VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2025-6518Medium· 6.3
1y ago

pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode function

pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode function

▾ Sunlitpyspur · pyspurEPSS 0.39%via OSV
CVE-2025-50181Medium· 5.3
1y ago

urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation (CVE-2025-50181)

A flaw was found in urllib3. The `PoolManager` class allows redirects to be disabled by configuring retries in a specific manner, effectively bypassing intended HTTP redirection behavior. A network attacker can leverage this configuration …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.47%via CSAF
CVE-2025-50182Medium· 5.3
1y ago

urllib3: urllib3 does not control redirects in browsers and Node.js (CVE-2025-50182)

A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can en…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.39%via CSAF
CVE-2025-6050Medium· 4.8
1y ago

Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnera…

Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the "displayable_links_js" function, which fails to properly sanitize blog post tit…

▾ Sunlitmezzanine · mezzanineEPSS 0.32%via OSV
CVE-2025-48945Medium
1y ago

pycares has a Use-After-Free Vulnerability

pycares has a Use-After-Free Vulnerability

▾ Sunlitpycares · pycaresEPSS 0.48%via OSV
CVE-2025-4565High
1y ago

protobuf-python has a potential Denial of Service issue

protobuf-python has a potential Denial of Service issue

▾ Twilightprotobuf · protobufEPSS 0.26%via OSV
CVE-2025-47951Medium· 4.9
1y ago

Weblate lacks rate limiting when verifying second factor

Weblate lacks rate limiting when verifying second factor

▾ Sunlitweblate · weblateEPSS 0.27%via OSV
CVE-2025-49134Medium· 5.3
1y ago

Weblate exposes personal IP address via e-mail

Weblate exposes personal IP address via e-mail

▾ Sunlitweblate · weblateEPSS 0.32%via OSV
CVE-2025-28388Critical· 9.8
1y ago

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

▾ Midnightopenc3 · openc3EPSS 0.61%via OSV
CVE-2025-28384Critical· 9.1
1y ago

An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

▾ Midnightopenc3 · openc3EPSS 0.89%via OSV
CVE-2025-28382High· 7.5
1y ago

An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

▾ Twilightopenc3 · openc3EPSS 0.89%via OSV
CVE-2025-28381High· 7.5
1y ago

A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all co…

A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.

▾ Twilightopenc3 · openc3EPSS 0.52%via OSV
CVE-2025-28380Medium· 6.1
1y ago

A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via i…

A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter.

▾ Sunlitopenc3 · openc3EPSS 0.34%via OSV
CVE-2025-22240Medium· 6.3
1y ago

Salt allows arbitrary directory creation or file deletion

Salt allows arbitrary directory creation or file deletion

▾ Sunlitsalt · saltEPSS 0.16%via OSV
CVE-2025-22238Medium· 4.2
1y ago

Salt vulnerable to directory traversal attack in minion file cache creation

Salt vulnerable to directory traversal attack in minion file cache creation

▾ Sunlitsalt · saltEPSS 0.29%via OSV
CVE-2025-22236High· 8.1
1y ago

Salt has minion event bus authorization bypass vulnerability

Salt has minion event bus authorization bypass vulnerability

▾ Twilightsalt · saltEPSS 0.17%via OSV
CVE-2025-22237Medium· 6.7
1y ago

Salt's on demand pillar functionality vulnerable to arbitrary command injections

Salt's on demand pillar functionality vulnerable to arbitrary command injections

▾ Sunlitsalt · saltEPSS 0.18%via OSV
CVE-2025-22239High· 8.1
1y ago

Salt vulnerable to arbitrary event injection

Salt vulnerable to arbitrary event injection

▾ Twilightsalt · saltEPSS 0.18%via OSV
CVE-2025-22242Medium· 5.6
1y ago

Salt's worker process vulnerable to denial of service through file read operation

Salt's worker process vulnerable to denial of service through file read operation

▾ Sunlitsalt · saltEPSS 0.14%via OSV
CVE-2025-22241Medium· 5.6
1y ago

Salt's file contents overwrite the VirtKey class

Salt's file contents overwrite the VirtKey class

▾ Sunlitsalt · saltEPSS 0.18%via OSV
CVE-2024-38825Medium· 6.4
1y ago

Salt's salt.auth.pki module does not properly authenticate callers

Salt's salt.auth.pki module does not properly authenticate callers

▾ Sunlitsalt · saltEPSS 0.15%via OSV
CVE-2025-49143Medium
1y ago

Nautobot may allows uploaded media files to be accessible without authentication

Nautobot may allows uploaded media files to be accessible without authentication

▾ Sunlitnautobot · nautobotEPSS 0.44%via OSV
CVE-2025-48067Medium· 5.4
1y ago

OctoPrint vulnerable to possible file extraction via upload endpoints

OctoPrint vulnerable to possible file extraction via upload endpoints

▾ Sunlitoctoprint · octoprintEPSS 0.29%via OSV
CVE-2025-48879Medium· 6.5
1y ago

OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint

OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint

▾ Sunlitoctoprint · octoprintEPSS 0.26%via OSV
CVE-2025-49653High· 8.0
1y ago

BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

▾ Twilightbackend-ai · backend-aiEPSS 0.35%via OSV
CVE-2025-49651High· 8.1
1y ago

Backend.AI Missing Authorization vulnerability

Backend.AI Missing Authorization vulnerability

▾ Twilightbackend-ai · backend-aiEPSS 0.34%via OSV
CVE-2024-47081Medium· 5.3
1y ago

Requests vulnerable to .netrc credentials leak via malicious URLs

Requests vulnerable to .netrc credentials leak via malicious URLs

▾ Sunlitrequests · requestsEPSS 0.98%via OSV
CVE-2025-49619High· 8.5PoC
1y ago

Skyvern has a Jinja runtime leak

Skyvern has a Jinja runtime leak

▾ Midnightskyvern · skyvernEPSS 20%via OSV
CVE-2025-48432Medium· 4.0
1y ago

Django Improper Output Neutralization for Logs vulnerability

Django Improper Output Neutralization for Logs vulnerability

▾ Sunlitdjango · djangoEPSS 0.75%via OSV
CVE-2025-1793Critical· 9.8
1y ago

llama_index vulnerable to SQL Injection

llama_index vulnerable to SQL Injection

▾ Midnightllama-index · llama-indexEPSS 0.66%via OSV
CVEs tagged “pip” — page 93 · VulnSea