VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2025-53890Critical· 9.8
1y ago

pyLoad vulnerable to XSS through insecure CAPTCHA

pyLoad vulnerable to XSS through insecure CAPTCHA

▾ Midnightpyload-ng · pyload-ngEPSS 1.2%via OSV
CVE-2025-29606Medium· 4.3
1y ago

py-libp2p is vulnerable to DoS attacks through use of large RSA keys

py-libp2p is vulnerable to DoS attacks through use of large RSA keys

▾ Sunlitlibp2p · libp2pEPSS 0.33%via OSV
CVE-2025-53640MediumPoC
1y ago

Indico vulnerability allows attackers to bulk dump user details

Indico vulnerability allows attackers to bulk dump user details

▾ Twilightindico · indicoEPSS 0.60%via OSV
CVE-2025-53643Low
1y ago

AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections

AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections

▾ Sunlitaiohttp · aiohttpEPSS 0.31%via OSV
CVE-2025-30402High· 8.1
1y ago

ExecuTorch vulnerable to Heap-based Buffer Overflow attack

ExecuTorch vulnerable to Heap-based Buffer Overflow attack

▾ Twilightexecutorch · executorchEPSS 0.36%via OSV
CVE-2025-3933Medium· 5.3
1y ago

Transformers is vulnerable to ReDoS attack through its DonutProcessor class

Transformers is vulnerable to ReDoS attack through its DonutProcessor class

▾ Sunlittransformers · transformersEPSS 0.43%via OSV
CVE-2025-6211Medium· 6.5
1y ago

LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class

LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class

▾ Sunlitllama-index · llama-indexEPSS 0.32%via OSV
CVE-2025-7346High· 7.5
1y ago

pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages

pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages

▾ Twilightpyload-ng · pyload-ngEPSS 0.32%via OSV
CVE-2025-3225High· 7.5
1y ago

LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser

LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser

▾ Twilightllama-index-readers-papers · llama-index-readers-papersEPSS 0.45%via OSV
CVE-2023-51232High· 7.5
1y ago

Dagster vulnerable to Path Traversal attack through its /logs endpoint

Dagster vulnerable to Path Traversal attack through its /logs endpoint

▾ Twilightdagster · dagsterEPSS 0.94%via OSV
CVE-2025-3263Medium· 5.3
1y ago

Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking

Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking

▾ Sunlittransformers · transformersEPSS 0.46%via OSV
CVE-2025-3777Low· 3.5
1y ago

Transformers's Improper Input Validation vulnerability can be exploited through username injection

Transformers's Improper Input Validation vulnerability can be exploited through username injection

▾ Sunlittransformers · transformersEPSS 0.38%via OSV
CVE-2025-3044Medium· 5.3
1y ago

LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions

LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions

▾ Sunlitllama-index-readers-papers · llama-index-readers-papersEPSS 0.30%via OSV
CVE-2025-3108Medium· 5.0
1y ago

LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component

LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component

▾ Sunlitllama-index-core · llama-index-coreEPSS 0.47%via OSV
CVE-2025-3264Medium· 5.3
1y ago

Transformers vulnerable to ReDoS attack through its get_imports() function

Transformers vulnerable to ReDoS attack through its get_imports() function

▾ Sunlittransformers · transformersEPSS 0.46%via OSV
CVE-2025-6386High· 7.5
1y ago

Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function

Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function

▾ Twilightlollms · lollmsEPSS 0.39%via OSV
CVE-2025-53539Medium
1y ago

fastapi-guard is vulnerable to ReDoS through inefficient regex

fastapi-guard is vulnerable to ReDoS through inefficient regex

▾ Sunlitfastapi-guard · fastapi-guardEPSS 0.45%via OSV
CVE-2025-3046High· 7.5
1y ago

LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class

LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class

▾ Twilightllama-index-readers-obsidian · llama-index-readers-obsidianEPSS 0.59%via OSV
CVE-2025-3262Medium· 5.3
1y ago

Transformers vulnerable to ReDoS attack through its SETTING_RE variable

Transformers vulnerable to ReDoS attack through its SETTING_RE variable

▾ Sunlittransformers · transformersEPSS 0.46%via OSV
CVE-2025-5472Medium· 6.5
1y ago

LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing

LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing

▾ Sunlitllama-index-core · llama-index-coreEPSS 0.36%via OSV
CVE-2025-6210Medium· 6.2
1y ago

LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit

LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit

▾ Sunlitllama-index-readers-obsidian · llama-index-readers-obsidianEPSS 0.31%via OSV
CVE-2025-6209High· 7.5
1y ago

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

▾ Twilightllama-index-core · llama-index-coreEPSS 0.58%via OSV
CVE-2025-53365High
1y ago

MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service

MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service

▾ Twilightmcp · mcpEPSS 0.39%via OSV
CVE-2025-53366High
1y ago

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

▾ Twilightmcp · mcpEPSS 7.7%via OSV
CVE-2025-6853Medium· 6.3
1y ago

Langchain-Chatchat has a Path Traversal vulnerability

Langchain-Chatchat has a Path Traversal vulnerability

▾ Sunlitlangchain-chatchat · langchain-chatchatEPSS 0.55%via OSV
CVE-2025-6855Medium· 5.5
1y ago

Langchain-Chatchat vulnerable to path traversal

Langchain-Chatchat vulnerable to path traversal

▾ Sunlitlangchain-chatchat · langchain-chatchatEPSS 0.62%via OSV
CVE-2025-6854Medium· 4.3
1y ago

Langchain-Chatchat vulnerable to path traversal

Langchain-Chatchat vulnerable to path traversal

▾ Sunlitlangchain-chatchat · langchain-chatchatEPSS 0.54%via OSV
CVE-2025-53002High· 8.3
1y ago

LLaMA-Factory allows Code Injection through improper vhead_file safeguards

LLaMA-Factory allows Code Injection through improper vhead_file safeguards

▾ Twilightllamafactory · llamafactoryEPSS 1.2%via OSV
CVE-2025-6773Medium· 5.3
1y ago

HKUDS LightRAG allows Path Traversal via function upload_to_input_dir

HKUDS LightRAG allows Path Traversal via function upload_to_input_dir

▾ Sunlitlightrag-hku · lightrag-hkuEPSS 0.19%via OSV
CVE-2025-52558High
1y ago

ChangeDetection.io XSS in watch overview

ChangeDetection.io XSS in watch overview

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.59%via OSV
CVEs tagged “pip” — page 92 · VulnSea