Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2025-48995MediumSignXML's signature verification with HMAC is vulnerable to a timing attack
SignXML's signature verification with HMAC is vulnerable to a timing attack
CVE-2025-48994MediumSignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
CVE-2025-48957High· 7.5AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
CVE-2025-30167High· 7.3Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
CVE-2025-1750Critical· 9.8An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnera…
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write ar…
CVE-2025-48912HighApache Superset: Improper authorization bypass on row level security via SQL Injection
Apache Superset: Improper authorization bypass on row level security via SQL Injection
CVE-2025-5320Low· 3.7Gradio CORS Origin Validation Bypass Vulnerability
Gradio CORS Origin Validation Bypass Vulnerability
CVE-2025-5321Medium· 6.3Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution
Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution
CVE-2025-48887Medium· 6.5vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
CVE-2025-46722Medium· 4.2vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
CVE-2025-48943Medium· 6.5vLLM allows clients to crash the openai server with invalid regex
vLLM allows clients to crash the openai server with invalid regex
CVE-2025-48942Medium· 6.5vLLM DOS: Remotely kill vllm over http with invalid JSON schema
vLLM DOS: Remotely kill vllm over http with invalid JSON schema
CVE-2025-46570Low· 2.6Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching
CVE-2025-48944Medium· 6.5vLLM Tool Schema allows DoS via Malformed pattern and type Fields
vLLM Tool Schema allows DoS via Malformed pattern and type Fields
CVE-2025-5279High· 7.5Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
CVE-2025-71379Medium· 4.3vLLM vulnerable to Regular Expression Denial of Service
vLLM vulnerable to Regular Expression Denial of Service
CVE-2025-1753High· 7.8LLama-Index CLI OS command injection vulnerability
LLama-Index CLI OS command injection vulnerability
CVE-2025-48383High· 8.2Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
CVE-2025-5173Medium· 5.3HumanSignal label-studio-ml-backend Deserialization of Untrusted Data vulnerability
HumanSignal label-studio-ml-backend Deserialization of Untrusted Data vulnerability
CVE-2025-5148Medium· 5.3FunAudioLLM InspireMusic deserialization vulnerability
FunAudioLLM InspireMusic deserialization vulnerability
CVE-2025-5150Medium· 6.3docarray prototype pollution
docarray prototype pollution
CVE-2025-47277Critical· 9.8vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
CVE-2025-46724Critical· 9.8Langroid has a Code Injection vulnerability in TableChatAgent
Langroid has a Code Injection vulnerability in TableChatAgent
CVE-2025-46725HighLangroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
CVE-2025-47273HighPoCsetuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
CVE-2025-47285LowVyper's `concat()` builtin may elide side-effects for zero-length arguments
Vyper's `concat()` builtin may elide side-effects for zero-length arguments
CVE-2025-32962Medium· 4.3Flask-AppBuilder open redirect vulnerability using HTTP host injection
Flask-AppBuilder open redirect vulnerability using HTTP host injection
CVE-2025-47287High· 7.5Tornado vulnerable to excessive logging caused by malformed multipart form data
Tornado vulnerable to excessive logging caused by malformed multipart form data
CVE-2025-47774LowVyper's `slice()` may elide side-effects when output length is 0
Vyper's `slice()` may elide side-effects when output length is 0
CVE-2025-47782HighmotionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution