VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4642 CVEsRSS

CVE-2025-61385High
11mo ago

pg8000 SQL injection vulnerability via a specially crafted Python list input

pg8000 SQL injection vulnerability via a specially crafted Python list input

▾ Twilightpg8000 · pg8000EPSS 0.36%via OSV
CVE-2025-10282Medium· 4.7
11mo ago

BBOT's gitlab.py exposes globally configured "gitlab" API key

BBOT's gitlab.py exposes globally configured "gitlab" API key

▾ Sunlitbbot · bbotEPSS 0.23%via OSV
CVE-2025-8709High· 7.3
11mo ago

LangGraph's SQLite store implementation has a SQL Injection Vulnerability

LangGraph's SQLite store implementation has a SQL Injection Vulnerability

▾ Twilightlanggraph-checkpoint-sqlite · langgraph-checkpoint-sqliteEPSS 0.18%via OSV
CVE-2025-62707Medium
11mo ago

pypdf possibly loops infinitely when reading DCT inline images without EOF marker

pypdf possibly loops infinitely when reading DCT inline images without EOF marker

▾ Sunlitpypdf · pypdfEPSS 0.44%via OSV
CVE-2025-62611High
11mo ago

aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server

aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server

▾ Twilightaiomysql · aiomysqlEPSS 0.39%via OSV
CVE-2025-62708Medium
11mo ago

pypdf can exhaust RAM via manipulated LZWDecode streams

pypdf can exhaust RAM via manipulated LZWDecode streams

▾ Sunlitpypdf · pypdfEPSS 0.44%via OSV
CVE-2025-11844Medium· 5.4PoC
11mo ago

Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function

Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function

▾ Twilightsmolagents · smolagentsEPSS 0.28%via OSV
CVE-2025-62607Medium· 5.3
11mo ago

Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL

Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL

▾ Sunlitnautobot-ssot · nautobot-ssotEPSS 0.29%via OSV
CVE-2025-62379Low· 3.1
11mo ago

reflex-dev/reflex has an Open Redirect vulnerability

reflex-dev/reflex has an Open Redirect vulnerability

▾ Sunlitreflex · reflexEPSS 0.25%via OSV
CVE-2025-62172High
11mo ago

Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name

Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name

▾ Twilighthomeassistant · homeassistantEPSS 0.42%via OSV
CVE-2025-7707High· 7.1
11mo ago

llama-index has Insecure Temporary File

llama-index has Insecure Temporary File

▾ Twilightllama-index · llama-indexEPSS 0.19%via OSV
CVE-2025-61911Medium
11mo ago

python-ldap has sanitization bypass in ldap.filter.escape_filter_chars

python-ldap has sanitization bypass in ldap.filter.escape_filter_chars

▾ Sunlitpython-ldap · python-ldapEPSS 0.32%via OSV
CVE-2025-61920High· 7.5
11mo ago

Authlib is vulnerable to Denial of Service via Oversized JOSE Segments

Authlib is vulnerable to Denial of Service via Oversized JOSE Segments

▾ Twilightauthlib · authlibEPSS 0.64%via OSV
CVE-2025-61912Medium
11mo ago

python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination

python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination

▾ Sunlitpython-ldap · python-ldapEPSS 0.46%via OSV
CVE-2025-62706Medium· 6.5
11mo ago

Authlib : JWE zip=DEF decompression bomb enables DoS

Authlib : JWE zip=DEF decompression bomb enables DoS

▾ Sunlitauthlib · authlibEPSS 0.46%via OSV
CVE-2025-61783Medium
11mo ago

Python Social Auth - Django has unsafe account association

Python Social Auth - Django has unsafe account association

▾ Sunlitsocial-auth-app-django · social-auth-app-djangoEPSS 0.42%via OSV
CVE-2025-61773High· 8.1
11mo ago

pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters

pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters

▾ Twilightpyload-ng · pyload-ngEPSS 0.41%via OSV
CVE-2025-10281Medium· 4.7
11mo ago

BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver

BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver

▾ Sunlitbbot · bbotEPSS 0.23%via OSV
CVE-2025-61672Medium
11mo ago

Synapse's invalid device keys degrade federation functionality

Synapse's invalid device keys degrade federation functionality

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.47%via OSV
CVE-2025-61670Low· 3.3
11mo ago

Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref`…

Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref` or `externref` WebAssembly values. This is caused by a regression introduced during the development…

▾ Sunlitwasmtime-bin · wasmtime-binEPSS 0.19%via OSV
CVE-2025-59425High· 7.5
11mo ago

vllm: Timing Attack in vLLM API Token Verification Leading to Authentication Bypass (CVE-2025-59425)

A flaw was found in vLLM’s API token authentication logic, where token comparisons were not performed in constant time. This weakness could allow an attacker to exploit timing differences to guess valid tokens and bypass authentication.

▾ TwilightRed Hat · Red Hat OpenShift AI 3.3EPSS 0.57%via CSAF
CVE-2025-61765Medium· 6.4PoC
11mo ago

python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server depl…

python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments

▾ Twilightpython-socketio · python-socketioEPSS 0.48%via OSV
CVE-2025-61620Medium· 6.5
11mo ago

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

▾ Sunlitvllm · vllmvia OSV
CVE-2025-61784High· 7.6
11mo ago

LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities

LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities

▾ Twilightllamafactory · llamafactoryEPSS 0.38%via OSV
CVE-2025-6242High· 7.1
11mo ago

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

▾ Twilightvllm · vllmEPSS 0.25%via OSV
CVE-2025-6985High· 7.5
11mo ago

LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing

LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing

▾ Twilightlangchain-text-splitters · langchain-text-splittersEPSS 0.51%via OSV
CVE-2025-59152High· 7.5
11mo ago

Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion

Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion

▾ Twilightlitestar · litestarEPSS 0.48%via OSV
CVE-2025-8406Medium· 6.3
11mo ago

ZenML is vulnerable to Path Traversal through its `PathMaterializer` class

ZenML is vulnerable to Path Traversal through its `PathMaterializer` class

▾ Sunlitzenml · zenmlEPSS 0.36%via OSV
CVE-2025-8917Medium· 5.8
11mo ago

clearml is vulnerable to Path Traversal through its `safe_extract` function

clearml is vulnerable to Path Traversal through its `safe_extract` function

▾ Sunlitclearml · clearmlEPSS 0.30%via OSV
CVE-2025-53354Medium· 6.1
12mo ago

NiceGUI has a Reflected XSS

NiceGUI has a Reflected XSS

▾ Sunlitnicegui · niceguiEPSS 0.20%via OSV
CVEs tagged “pip” — page 87 · VulnSea