Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2025-71358MediumPicklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity
CVE-2025-71341High· 8.1Picklescan has a missing detection when calling built-in python profile.Profile.runctx
Picklescan has a missing detection when calling built-in python profile.Profile.runctx
CVE-2025-71349MediumPicklescan has a missing detection when calling built-in python trace.Trace.run
Picklescan has a missing detection when calling built-in python trace.Trace.run
CVE-2025-71363MediumPicklescan is missing detection when calling built-in python cProfile.run
Picklescan is missing detection when calling built-in python cProfile.run
CVE-2025-71354MediumPicklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem
Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem
CVE-2025-71340MediumPicklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode
Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode
GHSA-63cx-g855-hvv4Mediummitmproxy binaries embed a vulnerable python-hyper/h2 dependency
mitmproxy binaries embed a vulnerable python-hyper/h2 dependency
CVE-2025-57804Mediumh2 allows HTTP Request Smuggling due to illegal characters in headers
h2 allows HTTP Request Smuggling due to illegal characters in headers
CVE-2025-57809High· 7.5xgrammar: XGrammar affected by Denial of Service by infinite recursion grammars (CVE-2025-57809)
A flaw was found in xgrammar. Recursive grammar definitions could trigger infinite recursion during parsing in GrammarMatcherBase::ExpandEquivalentStackElements, leading to unbounded stack growth and a segmentation fault. This vulnerabilit…
CVE-2025-57760High· 8.8Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
CVE-2025-71348High· 8.1Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config
Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config
CVE-2025-71370High· 8.1Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
CVE-2025-71350MediumPicklescan missing detection when calling pytorch function torch.utils.collect_env.run
Picklescan missing detection when calling pytorch function torch.utils.collect_env.run
CVE-2025-57751HighDenial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
CVE-2025-9141High· 8.8vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
CVE-2025-55214MediumCopier's safe template has filesystem write access outside destination path
Copier's safe template has filesystem write access outside destination path
CVE-2025-55201HighCopier's safe template has arbitrary filesystem read/write access
Copier's safe template has arbitrary filesystem read/write access
CVE-2025-55675MediumApache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
CVE-2025-55674MediumApache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
CVE-2025-55672MediumApache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
CVE-2025-55673MediumApache Superset data query improperly discloses database schema information to low-privileged guest user
Apache Superset data query improperly discloses database schema information to low-privileged guest user
CVE-2025-54791Medium· 5.3OMERO.web displays unecessary user information when requesting password reset
OMERO.web displays unecessary user information when requesting password reset
CVE-2025-55197MediumPyPDF's Manipulated FlateDecode streams can exhaust RAM
PyPDF's Manipulated FlateDecode streams can exhaust RAM
CVE-2025-8747High· 8.8Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-55156HighPyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
CVE-2025-71325HighPicklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
CVE-2025-55149MediumTinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)
TinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)
CVE-2025-54952MediumExecuTorch integer overflow vulnerability leads to code execution
ExecuTorch integer overflow vulnerability leads to code execution
CVE-2025-54368Mediumuv allows ZIP payload obfuscation through parsing differentials
uv allows ZIP payload obfuscation through parsing differentials
CVE-2025-54886High· 8.4SKOPS Card.get_model happily allows arbitrary code execution
SKOPS Card.get_model happily allows arbitrary code execution