VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2025-48995Medium
1y ago

SignXML's signature verification with HMAC is vulnerable to a timing attack

SignXML's signature verification with HMAC is vulnerable to a timing attack

▾ Sunlitsignxml · signxmlEPSS 0.23%via OSV
CVE-2025-48994Medium
1y ago

SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack

SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack

▾ Sunlitsignxml · signxmlEPSS 0.22%via OSV
CVE-2025-48957High· 7.5
1y ago

AstrBot Has Path Traversal Vulnerability in /api/chat/get_file

AstrBot Has Path Traversal Vulnerability in /api/chat/get_file

▾ Twilightastrbot · astrbotEPSS 0.74%via OSV
CVE-2025-30167High· 7.3
1y ago

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

▾ Twilightjupyter-core · jupyter-coreEPSS 0.19%via OSV
CVE-2025-1750Critical· 9.8
1y ago

An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnera…

An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write ar…

▾ Midnightllama-index · llama-indexEPSS 0.82%via OSV
CVE-2025-48912High
1y ago

Apache Superset: Improper authorization bypass on row level security via SQL Injection

Apache Superset: Improper authorization bypass on row level security via SQL Injection

▾ Twilightapache-superset · apache-supersetEPSS 0.72%via OSV
CVE-2025-5320Low· 3.7
1y ago

Gradio CORS Origin Validation Bypass Vulnerability

Gradio CORS Origin Validation Bypass Vulnerability

▾ Sunlitgradio · gradioEPSS 0.26%via OSV
CVE-2025-5321Medium· 6.3
1y ago

Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution

Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution

▾ Sunlitaim · aimEPSS 0.59%via OSV
CVE-2025-48887Medium· 6.5
1y ago

vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`

vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`

▾ Sunlitvllm · vllmEPSS 0.51%via OSV
CVE-2025-46722Medium· 4.2
1y ago

vLLM has a Weakness in MultiModalHasher Image Hashing Implementation

vLLM has a Weakness in MultiModalHasher Image Hashing Implementation

▾ Sunlitvllm · vllmEPSS 0.32%via OSV
CVE-2025-48943Medium· 6.5
1y ago

vLLM allows clients to crash the openai server with invalid regex

vLLM allows clients to crash the openai server with invalid regex

▾ Sunlitvllm · vllmEPSS 0.47%via OSV
CVE-2025-48942Medium· 6.5
1y ago

vLLM DOS: Remotely kill vllm over http with invalid JSON schema

vLLM DOS: Remotely kill vllm over http with invalid JSON schema

▾ Sunlitvllm · vllmEPSS 0.54%via OSV
CVE-2025-46570Low· 2.6
1y ago

Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching

Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching

▾ Sunlitvllm · vllmEPSS 0.29%via OSV
CVE-2025-48944Medium· 6.5
1y ago

vLLM Tool Schema allows DoS via Malformed pattern and type Fields

vLLM Tool Schema allows DoS via Malformed pattern and type Fields

▾ Sunlitvllm · vllmEPSS 0.52%via OSV
CVE-2025-5279High· 7.5
1y ago

Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin

Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin

▾ Twilightredshift-connector · redshift-connectorEPSS 0.30%via OSV
CVE-2025-71379Medium· 4.3
1y ago

vLLM vulnerable to Regular Expression Denial of Service

vLLM vulnerable to Regular Expression Denial of Service

▾ Sunlitvllm · vllmEPSS 0.48%via OSV
CVE-2025-1753High· 7.8
1y ago

LLama-Index CLI OS command injection vulnerability

LLama-Index CLI OS command injection vulnerability

▾ Twilightllama-index-cli · llama-index-cliEPSS 1.1%via OSV
CVE-2025-48383High· 8.2
1y ago

Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking

Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking

▾ Twilightdjango-select2 · django-select2EPSS 0.31%via OSV
CVE-2025-5173Medium· 5.3
1y ago

HumanSignal label-studio-ml-backend Deserialization of Untrusted Data vulnerability

HumanSignal label-studio-ml-backend Deserialization of Untrusted Data vulnerability

▾ Sunlitlabel-studio-ml · label-studio-mlEPSS 0.22%via OSV
CVE-2025-5148Medium· 5.3
1y ago

FunAudioLLM InspireMusic deserialization vulnerability

FunAudioLLM InspireMusic deserialization vulnerability

▾ Sunlitinspiremusic · inspiremusicEPSS 0.19%via OSV
CVE-2025-5150Medium· 6.3
1y ago

docarray prototype pollution

docarray prototype pollution

▾ Sunlitdocarray · docarrayEPSS 0.67%via OSV
CVE-2025-47277Critical· 9.8
1y ago

vLLM Allows Remote Code Execution via PyNcclPipe Communication Service

vLLM Allows Remote Code Execution via PyNcclPipe Communication Service

▾ Midnightvllm · vllmEPSS 0.96%via OSV
CVE-2025-46724Critical· 9.8
1y ago

Langroid has a Code Injection vulnerability in TableChatAgent

Langroid has a Code Injection vulnerability in TableChatAgent

▾ Midnightlangroid · langroidEPSS 0.83%via OSV
CVE-2025-46725High
1y ago

Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store

Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store

▾ Twilightlangroid · langroidEPSS 0.53%via OSV
CVE-2025-47273HighPoC
1y ago

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

▾ Midnightsetuptools · setuptoolsEPSS 1.5%via OSV
CVE-2025-47285Low
1y ago

Vyper's `concat()` builtin may elide side-effects for zero-length arguments

Vyper's `concat()` builtin may elide side-effects for zero-length arguments

▾ Sunlitvyper · vyperEPSS 0.45%via OSV
CVE-2025-32962Medium· 4.3
1y ago

Flask-AppBuilder open redirect vulnerability using HTTP host injection

Flask-AppBuilder open redirect vulnerability using HTTP host injection

▾ Sunlitflask-appbuilder · flask-appbuilderEPSS 0.22%via OSV
CVE-2025-47287High· 7.5
1y ago

Tornado vulnerable to excessive logging caused by malformed multipart form data

Tornado vulnerable to excessive logging caused by malformed multipart form data

▾ Twilighttornado · tornadoEPSS 0.74%via OSV
CVE-2025-47774Low
1y ago

Vyper's `slice()` may elide side-effects when output length is 0

Vyper's `slice()` may elide side-effects when output length is 0

▾ Sunlitvyper · vyperEPSS 0.46%via OSV
CVE-2025-47782High
1y ago

motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution

motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution

▾ Twilightmotioneye · motioneyeEPSS 0.49%via OSV
CVEs tagged “pip” — page 94 · VulnSea