discovered in the Tornado networking library. In Tornado, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (whe…
CVE-2025-67644High· 7.3PoCLangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method
LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method
CVE-2025-67720Medium· 6.5Pyrofork has a Path Traversal in download_media Method
Pyrofork has a Path Traversal in download_media Method
CVE-2025-67485Medium· 5.3HTTP/HTTPS Traffic Interception Bypass in mad-proxy
HTTP/HTTPS Traffic Interception Bypass in mad-proxy
CVE-2025-66645High· 7.5NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read
NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read
CVE-2025-67502Medium· 5.4Open Redirect Vulnerability in Taguette
Open Redirect Vulnerability in Taguette
CVE-2025-66469Medium· 6.1NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection
NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection
CVE-2025-66470Medium· 6.1PoCNiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
MAL-2025-192323NoneMalicious code in rendom (PyPI)
Malicious code in rendom (PyPI)
CVE-2025-66418High· 7.5urllib3 is a user-friendly HTTP client library for Python
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of co…
CVE-2025-66471High· 7.5urllib3 is a user-friendly HTTP client library for Python
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large H…
CVE-2025-63681Lowopen-webui is Vulnerable to Incorrect Access Control
open-webui is Vulnerable to Incorrect Access Control
CVE-2025-65958High· 8.5Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
CVE-2025-14010Medium· 5.5Ansible Community General Collection is vulnerable to exposure of sensitive information
Ansible Community General Collection is vulnerable to exposure of sensitive information
CVE-2025-56427High· 7.5ComposioHQ has a directory traversal vulnerability
ComposioHQ has a directory traversal vulnerability
CVE-2025-64460MediumDjango is vulnerable to DoS via XML serializer text extraction
Django is vulnerable to DoS via XML serializer text extraction
CVE-2025-13372Medium· 4.3Django is vulnerable to SQL injection in column aliases
Django is vulnerable to SQL injection in column aliases
CVE-2025-65896Critical· 9.8asyncmy is vulnerable to SQL injection via crafted dict keys
asyncmy is vulnerable to SQL injection via crafted dict keys
CVE-2025-65858LowPoCCalibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
CVE-2025-12060Critical· 9.8Keras Directory Traversal Vulnerability
Keras Directory Traversal Vulnerability
CVE-2025-66221MediumWerkzeug safe_join() allows Windows special device names
Werkzeug safe_join() allows Windows special device names
CVE-2025-66454Medium· 6.5arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints
arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints
CVE-2025-66416HighModel Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
CVE-2025-66040Low· 3.6Spotipy has a XSS vulnerability in its OAuth callback server
Spotipy has a XSS vulnerability in its OAuth callback server
CVE-2025-66448High· 7.5vllm: vLLM: Remote Code Execution via malicious model configuration (CVE-2025-66448)
A remote code execution vulnerability has been identified in vLLM. An attacker can exploit a weakness in the model loading process to silently fetch and run unauthorized, malicious Python code on the host system. This happens because the e…
CVE-2025-66034Medium· 6.3PoCfontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
CVE-2025-66423High· 7.1trytond does not enforce access rights for the route of the HTML editor.
trytond does not enforce access rights for the route of the HTML editor.