VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2025-61677Low· 2.5
12mo ago

DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables

DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables

▾ Sunlitdatachain · datachainEPSS 0.16%via OSV
GHSA-xjv7-6w92-42r7Medium
12mo ago

marimo vulnerable to proxy abuse of /mpl/{port}/

marimo vulnerable to proxy abuse of /mpl/{port}/

▾ Sunlitmarimo · marimovia OSV
CVE-2025-61587Medium· 6.1
12mo ago

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website…

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL…

▾ Sunlitweblate · weblateEPSS 0.39%via OSV
CVE-2025-59682High· 8.8⚖ disputed
12mo ago

django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682)

A flaw was found in Django. The django.utils.archive.extract() function, used by startapp --templateand startproject --template, allowed partial directory-traversal via an archive with file paths sharing a common prefix with the target dir…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2.5 for RHEL 8EPSS 0.91%via CSAF
CVE-2025-57275Medium· 5.5
12mo ago

SPDK is vulnerable to buffer overflow in the NVMe-oF target component

SPDK is vulnerable to buffer overflow in the NVMe-oF target component

▾ Sunlitspdk · spdkEPSS 0.33%via OSV
CVE-2025-59940Medium· 6.5
1y ago

mkdocs-include-markdown-plugin: mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders (C…

There is an improper input validation flaw in the python `mkdocs-include-markdown-plugin` package. Under certain conditions placeholders are not properly validated and may collide with other data elements resulting in inconsistent output.

▾ SunlitRed Hat · Multicluster Engine for KubernetesEPSS 0.34%via CSAF
CVE-2025-7647High· 7.3
1y ago

llama-index-core insecurely handles temporary files

llama-index-core insecurely handles temporary files

▾ Twilightllama-index-core · llama-index-coreEPSS 0.15%via OSV
CVE-2025-59842Low
1y ago

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute

▾ Sunlitjupyterlab · jupyterlabEPSS 0.24%via OSV
CVE-2025-10952Medium· 5.3PoC
1y ago

ml-logger file handler allows reading arbitrary files

ml-logger file handler allows reading arbitrary files

▾ Twilightml-logger · ml-loggerEPSS 0.45%via OSV
CVE-2025-10951High· 7.3PoC
1y ago

ml-logger has path traversal in the file argument

ml-logger has path traversal in the file argument

▾ Midnightml-logger · ml-loggerEPSS 0.61%via OSV
CVE-2025-10950Medium· 6.3
1y ago

ml-logger deserialization vulnerability

ml-logger deserialization vulnerability

▾ Sunlitml-logger · ml-loggerEPSS 0.31%via OSV
CVE-2025-55178Medium· 5.3
1y ago

Llama Stack could potentially allow for remote code execution

Llama Stack could potentially allow for remote code execution

▾ Sunlitllama-stack · llama-stackEPSS 0.50%via OSV
CVE-2025-8869Medium
1y ago

When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known…

When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known…

▾ Sunlitpip · pipEPSS 0.47%via NVD
CVE-2025-6921Medium· 5.3
1y ago

Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer

Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer

▾ Sunlittransformers · transformersEPSS 0.51%via OSV
CVE-2025-59420High· 7.5
1y ago

authlib: Authlib RFC violation (CVE-2025-59420)

Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 “must‑understand” semantics. An attacker can craft a signed token with a critical header (for example, bork or cnf) that s…

▾ TwilightRed Hat · Red Hat Quay 3.10EPSS 0.26%via CSAF
CVE-2025-9905High
1y ago

The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file i…

The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.

▾ Twilightkeras · kerasEPSS 0.22%via OSV
CVE-2025-9906High· 7.3
1y ago

Keras is vulnerable to Deserialization of Untrusted Data

Keras is vulnerable to Deserialization of Untrusted Data

▾ Twilightkeras · kerasEPSS 0.20%via OSV
CVE-2025-59376Medium· 5.3PoC
1y ago

mcp-kubernetes-server has a Command Injection vulnerability

mcp-kubernetes-server has a Command Injection vulnerability

▾ Twilightmcp-kubernetes-server · mcp-kubernetes-serverEPSS 0.30%via OSV
CVE-2025-6051Medium· 5.3
1y ago

Hugging Face Transformers library has Regular Expression Denial of Service

Hugging Face Transformers library has Regular Expression Denial of Service

▾ Sunlittransformers · transformersEPSS 0.38%via OSV
CVE-2025-6638Medium· 5.3
1y ago

Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer

Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer

▾ Sunlittransformers · transformersEPSS 0.53%via OSV
CVE-2025-10193High
1y ago

Neo4j Cypher MCP server is vulnerable to DNS rebinding

Neo4j Cypher MCP server is vulnerable to DNS rebinding

▾ Twilightmcp-neo4j-cypher · mcp-neo4j-cypherEPSS 0.22%via OSV
CVE-2025-58065Medium· 6.5
1y ago

Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods

Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods

▾ Sunlitflask-appbuilder · flask-appbuilderEPSS 0.40%via OSV
CVE-2025-59036Medium· 5.5
1y ago

Infrahub: Deleted and expired API tokens can still authenticate

Infrahub: Deleted and expired API tokens can still authenticate

▾ Sunlitinfrahub-server · infrahub-serverEPSS 0.19%via OSV
CVE-2025-59042High
1y ago

PyInstaller has local privilege escalation vulnerability

PyInstaller has local privilege escalation vulnerability

▾ Twilightpyinstaller · pyinstallerEPSS 0.12%via OSV
CVE-2025-11059High
1y ago

xml2rfc is vulnerable to arbitrary file reads through prepped files

xml2rfc is vulnerable to arbitrary file reads through prepped files

▾ Twilightxml2rfc · xml2rfcvia OSV
CVE-2025-59035Medium· 4.6
1y ago

Indico vulnerable to Cross-Site Scripting via LaTeX math code

Indico vulnerable to Cross-Site Scripting via LaTeX math code

▾ Sunlitindico · indicoEPSS 0.20%via OSV
CVE-2025-59034Medium· 4.3
1y ago

Indico may disclose unauthorized user details access via legacy API

Indico may disclose unauthorized user details access via legacy API

▾ Sunlitindico · indicoEPSS 0.25%via OSV
CVE-2025-58753Medium
1y ago

copyparty: Sharing a single file does not fully restrict access to other files in source folder

copyparty: Sharing a single file does not fully restrict access to other files in source folder

▾ Sunlitcopyparty · copypartyEPSS 0.37%via OSV
CVE-2025-10164High· 7.3
1y ago

SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor

SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor

▾ Twilightsglang · sglangEPSS 0.40%via OSV
CVE-2025-58180High· 8.8PoC
1y ago

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

▾ Midnightoctoprint · octoprintEPSS 21%via OSV
CVEs tagged “pip” — page 88 · VulnSea