Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2025-66422Medium· 4.3trytond allows remote attackers to obtain sensitive trace-back (server setup) information
trytond allows remote attackers to obtain sensitive trace-back (server setup) information
CVE-2025-66424Medium· 6.5trytond does not enforce access rights for data export
trytond does not enforce access rights for data export
CVE-2025-66371Medium· 5.0Peppol-py is vulnerable to XXE attacks due to Saxon configuration
Peppol-py is vulnerable to XXE attacks due to Saxon configuration
CVE-2025-34351CriticalRay's New Token Authentication is Disabled By Default
Ray's New Token Authentication is Disabled By Default
CVE-2025-62593CriticalCISA KEVPoCRay is an AI compute engine
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient gu…
CVE-2021-4472Medium· 6.5OpenStack's Mistral Client has a local file inclusion vulnerability
OpenStack's Mistral Client has a local file inclusion vulnerability
CVE-2025-62703High· 8.8Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer
Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer
CVE-2025-66019Mediumpypdf's LZWDecode streams be manipulated to exhaust RAM
pypdf's LZWDecode streams be manipulated to exhaust RAM
MAL-2025-191875NoneMalicious code in speed-testing-vps (PyPI)
Malicious code in speed-testing-vps (PyPI)
CVE-2025-62426Medium· 6.5vllm: vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs` (CVE-2025-624…
A vulnerability in vLLM allows an authenticated user to trigger unintended tokenization during chat template processing by supplying crafted chat_template_kwargs to the /v1/chat/completions or /tokenize endpoints. By forcing the server to …
CVE-2025-62372Medium· 6.5vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
CVE-2025-62164High· 8.8vLLM deserialization vulnerability leading to DoS and potential RCE
vLLM deserialization vulnerability leading to DoS and potential RCE
CVE-2025-65106HighLangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
CVE-2025-64521Medium· 4.8authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_se…
authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authent…
CVE-2025-65015Criticaljoserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
CVE-2025-64076High· 7.5Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (s…
Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (source/decoder.c): (1) Integer Underflow Leading to Out-of-Bounds Read (CWE-191, CWE-125): An incorre…
CVE-2025-60455CriticalModular Max Serve has Unsafe Deserialization vulnerability
Modular Max Serve has Unsafe Deserialization vulnerability
CVE-2025-65073High· 7.5OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
CVE-2025-64509High· 7.5Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)
CVE-2025-12763Medium· 6.8pgAdmin 4 has command injection vulnerability on Windows systems
pgAdmin 4 has command injection vulnerability on Windows systems
CVE-2025-12765High· 7.5pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verification
pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verification
CVE-2025-64508High· 7.5Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input
CVE-2025-12764High· 7.5pgAdmin is affected by an LDAP injection vulnerability
pgAdmin is affected by an LDAP injection vulnerability
CVE-2025-12967High· 8.0AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance
AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance
CVE-2025-57698HighAstrBot contains a directory traversal vulnerability
AstrBot contains a directory traversal vulnerability
CVE-2025-64512High· 8.6PoCArbitrary Code Execution in pdfminer.six via Crafted PDF Input
Arbitrary Code Execution in pdfminer.six via Crafted PDF Input
CVE-2025-57697MediumAstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
CVE-2025-70559High· 7.8PoCInsecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
CVE-2025-64458High· 7.5PoCDjango has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-64439HighLangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer