VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2025-71358Medium
1y ago

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity

▾ Sunlitpicklescan · picklescanEPSS 0.43%via OSV
CVE-2025-71341High· 8.1
1y ago

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

▾ Twilightpicklescan · picklescanEPSS 0.61%via OSV
CVE-2025-71349Medium
1y ago

Picklescan has a missing detection when calling built-in python trace.Trace.run

Picklescan has a missing detection when calling built-in python trace.Trace.run

▾ Sunlitpicklescan · picklescanEPSS 0.61%via OSV
CVE-2025-71363Medium
1y ago

Picklescan is missing detection when calling built-in python cProfile.run

Picklescan is missing detection when calling built-in python cProfile.run

▾ Sunlitpicklescan · picklescanEPSS 0.64%via OSV
CVE-2025-71354Medium
1y ago

Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem

Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem

▾ Sunlitpicklescan · picklescanEPSS 0.45%via OSV
CVE-2025-71340Medium
1y ago

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode

▾ Sunlitpicklescan · picklescanEPSS 0.43%via OSV
GHSA-63cx-g855-hvv4Medium
1y ago

mitmproxy binaries embed a vulnerable python-hyper/h2 dependency

mitmproxy binaries embed a vulnerable python-hyper/h2 dependency

▾ Sunlitmitmproxy · mitmproxyvia OSV
CVE-2025-57804Medium
1y ago

h2 allows HTTP Request Smuggling due to illegal characters in headers

h2 allows HTTP Request Smuggling due to illegal characters in headers

▾ Sunlith2 · h2EPSS 1.7%via OSV
CVE-2025-57809High· 7.5
1y ago

xgrammar: XGrammar affected by Denial of Service by infinite recursion grammars (CVE-2025-57809)

A flaw was found in xgrammar. Recursive grammar definitions could trigger infinite recursion during parsing in GrammarMatcherBase::ExpandEquivalentStackElements, leading to unbounded stack growth and a segmentation fault. This vulnerabilit…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI 1.5EPSS 0.47%via CSAF
CVE-2025-57760High· 8.8
1y ago

Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)

Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)

▾ Twilightlangflow · langflowEPSS 0.52%via OSV
CVE-2025-71348High· 8.1
1y ago

Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config

Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config

▾ Twilightpicklescan · picklescanEPSS 0.55%via OSV
CVE-2025-71370High· 8.1
1y ago

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

▾ Twilightpicklescan · picklescanEPSS 0.54%via OSV
CVE-2025-71350Medium
1y ago

Picklescan missing detection when calling pytorch function torch.utils.collect_env.run

Picklescan missing detection when calling pytorch function torch.utils.collect_env.run

▾ Sunlitpicklescan · picklescanEPSS 0.43%via OSV
CVE-2025-57751High
1y ago

Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs

Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs

▾ Twilightpyload-ng · pyload-ngEPSS 0.33%via OSV
CVE-2025-9141High· 8.8
1y ago

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

▾ Twilightvllm · vllmvia OSV
CVE-2025-55214Medium
1y ago

Copier's safe template has filesystem write access outside destination path

Copier's safe template has filesystem write access outside destination path

▾ Sunlitcopier · copierEPSS 0.26%via OSV
CVE-2025-55201High
1y ago

Copier's safe template has arbitrary filesystem read/write access

Copier's safe template has arbitrary filesystem read/write access

▾ Twilightcopier · copierEPSS 0.26%via OSV
CVE-2025-55675Medium
1y ago

Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access

Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access

▾ Sunlitapache-superset · apache-supersetEPSS 0.53%via OSV
CVE-2025-55674Medium
1y ago

Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions

Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions

▾ Sunlitapache-superset · apache-supersetEPSS 0.69%via OSV
CVE-2025-55672Medium
1y ago

Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability

Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 0.74%via OSV
CVE-2025-55673Medium
1y ago

Apache Superset data query improperly discloses database schema information to low-privileged guest user

Apache Superset data query improperly discloses database schema information to low-privileged guest user

▾ Sunlitapache-superset · apache-supersetEPSS 0.57%via OSV
CVE-2025-54791Medium· 5.3
1y ago

OMERO.web displays unecessary user information when requesting password reset

OMERO.web displays unecessary user information when requesting password reset

▾ Sunlitomero-web · omero-webEPSS 0.26%via OSV
CVE-2025-55197Medium
1y ago

PyPDF's Manipulated FlateDecode streams can exhaust RAM

PyPDF's Manipulated FlateDecode streams can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.46%via OSV
CVE-2025-8747High· 8.8
1y ago

Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality

Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality

▾ Twilightkeras · kerasEPSS 0.12%via OSV
CVE-2025-55156High
1y ago

PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter

PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter

▾ Twilightpyload-ng · pyload-ngEPSS 0.33%via OSV
CVE-2025-71325High
1y ago

Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

▾ Twilightpicklescan · picklescanEPSS 0.47%via OSV
CVE-2025-55149Medium
1y ago

TinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)

TinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)

▾ Sunlittiny-scientist · tiny-scientistEPSS 0.65%via OSV
CVE-2025-54952Medium
1y ago

ExecuTorch integer overflow vulnerability leads to code execution

ExecuTorch integer overflow vulnerability leads to code execution

▾ Sunlitexecutorch · executorchEPSS 0.61%via OSV
CVE-2025-54368Medium
1y ago

uv allows ZIP payload obfuscation through parsing differentials

uv allows ZIP payload obfuscation through parsing differentials

▾ Sunlituv · uvEPSS 0.20%via OSV
CVE-2025-54886High· 8.4
1y ago

SKOPS Card.get_model happily allows arbitrary code execution

SKOPS Card.get_model happily allows arbitrary code execution

▾ Twilightskops · skopsEPSS 0.22%via OSV
CVEs tagged “pip” — page 90 · VulnSea