Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2025-57833High· 7.1PoCDjango is subject to SQL injection through its column aliases
Django is subject to SQL injection through its column aliases
CVE-2025-57766Medium· 4.8Fides' Admin UI User Password Change Does Not Invalidate Current Session
Fides' Admin UI User Password Change Does Not Invalidate Current Session
CVE-2025-57817High· 7.2Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation
Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation
CVE-2025-57816High· 7.5Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
CVE-2025-57815Medium· 6.5Fides has a Lack of Brute-Force Protections on Authentication Endpoints
Fides has a Lack of Brute-Force Protections on Authentication Endpoints
CVE-2025-55671High· 7.8TkEasyGUI Affected by Uncontrolled Search Path Element Issue
TkEasyGUI Affected by Uncontrolled Search Path Element Issue
CVE-2025-58446Mediumxgrammar vulnerable to denial of service by huge enum grammar
xgrammar vulnerable to denial of service by huge enum grammar
CVE-2025-9636High· 7.9pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability
pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability
CVE-2025-6984High· 7.5Langchain Community Vulnerable to XML External Entity (XXE) Attacks
Langchain Community Vulnerable to XML External Entity (XXE) Attacks
CVE-2025-58352LowWeblate has a long session expiry when verifying second factor
Weblate has a long session expiry when verifying second factor
CVE-2025-57808High· 8.1PoCESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
CVE-2025-58161LowMobSF Path Traversal in GET /download/<filename> using absolute filenames
MobSF Path Traversal in GET /download/<filename> using absolute filenames
CVE-2025-58162Medium· 6.5MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction
MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction
CVE-2023-41471High· 7.8Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to t…
Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors…
CVE-2025-55304LowExiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
CVE-2025-58068MediumEventlet affected by HTTP request smuggling in unparsed trailers
Eventlet affected by HTTP request smuggling in unparsed trailers
CVE-2025-54080LowExiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
CVE-2025-58050Critical· 9.1The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow re…
The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the han…
CVE-2025-71378MediumPicklescan is missing detection when calling built-in Python cProfile.runctx
Picklescan is missing detection when calling built-in Python cProfile.runctx
CVE-2025-71357HighPicklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
CVE-2025-71344MediumPicklescan is missing detection when calling built-in python ensurepip._run_pip
Picklescan is missing detection when calling built-in python ensurepip._run_pip
CVE-2025-71374MediumPicklescan has a missing detection when calling built-in python profile.Profile.run
Picklescan has a missing detection when calling built-in python profile.Profile.run
CVE-2025-48956High· 7.5vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests (CVE-2025-48956)
A flaw was found in vLLM. A denial of service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large X-Forwarded-For header to an HTTP endpoint. This results in server memory exhaustion, potential…
CVE-2025-71352MediumPicklescan has a missing detection when calling built-in python trace.Trace.runctx
Picklescan has a missing detection when calling built-in python trace.Trace.runctx
CVE-2025-71368MediumPicklescan is missing detection when calling built-in python doctest.debug_script
Picklescan is missing detection when calling built-in python doctest.debug_script
CVE-2025-71371MediumPicklescan has a missing detection when calling built-in python code.InteractiveInterpreter
Picklescan has a missing detection when calling built-in python code.InteractiveInterpreter
CVE-2025-11058Highxml2rfc has an arbitrary file read vulnerability
xml2rfc has an arbitrary file read vulnerability
CVE-2025-71361MediumPicklescan has a missing detection when calling built-in python idlelib.calltip.Calltip
Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip
CVE-2025-71376High· 8.1Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
CVE-2025-5302High· 8.6LlamaIndex affected by a Denial of Service (DOS) in JSONReader
LlamaIndex affected by a Denial of Service (DOS) in JSONReader