VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2025-27696High· 8.8
1y ago

Apache Superset Allows Ownership Takeover

Apache Superset Allows Ownership Takeover

▾ Twilightapache-superset · apache-supersetEPSS 1.2%via OSV
CVE-2025-47278Low
1y ago

Flask uses fallback key instead of current signing key

Flask uses fallback key instead of current signing key

▾ Sunlitflask · flaskEPSS 0.18%via OSV
CVE-2025-1752High· 7.5
1y ago

LlamaIndex Vulnerable to Denial of Service (DoS)

LlamaIndex Vulnerable to Denial of Service (DoS)

▾ Twilightllama-index · llama-indexEPSS 0.50%via OSV
CVE-2025-32873Medium· 5.3PoC
1y ago

Django has a denial-of-service possibility in strip_tags()

Django has a denial-of-service possibility in strip_tags()

▾ Twilightdjango · djangoEPSS 14%via OSV
CVE-2025-46814High· 7.5
1y ago

FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. A…

FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. An HTTP header injection vulnerability has been identified in versions prior to 2.0.0. By manipulatin…

▾ Twilightfastapi-guard · fastapi-guardEPSS 0.32%via OSV
CVE-2025-30165High· 8.0
1y ago

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

▾ Twilightvllm · vllmEPSS 0.48%via OSV
CVE-2025-46726High
1y ago

Langroid Allows XXE Injection via XMLToolMessage

Langroid Allows XXE Injection via XMLToolMessage

▾ Twilightlangroid · langroidEPSS 0.62%via OSV
CVE-2025-46335Medium
1y ago

Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload

Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload

▾ Sunlitmobsf · mobsfEPSS 0.30%via OSV
CVE-2025-46730Medium· 6.8
1y ago

Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

▾ Sunlitmobsf · mobsfEPSS 0.48%via OSV
CVE-2025-32444Critical· 10.0
1y ago

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

▾ Midnightvllm · vllmEPSS 1.8%via OSV
CVE-2025-46560Medium· 6.5
1y ago

phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

▾ Sunlitvllm · vllmEPSS 0.52%via OSV
CVE-2025-1194Medium· 4.3
1y ago

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

▾ Sunlittransformers · transformersEPSS 0.48%via OSV
CVE-2025-30202High· 7.5
1y ago

Data exposure via ZeroMQ on multi-node vLLM deployment

Data exposure via ZeroMQ on multi-node vLLM deployment

▾ Twilightvllm · vllmEPSS 0.60%via OSV
CVE-2025-4032Medium· 5.0
1y ago

AWorld OS Command Injection vulnerability

AWorld OS Command Injection vulnerability

▾ Sunlitaworld · aworldEPSS 3.3%via OSV
CVE-2025-46656Low· 2.9
1y ago

markdownify allows large headline prefixes such as <h9999999>, which causes memory consumption

markdownify allows large headline prefixes such as <h9999999>, which causes memory consumption

▾ Sunlitmarkdownify · markdownifyEPSS 0.22%via OSV
CVE-2025-43859Critical· 9.1
1y ago

h11 accepts some malformed Chunked-Encoding bodies

h11 accepts some malformed Chunked-Encoding bodies

▾ Midnighth11 · h11EPSS 0.58%via OSV
GHSA-ggpf-24jw-3fcwCritical· 9.8
1y ago

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

▾ Midnightvllm · vllmvia OSV
CVE-2025-46567Medium· 6.1
1y ago

LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py

LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py

▾ Sunlitllamafactory · llamafactoryEPSS 0.29%via OSV
CVE-2025-32434CriticalPoC
1y ago

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

▾ Abyssaltorch · torchEPSS 2.2%via OSV
CVE-2025-28197Medium
1y ago

Crawl4AI SSRF vulnerability

Crawl4AI SSRF vulnerability

▾ Sunlitcrawl4ai · crawl4aiEPSS 0.36%via OSV
CVE-2025-32377Medium· 6.5
1y ago

Rasa Pro Missing Authentication For Voice Connector APIs

Rasa Pro Missing Authentication For Voice Connector APIs

▾ Sunlitrasa-pro · rasa-proEPSS 0.46%via OSV
CVE-2025-3730Low· 3.3
1y ago

PyTorch Improper Resource Shutdown or Release vulnerability

PyTorch Improper Resource Shutdown or Release vulnerability

▾ Sunlittorch · torchEPSS 0.33%via OSV
CVE-2024-53305High
1y ago

Whoogle allows attackers to execute arbitrary code via supplying a crafted search query

Whoogle allows attackers to execute arbitrary code via supplying a crafted search query

▾ Twilightwhoogle-search · whoogle-searchEPSS 0.58%via OSV
CVE-2025-32381Medium· 6.5
1y ago

xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory

xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory

▾ Sunlitxgrammar · xgrammarEPSS 0.50%via OSV
CVE-2025-71351Medium
1y ago

Picklescan missing detection when calling built-in python library function timeit.timeit()

Picklescan missing detection when calling built-in python library function timeit.timeit()

▾ Sunlitpicklescan · picklescanEPSS 0.71%via OSV
CVE-2025-71355Medium
1y ago

Picklescan failed to detect to some unsafe global function in Numpy library

Picklescan failed to detect to some unsafe global function in Numpy library

▾ Sunlitpicklescan · picklescanEPSS 0.58%via OSV
CVE-2025-46417High
1y ago

Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate

Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate

▾ Twilightpicklescan · picklescanEPSS 0.22%via OSV
CVE-2025-30473High· 8.8
1y ago

Apache Airflow Common SQL Provider Vulnerable to SQL Injection

Apache Airflow Common SQL Provider Vulnerable to SQL Injection

▾ Twilightapache-airflow-providers-common-sql · apache-airflow-providers-common-sqlEPSS 0.92%via OSV
CVE-2025-27520Critical· 9.8PoC
1y ago

BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization

BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization

▾ Abyssalbentoml · bentomlEPSS 41%via OSV
CVE-2025-30370High· 7.4
1y ago

jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"

jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"

▾ Twilightjupyterlab-git · jupyterlab-gitEPSS 0.58%via OSV
CVEs tagged “pip” — page 95 · VulnSea