Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2025-5197Medium· 5.3Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2025-54802Critical· 9.8pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
CVE-2025-54796High· 7.5copyparty allows Regex Denial of Service (ReDoS) in the upload listing
copyparty allows Regex Denial of Service (ReDoS) in the upload listing
GHSA-jxr6-qrxx-2ph2Criticalnum2words subjected to phishing attack, two versions published containing malware
num2words subjected to phishing attack, two versions published containing malware
MAL-2025-6794NoneMalicious code in num2words (PyPI)
Malicious code in num2words (PyPI)
CVE-2025-48074MediumOpenEXR Out-Of-Memory via Unbounded File Header Values
OpenEXR Out-Of-Memory via Unbounded File Header Values
CVE-2025-53009MediumMaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit
MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit
CVE-2025-48073MediumOpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode
OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode
CVE-2025-53012MediumMaterialX Lack of MTLX Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion
MaterialX Lack of MTLX Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion
CVE-2025-48071High· 7.8OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size
OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size
CVE-2025-50460Critical· 9.8PoCMS SWIFT Remote Code Execution via unsafe PyYAML deserialization
MS SWIFT Remote Code Execution via unsafe PyYAML deserialization
CVE-2025-54589Medium· 6.3PoCcopyparty Reflected XSS via Filter Parameter
copyparty Reflected XSS via Filter Parameter
CVE-2025-53011LowMaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput
MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput
CVE-2025-41419MediumMS SWIFT WEB-UI RCE Vulnerability
MS SWIFT WEB-UI RCE Vulnerability
CVE-2025-48072MediumOpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute
OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute
CVE-2025-53010LowMaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return
MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return
CVE-2025-54381Critical· 9.9PoCBentoML SSRF Vulnerability in File Upload Processing
BentoML SSRF Vulnerability in File Upload Processing
CVE-2025-54433HighBugsink path traversal via event_id in ingestion
Bugsink path traversal via event_id in ingestion
CVE-2025-54423Medium· 5.4copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata
copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata
CVE-2025-54412HighSkops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
CVE-2025-55013Medium· 4.2Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code
Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code
CVE-2025-54413HighSkops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
CVE-2025-54379High· 9.8eKuiper API endpoints handling SQL queries with user-controlled table names.
eKuiper API endpoints handling SQL queries with user-controlled table names.
CVE-2025-7404MediumPoCCalibre Web and Autocaliweb have OS Command Injection vulnerability
Calibre Web and Autocaliweb have OS Command Injection vulnerability
CVE-2025-6998HighPoCCalibre Web and Autocaliweb have a ReDoS vulnerability
Calibre Web and Autocaliweb have a ReDoS vulnerability
CVE-2025-54365HighFastAPI Guard has a regex bypass
FastAPI Guard has a regex bypass
CVE-2025-51481Medium· 6.6Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read a…
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookD…
CVE-2025-51464MediumAim vulnerable to Cross-site Scripting
Aim vulnerable to Cross-site Scripting
CVE-2025-54140High· 7.5`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
CVE-2025-54121Medium· 5.3Starlette has possible denial-of-service vector when parsing large files in multipart forms
Starlette has possible denial-of-service vector when parsing large files in multipart forms