VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2025-3160Low· 3.3
1y ago

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the fu…

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the compone…

▾ Sunlitpyassimp · pyassimpEPSS 0.28%via OSV
CVE-2025-3159High· 7.8
1y ago

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp:…

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component…

▾ Twilightpyassimp · pyassimpEPSS 0.33%via OSV
CVE-2025-3163Medium· 5.3
1y ago

InternLM LMDeploy code injection vulnerability

InternLM LMDeploy code injection vulnerability

▾ Sunlitlmdeploy · lmdeployEPSS 0.37%via OSV
CVE-2025-3162Medium· 5.3
1y ago

LMDeploy Improper Input Validation Vulnerability

LMDeploy Improper Input Validation Vulnerability

▾ Sunlitlmdeploy · lmdeployEPSS 0.32%via OSV
CVE-2025-3016Medium· 6.5
1y ago

A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function As…

A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the …

▾ Sunlitpyassimp · pyassimpEPSS 0.62%via OSV
CVE-2025-3015High· 8.8
1y ago

A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImp…

A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE Fi…

▾ Twilightpyassimp · pyassimpEPSS 0.50%via OSV
CVE-2025-3001None
1y ago

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulat…

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disc…

▾ Sunlittorch · torchEPSS 0.20%via OSV
CVE-2025-3000Medium· 5.3
1y ago

PyTorch is vulnerable to memory corruption through its torch.jit.script function

PyTorch is vulnerable to memory corruption through its torch.jit.script function

▾ Sunlittorch · torchEPSS 0.20%via OSV
CVE-2025-2999None
1y ago

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpa…

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The ex…

▾ Sunlittorch · torchEPSS 0.20%via OSV
CVE-2025-3047Medium· 6.5PoC
1y ago

AWS SAM CLI Path Traversal allows file copy to build container

AWS SAM CLI Path Traversal allows file copy to build container

▾ Twilightaws-sam-cli · aws-sam-cliEPSS 0.76%via OSV
CVE-2025-3048Medium· 6.5
1y ago

AWS SAM CLI Path Traversal allows file copy to local cache

AWS SAM CLI Path Traversal allows file copy to local cache

▾ Sunlitaws-sam-cli · aws-sam-cliEPSS 0.65%via OSV
CVE-2025-2953Low· 3.3
1y ago

PyTorch susceptible to local Denial of Service

PyTorch susceptible to local Denial of Service

▾ Sunlittorch · torchEPSS 0.26%via OSV
CVE-2025-30355High· 7.1
1y ago

Synapse vulnerable to federation denial of service via malformed events

Synapse vulnerable to federation denial of service via malformed events

▾ Twilightmatrix-synapse · matrix-synapseEPSS 1.2%via OSV
CVE-2025-30358High· 8.1
1y ago

Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks

Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks

▾ Twilightmesop · mesopEPSS 0.70%via OSV
CVE-2025-30217Medium
1y ago

Frappe has possibility of SQL injection due to improper validations

Frappe has possibility of SQL injection due to improper validations

▾ Sunlitfrappe · frappeEPSS 0.36%via OSV
CVE-2025-30213Medium
1y ago

Frappe has Possibility of Remote Code Execution due to improper validation

Frappe has Possibility of Remote Code Execution due to improper validation

▾ Sunlitfrappe · frappeEPSS 0.72%via OSV
CVE-2025-30214High
1y ago

Frappe vulnerable to information disclosure leading to account takeover

Frappe vulnerable to information disclosure leading to account takeover

▾ Twilightfrappe · frappeEPSS 0.41%via OSV
CVE-2025-30212Medium
1y ago

Frappe has possibility of SQL injection due to improper validations

Frappe has possibility of SQL injection due to improper validations

▾ Sunlitfrappe · frappeEPSS 0.43%via OSV
CVE-2025-2592High· 8.8
1y ago

A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the funct…

A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads …

▾ Twilightpyassimp · pyassimpEPSS 0.73%via OSV
CVE-2024-8769Critical· 9.1
1y ago

Aim path traversal in LockManager.release_locks

Aim path traversal in LockManager.release_locks

▾ Midnightaim · aimEPSS 0.91%via OSV
CVE-2024-8019Critical· 9.1
1y ago

PyTorch Lightning path traversal vulnerability

PyTorch Lightning path traversal vulnerability

▾ Midnightpytorch-lightning · pytorch-lightningEPSS 1.1%via OSV
CVE-2024-9052Critical· 9.8
1y ago

vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object

vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object

▾ Midnightvllm · vllmvia OSV
CVE-2024-9053Critical· 9.8
1y ago

vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints

vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints

▾ Midnightvllm · vllmEPSS 1.4%via OSV
CVE-2024-11041Critical· 9.8
1y ago

vLLM Deserialization of Untrusted Data vulnerability

vLLM Deserialization of Untrusted Data vulnerability

▾ Midnightvllm · vllmEPSS 1.6%via OSV
CVE-2024-11958Critical· 9.8
1y ago

LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection

LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection

▾ Midnightllama-index-retrievers-duckdb-retriever · llama-index-retrievers-duckdb-retrieverEPSS 1.4%via OSV
CVE-2024-8613High· 8.8
1y ago

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. …

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, en…

▾ Twilightchuanhuchatgpt · chuanhuchatgptEPSS 0.59%via OSV
CVE-2024-6577Medium· 6.3
1y ago

TorchServe script references S3 bucket without ensuring ownership or confirming accessibility

TorchServe script references S3 bucket without ensuring ownership or confirming accessibility

▾ Sunlittorchserve · torchserveEPSS 0.39%via OSV
CVE-2024-7959High· 7.7
1y ago

Open WebUI has SSRF in /openai/models

Open WebUI has SSRF in /openai/models

▾ Twilightopen-webui · open-webuiEPSS 24%via OSV
CVE-2024-12761High· 7.5
1y ago

imaginAIry Denial of Service (DoS) vulnerability

imaginAIry Denial of Service (DoS) vulnerability

▾ Twilightimaginairy · imaginairyEPSS 0.70%via OSV
CVE-2024-11602High· 7.4
1y ago

Feast Cross-Origin Resource Sharing vulnerability

Feast Cross-Origin Resource Sharing vulnerability

▾ Twilightfeast · feastEPSS 0.30%via OSV
CVEs tagged “pip” — page 96 · VulnSea