VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2025-58337Medium
10mo ago

Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode

Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode

▾ Sunlitdoris-mcp-server · doris-mcp-serverEPSS 0.35%via OSV
CVE-2025-12695Medium· 5.9
10mo ago

DSPy does not properly restrict file reads

DSPy does not properly restrict file reads

▾ Sunlitdspy · dspyEPSS 0.32%via OSV
CVE-2025-64187Medium
10mo ago

OctoPrint vulnerable to XSS in Action Commands Notification and Prompt

OctoPrint vulnerable to XSS in Action Commands Notification and Prompt

▾ Sunlitoctoprint · octoprintEPSS 0.16%via OSV
CVE-2025-64184High· 8.8
10mo ago

Dosage vulnerable to a Directory Traversal through crafted HTTP responses

Dosage vulnerable to a Directory Traversal through crafted HTTP responses

▾ Twilightdosage · dosageEPSS 0.45%via OSV
CVE-2025-60787High· 7.2PoC
11mo ago

motionEye vulnerable to RCE via unsanitized motion config parameter

motionEye vulnerable to RCE via unsanitized motion config parameter

▾ Midnightmotioneye · motioneyeEPSS 18%via OSV
MAL-2025-191874None
11mo ago

Malicious code in speed-testing-nt (PyPI)

Malicious code in speed-testing-nt (PyPI)

▾ Sunlitspeed-testing-nt · speed-testing-ntvia OSV
CVE-2025-64168High· 7.1
11mo ago

Agno session state overwrites between different sessions/users

Agno session state overwrites between different sessions/users

▾ Twilightagno · agnoEPSS 0.15%via OSV
CVE-2025-63675Medium· 6.9
11mo ago

cryptidy allows code execution via untrusted data due to pickle.loads

cryptidy allows code execution via untrusted data due to pickle.loads

▾ Sunlitcryptidy · cryptidyEPSS 0.24%via OSV
CVE-2025-6176High· 7.5
11mo ago

Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

▾ Twilightbrotli · brotliEPSS 0.50%via OSV
CVE-2025-54941Medium
11mo ago

Apache Airflow has a command injection vulnerability in "example_dag_decorator"

Apache Airflow has a command injection vulnerability in "example_dag_decorator"

▾ Sunlitapache-airflow · apache-airflowEPSS 0.46%via OSV
CVE-2025-50736Low
11mo ago

Byaidu PDFMathTranslate vulnerable to open redirect

Byaidu PDFMathTranslate vulnerable to open redirect

▾ Sunlitpdf2zh · pdf2zhEPSS 0.21%via OSV
CVE-2025-62503Medium· 4.6
11mo ago

Apache Airflow's create action can upsert existing Pools/Connections/Variables

Apache Airflow's create action can upsert existing Pools/Connections/Variables

▾ Sunlitapache-airflow · apache-airflowEPSS 0.40%via OSV
CVE-2025-62402Medium· 5.4
11mo ago

Apache Airflow `/api/v2/dagReports` executes DAG Python in API

Apache Airflow `/api/v2/dagReports` executes DAG Python in API

▾ Sunlitapache-airflow · apache-airflowEPSS 0.49%via OSV
CVE-2025-13327Medium
11mo ago

uv allows ZIP payload obfuscation through parsing differentials

uv allows ZIP payload obfuscation through parsing differentials

▾ Sunlituv · uvEPSS 0.15%via OSV
CVE-2025-62801Medium
11mo ago

FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name

FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name

▾ Sunlitfastmcp · fastmcpEPSS 0.21%via OSV
CVE-2025-62800Medium
11mo ago

FastMCP vulnerable to reflected XSS in client's callback page

FastMCP vulnerable to reflected XSS in client's callback page

▾ Sunlitfastmcp · fastmcpEPSS 0.26%via OSV
CVE-2025-12058Medium
11mo ago

Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery

Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery

▾ Sunlitkeras · kerasEPSS 0.25%via OSV
CVE-2025-64104High· 7.3
11mo ago

LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore

LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore

▾ Twilightlanggraph-checkpoint-sqlite · langgraph-checkpoint-sqliteEPSS 0.18%via OSV
CVE-2025-11200High· 8.10day
11mo ago

MLflow Weak Password Requirements Authentication Bypass Vulnerability

MLflow Weak Password Requirements Authentication Bypass Vulnerability

▾ Abyssalmlflow · mlflowEPSS 1.5%via OSV
CVE-2025-11201High· 8.10dayPoC
11mo ago

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability

▾ Abyssalmlflow · mlflowEPSS 27%via OSV
CVE-2025-54384Medium· 6.3
11mo ago

CKAN vulnerable to stored XSS in resource description

CKAN vulnerable to stored XSS in resource description

▾ Sunlitckan · ckanEPSS 0.21%via OSV
CVE-2025-64100Medium· 6.1
11mo ago

CKAN vulnerable to fixed session IDs

CKAN vulnerable to fixed session IDs

▾ Sunlitckan · ckanEPSS 0.28%via OSV
MAL-2025-191876None
11mo ago

Malicious code in speedd-testing-bot (PyPI)

Malicious code in speedd-testing-bot (PyPI)

▾ Sunlitspeedd-testing-bot · speedd-testing-botvia OSV
CVE-2025-62727High· 7.5PoC
11mo ago

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

▾ Midnightstarlette · starletteEPSS 0.64%via OSV
CVE-2025-61385High
11mo ago

pg8000 SQL injection vulnerability via a specially crafted Python list input

pg8000 SQL injection vulnerability via a specially crafted Python list input

▾ Twilightpg8000 · pg8000EPSS 0.36%via OSV
CVE-2025-10282Medium· 4.7
11mo ago

BBOT's gitlab.py exposes globally configured "gitlab" API key

BBOT's gitlab.py exposes globally configured "gitlab" API key

▾ Sunlitbbot · bbotEPSS 0.23%via OSV
CVE-2025-8709High· 7.3
11mo ago

LangGraph's SQLite store implementation has a SQL Injection Vulnerability

LangGraph's SQLite store implementation has a SQL Injection Vulnerability

▾ Twilightlanggraph-checkpoint-sqlite · langgraph-checkpoint-sqliteEPSS 0.18%via OSV
CVE-2025-62707Medium
11mo ago

pypdf possibly loops infinitely when reading DCT inline images without EOF marker

pypdf possibly loops infinitely when reading DCT inline images without EOF marker

▾ Sunlitpypdf · pypdfEPSS 0.44%via OSV
CVE-2025-62611High
11mo ago

aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server

aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server

▾ Twilightaiomysql · aiomysqlEPSS 0.39%via OSV
CVE-2025-62708Medium
11mo ago

pypdf can exhaust RAM via manipulated LZWDecode streams

pypdf can exhaust RAM via manipulated LZWDecode streams

▾ Sunlitpypdf · pypdfEPSS 0.44%via OSV
CVEs tagged “pip” — page 86 · VulnSea