Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2025-27696High· 8.8Apache Superset Allows Ownership Takeover
Apache Superset Allows Ownership Takeover
CVE-2025-47278LowFlask uses fallback key instead of current signing key
Flask uses fallback key instead of current signing key
CVE-2025-1752High· 7.5LlamaIndex Vulnerable to Denial of Service (DoS)
LlamaIndex Vulnerable to Denial of Service (DoS)
CVE-2025-32873Medium· 5.3PoCDjango has a denial-of-service possibility in strip_tags()
Django has a denial-of-service possibility in strip_tags()
CVE-2025-46814High· 7.5FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. A…
FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. An HTTP header injection vulnerability has been identified in versions prior to 2.0.0. By manipulatin…
CVE-2025-30165High· 8.0Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
CVE-2025-46726HighLangroid Allows XXE Injection via XMLToolMessage
Langroid Allows XXE Injection via XMLToolMessage
CVE-2025-46335MediumMobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
CVE-2025-46730Medium· 6.8Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
CVE-2025-32444Critical· 10.0vLLM Vulnerable to Remote Code Execution via Mooncake Integration
vLLM Vulnerable to Remote Code Execution via Mooncake Integration
CVE-2025-46560Medium· 6.5phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
CVE-2025-1194Medium· 4.3Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2025-30202High· 7.5Data exposure via ZeroMQ on multi-node vLLM deployment
Data exposure via ZeroMQ on multi-node vLLM deployment
CVE-2025-4032Medium· 5.0AWorld OS Command Injection vulnerability
AWorld OS Command Injection vulnerability
CVE-2025-46656Low· 2.9markdownify allows large headline prefixes such as <h9999999>, which causes memory consumption
markdownify allows large headline prefixes such as <h9999999>, which causes memory consumption
CVE-2025-43859Critical· 9.1h11 accepts some malformed Chunked-Encoding bodies
h11 accepts some malformed Chunked-Encoding bodies
GHSA-ggpf-24jw-3fcwCritical· 9.8CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
CVE-2025-46567Medium· 6.1LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py
LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py
CVE-2025-32434CriticalPoCPyTorch: `torch.load` with `weights_only=True` leads to remote code execution
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
CVE-2025-28197MediumCrawl4AI SSRF vulnerability
Crawl4AI SSRF vulnerability
CVE-2025-32377Medium· 6.5Rasa Pro Missing Authentication For Voice Connector APIs
Rasa Pro Missing Authentication For Voice Connector APIs
CVE-2025-3730Low· 3.3PyTorch Improper Resource Shutdown or Release vulnerability
PyTorch Improper Resource Shutdown or Release vulnerability
CVE-2024-53305HighWhoogle allows attackers to execute arbitrary code via supplying a crafted search query
Whoogle allows attackers to execute arbitrary code via supplying a crafted search query
CVE-2025-32381Medium· 6.5xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory
xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory
CVE-2025-71351MediumPicklescan missing detection when calling built-in python library function timeit.timeit()
Picklescan missing detection when calling built-in python library function timeit.timeit()
CVE-2025-71355MediumPicklescan failed to detect to some unsafe global function in Numpy library
Picklescan failed to detect to some unsafe global function in Numpy library
CVE-2025-46417HighPicklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
CVE-2025-30473High· 8.8Apache Airflow Common SQL Provider Vulnerable to SQL Injection
Apache Airflow Common SQL Provider Vulnerable to SQL Injection
CVE-2025-27520Critical· 9.8PoCBentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
CVE-2025-30370High· 7.4jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"
jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"