Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2025-6518Medium· 6.3pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode function
pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode function
CVE-2025-50181Medium· 5.3urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation (CVE-2025-50181)
A flaw was found in urllib3. The `PoolManager` class allows redirects to be disabled by configuring retries in a specific manner, effectively bypassing intended HTTP redirection behavior. A network attacker can leverage this configuration …
CVE-2025-50182Medium· 5.3urllib3: urllib3 does not control redirects in browsers and Node.js (CVE-2025-50182)
A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can en…
CVE-2025-6050Medium· 4.8Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnera…
Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the "displayable_links_js" function, which fails to properly sanitize blog post tit…
CVE-2025-48945Mediumpycares has a Use-After-Free Vulnerability
pycares has a Use-After-Free Vulnerability
CVE-2025-4565Highprotobuf-python has a potential Denial of Service issue
protobuf-python has a potential Denial of Service issue
CVE-2025-47951Medium· 4.9Weblate lacks rate limiting when verifying second factor
Weblate lacks rate limiting when verifying second factor
CVE-2025-49134Medium· 5.3Weblate exposes personal IP address via e-mail
Weblate exposes personal IP address via e-mail
CVE-2025-28388Critical· 9.8OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
CVE-2025-28384Critical· 9.1An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
CVE-2025-28382High· 7.5An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
CVE-2025-28381High· 7.5A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all co…
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.
CVE-2025-28380Medium· 6.1A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via i…
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter.
CVE-2025-22240Medium· 6.3Salt allows arbitrary directory creation or file deletion
Salt allows arbitrary directory creation or file deletion
CVE-2025-22238Medium· 4.2Salt vulnerable to directory traversal attack in minion file cache creation
Salt vulnerable to directory traversal attack in minion file cache creation
CVE-2025-22236High· 8.1Salt has minion event bus authorization bypass vulnerability
Salt has minion event bus authorization bypass vulnerability
CVE-2025-22237Medium· 6.7Salt's on demand pillar functionality vulnerable to arbitrary command injections
Salt's on demand pillar functionality vulnerable to arbitrary command injections
CVE-2025-22239High· 8.1Salt vulnerable to arbitrary event injection
Salt vulnerable to arbitrary event injection
CVE-2025-22242Medium· 5.6Salt's worker process vulnerable to denial of service through file read operation
Salt's worker process vulnerable to denial of service through file read operation
CVE-2025-22241Medium· 5.6Salt's file contents overwrite the VirtKey class
Salt's file contents overwrite the VirtKey class
CVE-2024-38825Medium· 6.4Salt's salt.auth.pki module does not properly authenticate callers
Salt's salt.auth.pki module does not properly authenticate callers
CVE-2025-49143MediumNautobot may allows uploaded media files to be accessible without authentication
Nautobot may allows uploaded media files to be accessible without authentication
CVE-2025-48067Medium· 5.4OctoPrint vulnerable to possible file extraction via upload endpoints
OctoPrint vulnerable to possible file extraction via upload endpoints
CVE-2025-48879Medium· 6.5OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint
OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint
CVE-2025-49653High· 8.0BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-49651High· 8.1Backend.AI Missing Authorization vulnerability
Backend.AI Missing Authorization vulnerability
CVE-2024-47081Medium· 5.3Requests vulnerable to .netrc credentials leak via malicious URLs
Requests vulnerable to .netrc credentials leak via malicious URLs
CVE-2025-49619High· 8.5PoCSkyvern has a Jinja runtime leak
Skyvern has a Jinja runtime leak
CVE-2025-48432Medium· 4.0Django Improper Output Neutralization for Logs vulnerability
Django Improper Output Neutralization for Logs vulnerability
CVE-2025-1793Critical· 9.8llama_index vulnerable to SQL Injection
llama_index vulnerable to SQL Injection