VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2025-5197Medium· 5.3
1y ago

Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability

Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability

▾ Sunlittransformers · transformersEPSS 0.40%via OSV
CVE-2025-54802Critical· 9.8
1y ago

pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)

pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)

▾ Midnightpyload-ng · pyload-ngEPSS 1.2%via OSV
CVE-2025-54796High· 7.5
1y ago

copyparty allows Regex Denial of Service (ReDoS) in the upload listing

copyparty allows Regex Denial of Service (ReDoS) in the upload listing

▾ Twilightcopyparty · copypartyEPSS 0.42%via OSV
GHSA-jxr6-qrxx-2ph2Critical
1y ago

num2words subjected to phishing attack, two versions published containing malware

num2words subjected to phishing attack, two versions published containing malware

▾ Midnightnum2words · num2wordsvia OSV
MAL-2025-6794None
1y ago

Malicious code in num2words (PyPI)

Malicious code in num2words (PyPI)

▾ Sunlitnum2words · num2wordsvia OSV
CVE-2025-48074Medium
1y ago

OpenEXR Out-Of-Memory via Unbounded File Header Values

OpenEXR Out-Of-Memory via Unbounded File Header Values

▾ Sunlitopenexr · openexrEPSS 0.26%via OSV
CVE-2025-53009Medium
1y ago

MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit

MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit

▾ Sunlitmaterialx · materialxEPSS 0.60%via OSV
CVE-2025-48073Medium
1y ago

OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode

OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode

▾ Sunlitopenexr · openexrEPSS 0.20%via OSV
CVE-2025-53012Medium
1y ago

MaterialX Lack of MTLX Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion

MaterialX Lack of MTLX Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion

▾ Sunlitmaterialx · materialxEPSS 0.82%via OSV
CVE-2025-48071High· 7.8
1y ago

OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size

OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size

▾ Twilightopenexr · openexrEPSS 0.31%via OSV
CVE-2025-50460Critical· 9.8PoC
1y ago

MS SWIFT Remote Code Execution via unsafe PyYAML deserialization

MS SWIFT Remote Code Execution via unsafe PyYAML deserialization

▾ Abyssalms-swift · ms-swiftEPSS 2.5%via OSV
CVE-2025-54589Medium· 6.3PoC
1y ago

copyparty Reflected XSS via Filter Parameter

copyparty Reflected XSS via Filter Parameter

▾ Twilightcopyparty · copypartyEPSS 2.4%via OSV
CVE-2025-53011Low
1y ago

MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput

MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput

▾ Sunlitmaterialx · materialxEPSS 0.52%via OSV
CVE-2025-41419Medium
1y ago

MS SWIFT WEB-UI RCE Vulnerability

MS SWIFT WEB-UI RCE Vulnerability

▾ Sunlitms-swift · ms-swiftvia OSV
CVE-2025-48072Medium
1y ago

OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute

OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute

▾ Sunlitopenexr · openexrEPSS 0.49%via OSV
CVE-2025-53010Low
1y ago

MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return

MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return

▾ Sunlitmaterialx · materialxEPSS 0.46%via OSV
CVE-2025-54381Critical· 9.9PoC
1y ago

BentoML SSRF Vulnerability in File Upload Processing

BentoML SSRF Vulnerability in File Upload Processing

▾ Abyssalbentoml · bentomlEPSS 15%via OSV
CVE-2025-54433High
1y ago

Bugsink path traversal via event_id in ingestion

Bugsink path traversal via event_id in ingestion

▾ Twilightbugsink · bugsinkEPSS 0.56%via OSV
CVE-2025-54423Medium· 5.4
1y ago

copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata

copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata

▾ Sunlitcopyparty · copypartyEPSS 0.41%via OSV
CVE-2025-54412High
1y ago

Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution

Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution

▾ Twilightskops · skopsEPSS 0.14%via OSV
CVE-2025-55013Medium· 4.2
1y ago

Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code

Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code

▾ Sunlitassemblyline-service-client · assemblyline-service-clientEPSS 0.58%via OSV
CVE-2025-54413High
1y ago

Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time

Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time

▾ Twilightskops · skopsEPSS 0.14%via OSV
CVE-2025-54379High· 9.8
1y ago

eKuiper API endpoints handling SQL queries with user-controlled table names.

eKuiper API endpoints handling SQL queries with user-controlled table names.

▾ Twilightlf-edge · github.com/lf-edge/ekuiper/v2EPSS 0.77%via OSV
CVE-2025-7404MediumPoC
1y ago

Calibre Web and Autocaliweb have OS Command Injection vulnerability

Calibre Web and Autocaliweb have OS Command Injection vulnerability

▾ Twilightcalibreweb · calibrewebEPSS 2.8%via OSV
CVE-2025-6998HighPoC
1y ago

Calibre Web and Autocaliweb have a ReDoS vulnerability

Calibre Web and Autocaliweb have a ReDoS vulnerability

▾ Midnightcalibreweb · calibrewebEPSS 0.84%via OSV
CVE-2025-54365High
1y ago

FastAPI Guard has a regex bypass

FastAPI Guard has a regex bypass

▾ Twilightfastapi-guard · fastapi-guardEPSS 0.76%via OSV
CVE-2025-51481Medium· 6.6
1y ago

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read a…

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookD…

▾ Sunlitdagster-ge · dagster-geEPSS 0.55%via OSV
CVE-2025-51464Medium
1y ago

Aim vulnerable to Cross-site Scripting

Aim vulnerable to Cross-site Scripting

▾ Sunlitaim · aimEPSS 0.61%via OSV
CVE-2025-54140High· 7.5
1y ago

`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write

`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write

▾ Twilightpyload-ng · pyload-ngEPSS 0.65%via OSV
CVE-2025-54121Medium· 5.3
1y ago

Starlette has possible denial-of-service vector when parsing large files in multipart forms

Starlette has possible denial-of-service vector when parsing large files in multipart forms

▾ Sunlitstarlette · starletteEPSS 0.58%via OSV
CVEs tagged “pip” — page 91 · VulnSea