VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2025-57833High· 7.1PoC
1y ago

Django is subject to SQL injection through its column aliases

Django is subject to SQL injection through its column aliases

▾ Midnightdjango · djangoEPSS 17%via OSV
CVE-2025-57766Medium· 4.8
1y ago

Fides' Admin UI User Password Change Does Not Invalidate Current Session

Fides' Admin UI User Password Change Does Not Invalidate Current Session

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.30%via OSV
CVE-2025-57817High· 7.2
1y ago

Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation

Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.42%via OSV
CVE-2025-57816High· 7.5
1y ago

Fides Webserver API Rate Limiting Vulnerability in Proxied Environments

Fides Webserver API Rate Limiting Vulnerability in Proxied Environments

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.43%via OSV
CVE-2025-57815Medium· 6.5
1y ago

Fides has a Lack of Brute-Force Protections on Authentication Endpoints

Fides has a Lack of Brute-Force Protections on Authentication Endpoints

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.29%via OSV
CVE-2025-55671High· 7.8
1y ago

TkEasyGUI Affected by Uncontrolled Search Path Element Issue

TkEasyGUI Affected by Uncontrolled Search Path Element Issue

▾ Twilighttkeasygui · tkeasyguiEPSS 0.16%via OSV
CVE-2025-58446Medium
1y ago

xgrammar vulnerable to denial of service by huge enum grammar

xgrammar vulnerable to denial of service by huge enum grammar

▾ Sunlitxgrammar · xgrammarEPSS 0.53%via OSV
CVE-2025-9636High· 7.9
1y ago

pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability

pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability

▾ Twilightpgadmin4 · pgadmin4EPSS 0.22%via OSV
CVE-2025-6984High· 7.5
1y ago

Langchain Community Vulnerable to XML External Entity (XXE) Attacks

Langchain Community Vulnerable to XML External Entity (XXE) Attacks

▾ Twilightlangchain-community · langchain-communityEPSS 1.6%via OSV
CVE-2025-58352Low
1y ago

Weblate has a long session expiry when verifying second factor

Weblate has a long session expiry when verifying second factor

▾ Sunlitweblate · weblateEPSS 0.29%via OSV
CVE-2025-57808High· 8.1PoC
1y ago

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

▾ Midnightesphome · esphomeEPSS 1.6%via OSV
CVE-2025-58161Low
1y ago

MobSF Path Traversal in GET /download/<filename> using absolute filenames

MobSF Path Traversal in GET /download/<filename> using absolute filenames

▾ Sunlitmobsf · mobsfEPSS 0.78%via OSV
CVE-2025-58162Medium· 6.5
1y ago

MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction

MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction

▾ Sunlitmobsf · mobsfEPSS 0.60%via OSV
CVE-2023-41471High· 7.8
1y ago

Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to t…

Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors…

▾ Twilightcopyparty · copypartyEPSS 0.26%via OSV
CVE-2025-55304Low
1y ago

Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata

Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata

▾ Sunlitexiv2 · exiv2EPSS 0.24%via OSV
CVE-2025-58068Medium
1y ago

Eventlet affected by HTTP request smuggling in unparsed trailers

Eventlet affected by HTTP request smuggling in unparsed trailers

▾ Sunliteventlet · eventletEPSS 0.39%via OSV
CVE-2025-54080Low
1y ago

Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file

Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file

▾ Sunlitexiv2 · exiv2EPSS 0.14%via OSV
CVE-2025-58050Critical· 9.1
1y ago

The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow re…

The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the han…

▾ Midnightpcre2 · pcre2EPSS 0.80%via OSV
CVE-2025-71378Medium
1y ago

Picklescan is missing detection when calling built-in Python cProfile.runctx

Picklescan is missing detection when calling built-in Python cProfile.runctx

▾ Sunlitpicklescan · picklescanEPSS 0.48%via OSV
CVE-2025-71357High
1y ago

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

▾ Twilightpicklescan · picklescanEPSS 0.39%via OSV
CVE-2025-71344Medium
1y ago

Picklescan is missing detection when calling built-in python ensurepip._run_pip

Picklescan is missing detection when calling built-in python ensurepip._run_pip

▾ Sunlitpicklescan · picklescanEPSS 0.64%via OSV
CVE-2025-71374Medium
1y ago

Picklescan has a missing detection when calling built-in python profile.Profile.run

Picklescan has a missing detection when calling built-in python profile.Profile.run

▾ Sunlitpicklescan · picklescanEPSS 0.64%via OSV
CVE-2025-48956High· 7.5
1y ago

vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests (CVE-2025-48956)

A flaw was found in vLLM. A denial of service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large X-Forwarded-For header to an HTTP endpoint. This results in server memory exhaustion, potential…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI (RHEL AI)EPSS 0.56%via CSAF
CVE-2025-71352Medium
1y ago

Picklescan has a missing detection when calling built-in python trace.Trace.runctx

Picklescan has a missing detection when calling built-in python trace.Trace.runctx

▾ Sunlitpicklescan · picklescanEPSS 0.64%via OSV
CVE-2025-71368Medium
1y ago

Picklescan is missing detection when calling built-in python doctest.debug_script

Picklescan is missing detection when calling built-in python doctest.debug_script

▾ Sunlitpicklescan · picklescanEPSS 0.84%via OSV
CVE-2025-71371Medium
1y ago

Picklescan has a missing detection when calling built-in python code.InteractiveInterpreter

Picklescan has a missing detection when calling built-in python code.InteractiveInterpreter

▾ Sunlitpicklescan · picklescanEPSS 0.54%via OSV
CVE-2025-11058High
1y ago

xml2rfc has an arbitrary file read vulnerability

xml2rfc has an arbitrary file read vulnerability

▾ Twilightxml2rfc · xml2rfcvia OSV
CVE-2025-71361Medium
1y ago

Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip

Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip

▾ Sunlitpicklescan · picklescanEPSS 0.60%via OSV
CVE-2025-71376High· 8.1
1y ago

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

▾ Twilightpicklescan · picklescanEPSS 0.43%via OSV
CVE-2025-5302High· 8.6
1y ago

LlamaIndex affected by a Denial of Service (DOS) in JSONReader

LlamaIndex affected by a Denial of Service (DOS) in JSONReader

▾ Twilightllama-index-core · llama-index-coreEPSS 0.29%via OSV
CVEs tagged “pip” — page 89 · VulnSea