VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2025-66422Medium· 4.3
10mo ago

trytond allows remote attackers to obtain sensitive trace-back (server setup) information

trytond allows remote attackers to obtain sensitive trace-back (server setup) information

▾ Sunlittrytond · trytondEPSS 0.29%via OSV
CVE-2025-66424Medium· 6.5
10mo ago

trytond does not enforce access rights for data export

trytond does not enforce access rights for data export

▾ Sunlittrytond · trytondEPSS 0.24%via OSV
CVE-2025-66371Medium· 5.0
10mo ago

Peppol-py is vulnerable to XXE attacks due to Saxon configuration

Peppol-py is vulnerable to XXE attacks due to Saxon configuration

▾ Sunlitpeppol-py · peppol-pyEPSS 0.32%via OSV
CVE-2025-34351Critical
10mo ago

Ray's New Token Authentication is Disabled By Default

Ray's New Token Authentication is Disabled By Default

▾ Midnightray · rayvia OSV
CVE-2025-62593CriticalCISA KEVPoC
10mo ago

Ray is an AI compute engine

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient gu…

▾ Hadalray · rayEPSS 62%via NVD
CVE-2021-4472Medium· 6.5
10mo ago

OpenStack's Mistral Client has a local file inclusion vulnerability

OpenStack's Mistral Client has a local file inclusion vulnerability

▾ Sunlitpython-mistralclient · python-mistralclientEPSS 0.46%via OSV
CVE-2025-62703High· 8.8
10mo ago

Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer

Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer

▾ Twilightfugue · fugueEPSS 0.73%via OSV
CVE-2025-66019Medium
10mo ago

pypdf's LZWDecode streams be manipulated to exhaust RAM

pypdf's LZWDecode streams be manipulated to exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.36%via OSV
MAL-2025-191875None
10mo ago

Malicious code in speed-testing-vps (PyPI)

Malicious code in speed-testing-vps (PyPI)

▾ Sunlitspeed-testing-vps · speed-testing-vpsvia OSV
CVE-2025-62426Medium· 6.5
10mo ago

vllm: vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs` (CVE-2025-624…

A vulnerability in vLLM allows an authenticated user to trigger unintended tokenization during chat template processing by supplying crafted chat_template_kwargs to the /v1/chat/completions or /tokenize endpoints. By forcing the server to …

▾ SunlitRed Hat · Red Hat Enterprise Linux AI (RHEL AI)EPSS 0.37%via CSAF
CVE-2025-62372Medium· 6.5
10mo ago

vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

▾ Sunlitvllm · vllmEPSS 0.38%via OSV
CVE-2025-62164High· 8.8
10mo ago

vLLM deserialization vulnerability leading to DoS and potential RCE

vLLM deserialization vulnerability leading to DoS and potential RCE

▾ Twilightvllm · vllmEPSS 0.93%via OSV
CVE-2025-65106High
10mo ago

LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates

LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates

▾ Twilightlangchain-core · langchain-coreEPSS 0.51%via OSV
CVE-2025-64521Medium· 4.8
10mo ago

authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_se…

authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authent…

▾ Sunlitauthentik-client · authentik-clientEPSS 0.22%via OSV
CVE-2025-65015Critical
10mo ago

joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads

joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads

▾ Midnightjoserfc · joserfcEPSS 0.41%via OSV
CVE-2025-64076High· 7.5
10mo ago

Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (s…

Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (source/decoder.c): (1) Integer Underflow Leading to Out-of-Bounds Read (CWE-191, CWE-125): An incorre…

▾ Twilightcbor2 · cbor2EPSS 0.46%via OSV
CVE-2025-60455Critical
10mo ago

Modular Max Serve has Unsafe Deserialization vulnerability

Modular Max Serve has Unsafe Deserialization vulnerability

▾ Midnightmodular · modularEPSS 0.31%via OSV
CVE-2025-65073High· 7.5
10mo ago

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

▾ Twilightkeystone · keystoneEPSS 0.23%via OSV
CVE-2025-64509High· 7.5
10mo ago

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)

▾ Twilightbugsink · bugsinkEPSS 0.32%via OSV
CVE-2025-12763Medium· 6.8
10mo ago

pgAdmin 4 has command injection vulnerability on Windows systems

pgAdmin 4 has command injection vulnerability on Windows systems

▾ Sunlitpgadmin4 · pgadmin4EPSS 0.94%via OSV
CVE-2025-12765High· 7.5
10mo ago

pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verification

pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verification

▾ Twilightpgadmin4 · pgadmin4EPSS 0.22%via OSV
CVE-2025-64508High· 7.5
10mo ago

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input

▾ Twilightbugsink · bugsinkEPSS 0.47%via OSV
CVE-2025-12764High· 7.5
10mo ago

pgAdmin is affected by an LDAP injection vulnerability

pgAdmin is affected by an LDAP injection vulnerability

▾ Twilightpgadmin4 · pgadmin4EPSS 0.45%via OSV
CVE-2025-12967High· 8.0
10mo ago

AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance

AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance

▾ Twilightaws-advanced-python-wrapper · aws-advanced-python-wrapperEPSS 0.45%via OSV
CVE-2025-57698High
10mo ago

AstrBot contains a directory traversal vulnerability

AstrBot contains a directory traversal vulnerability

▾ Twilightastrbot · astrbotEPSS 0.78%via OSV
CVE-2025-64512High· 8.6PoC
10mo ago

Arbitrary Code Execution in pdfminer.six via Crafted PDF Input

Arbitrary Code Execution in pdfminer.six via Crafted PDF Input

▾ Midnightpdfminer-six · pdfminer-sixEPSS 0.31%via OSV
CVE-2025-57697Medium
10mo ago

AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64

AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64

▾ Sunlitastrbot · astrbotEPSS 0.32%via OSV
CVE-2025-70559High· 7.8PoC
10mo ago

Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc

Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc

▾ Midnightpdfminer-six · pdfminer-sixEPSS 0.30%via OSV
CVE-2025-64458High· 7.5PoC
10mo ago

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

▾ Midnightdjango · djangoEPSS 1.9%via OSV
CVE-2025-64439High
10mo ago

LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer

LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer

▾ Twilightlanggraph-checkpoint · langgraph-checkpointEPSS 0.88%via OSV
CVEs tagged “pip” — page 85 · VulnSea