Tagged “pip”
CVEs tagged pip, newest first.
4642 CVEsRSS
CVE-2025-61385Highpg8000 SQL injection vulnerability via a specially crafted Python list input
pg8000 SQL injection vulnerability via a specially crafted Python list input
CVE-2025-10282Medium· 4.7BBOT's gitlab.py exposes globally configured "gitlab" API key
BBOT's gitlab.py exposes globally configured "gitlab" API key
CVE-2025-8709High· 7.3LangGraph's SQLite store implementation has a SQL Injection Vulnerability
LangGraph's SQLite store implementation has a SQL Injection Vulnerability
CVE-2025-62707Mediumpypdf possibly loops infinitely when reading DCT inline images without EOF marker
pypdf possibly loops infinitely when reading DCT inline images without EOF marker
CVE-2025-62611Highaiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
CVE-2025-62708Mediumpypdf can exhaust RAM via manipulated LZWDecode streams
pypdf can exhaust RAM via manipulated LZWDecode streams
CVE-2025-11844Medium· 5.4PoCHugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function
Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function
CVE-2025-62607Medium· 5.3Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
CVE-2025-62379Low· 3.1reflex-dev/reflex has an Open Redirect vulnerability
reflex-dev/reflex has an Open Redirect vulnerability
CVE-2025-62172HighHome Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
CVE-2025-7707High· 7.1llama-index has Insecure Temporary File
llama-index has Insecure Temporary File
CVE-2025-61911Mediumpython-ldap has sanitization bypass in ldap.filter.escape_filter_chars
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
CVE-2025-61920High· 7.5Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
CVE-2025-61912Mediumpython-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
CVE-2025-62706Medium· 6.5Authlib : JWE zip=DEF decompression bomb enables DoS
Authlib : JWE zip=DEF decompression bomb enables DoS
CVE-2025-61783MediumPython Social Auth - Django has unsafe account association
Python Social Auth - Django has unsafe account association
CVE-2025-61773High· 8.1pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
CVE-2025-10281Medium· 4.7BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
CVE-2025-61672MediumSynapse's invalid device keys degrade federation functionality
Synapse's invalid device keys degrade federation functionality
CVE-2025-61670Low· 3.3Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref`…
Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref` or `externref` WebAssembly values. This is caused by a regression introduced during the development…
CVE-2025-59425High· 7.5vllm: Timing Attack in vLLM API Token Verification Leading to Authentication Bypass (CVE-2025-59425)
A flaw was found in vLLM’s API token authentication logic, where token comparisons were not performed in constant time. This weakness could allow an attacker to exploit timing differences to guess valid tokens and bypass authentication.
CVE-2025-61765Medium· 6.4PoCpython-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server depl…
python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments
CVE-2025-61620Medium· 6.5vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
CVE-2025-61784High· 7.6LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities
LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities
CVE-2025-6242High· 7.1vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
CVE-2025-6985High· 7.5LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing
LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing
CVE-2025-59152High· 7.5Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
CVE-2025-8406Medium· 6.3ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
CVE-2025-8917Medium· 5.8clearml is vulnerable to Path Traversal through its `safe_extract` function
clearml is vulnerable to Path Traversal through its `safe_extract` function
CVE-2025-53354Medium· 6.1NiceGUI has a Reflected XSS
NiceGUI has a Reflected XSS