Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2025-58337MediumApache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
CVE-2025-12695Medium· 5.9DSPy does not properly restrict file reads
DSPy does not properly restrict file reads
CVE-2025-64187MediumOctoPrint vulnerable to XSS in Action Commands Notification and Prompt
OctoPrint vulnerable to XSS in Action Commands Notification and Prompt
CVE-2025-64184High· 8.8Dosage vulnerable to a Directory Traversal through crafted HTTP responses
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
CVE-2025-60787High· 7.2PoCmotionEye vulnerable to RCE via unsanitized motion config parameter
motionEye vulnerable to RCE via unsanitized motion config parameter
MAL-2025-191874NoneMalicious code in speed-testing-nt (PyPI)
Malicious code in speed-testing-nt (PyPI)
CVE-2025-64168High· 7.1Agno session state overwrites between different sessions/users
Agno session state overwrites between different sessions/users
CVE-2025-63675Medium· 6.9cryptidy allows code execution via untrusted data due to pickle.loads
cryptidy allows code execution via untrusted data due to pickle.loads
CVE-2025-6176High· 7.5Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
CVE-2025-54941MediumApache Airflow has a command injection vulnerability in "example_dag_decorator"
Apache Airflow has a command injection vulnerability in "example_dag_decorator"
CVE-2025-50736LowByaidu PDFMathTranslate vulnerable to open redirect
Byaidu PDFMathTranslate vulnerable to open redirect
CVE-2025-62503Medium· 4.6Apache Airflow's create action can upsert existing Pools/Connections/Variables
Apache Airflow's create action can upsert existing Pools/Connections/Variables
CVE-2025-62402Medium· 5.4Apache Airflow `/api/v2/dagReports` executes DAG Python in API
Apache Airflow `/api/v2/dagReports` executes DAG Python in API
CVE-2025-13327Mediumuv allows ZIP payload obfuscation through parsing differentials
uv allows ZIP payload obfuscation through parsing differentials
CVE-2025-62801MediumFastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
CVE-2025-62800MediumFastMCP vulnerable to reflected XSS in client's callback page
FastMCP vulnerable to reflected XSS in client's callback page
CVE-2025-12058MediumKeras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
CVE-2025-64104High· 7.3LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
CVE-2025-11200High· 8.10dayMLflow Weak Password Requirements Authentication Bypass Vulnerability
MLflow Weak Password Requirements Authentication Bypass Vulnerability
CVE-2025-11201High· 8.10dayPoCMLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
CVE-2025-54384Medium· 6.3CKAN vulnerable to stored XSS in resource description
CKAN vulnerable to stored XSS in resource description
CVE-2025-64100Medium· 6.1CKAN vulnerable to fixed session IDs
CKAN vulnerable to fixed session IDs
MAL-2025-191876NoneMalicious code in speedd-testing-bot (PyPI)
Malicious code in speedd-testing-bot (PyPI)
CVE-2025-62727High· 7.5PoCStarlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
CVE-2025-61385Highpg8000 SQL injection vulnerability via a specially crafted Python list input
pg8000 SQL injection vulnerability via a specially crafted Python list input
CVE-2025-10282Medium· 4.7BBOT's gitlab.py exposes globally configured "gitlab" API key
BBOT's gitlab.py exposes globally configured "gitlab" API key
CVE-2025-8709High· 7.3LangGraph's SQLite store implementation has a SQL Injection Vulnerability
LangGraph's SQLite store implementation has a SQL Injection Vulnerability
CVE-2025-62707Mediumpypdf possibly loops infinitely when reading DCT inline images without EOF marker
pypdf possibly loops infinitely when reading DCT inline images without EOF marker
CVE-2025-62611Highaiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
CVE-2025-62708Mediumpypdf can exhaust RAM via manipulated LZWDecode streams
pypdf can exhaust RAM via manipulated LZWDecode streams