Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2024-7046Medium· 4.3Open WebUI Allows Viewing of Admin Details
Open WebUI Allows Viewing of Admin Details
CVE-2024-7990High· 8.4Open WebUI stored cross-site scripting (XSS) vulnerability
Open WebUI stored cross-site scripting (XSS) vulnerability
CVE-2024-9606High· 7.5LiteLLM Reveals Portion of API Key via a Logging File
LiteLLM Reveals Portion of API Key via a Logging File
CVE-2024-8616High· 8.2H2O Vulnerable to Arbitrary File Overwrite
H2O Vulnerable to Arbitrary File Overwrite
CVE-2024-12376High· 7.5FastChat Server-Side Request Forgery vulnerability
FastChat Server-Side Request Forgery vulnerability
CVE-2024-12534High· 7.5Open WebUI Uncontrolled Resource Consumption vulnerability
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-10110High· 7.5Aim Vulnerable to Denial of Service (DoS)
Aim Vulnerable to Denial of Service (DoS)
CVE-2025-0190High· 7.5Aim Excessive Data Query Operations in a Large Data Table vulnerability
Aim Excessive Data Query Operations in a Large Data Table vulnerability
CVE-2025-0628High· 8.1LiteLLM Has an Improper Authorization Vulnerability
LiteLLM Has an Improper Authorization Vulnerability
CVE-2024-8984High· 7.5LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
CVE-2024-11043High· 7.5InvokeAI Uncontrolled Resource Consumption vulnerability
InvokeAI Uncontrolled Resource Consumption vulnerability
CVE-2024-8060High· 8.1Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
CVE-2024-7034Medium· 6.5Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint
Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint
CVE-2024-12537High· 7.5PoCOpen WebUI Uncontrolled Resource Consumption vulnerability
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-10713High· 7.5HyperLPR Denial of Service vulnerability
HyperLPR Denial of Service vulnerability
CVE-2024-7045Medium· 4.3Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read
Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read
CVE-2024-8053High· 7.5Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
CVE-2024-8020High· 7.5PyTorch Lightning denial of service vulnerability
PyTorch Lightning denial of service vulnerability
CVE-2025-1473Medium· 5.4MLflow Cross-Site Request Forgery (CSRF) vulnerability
MLflow Cross-Site Request Forgery (CSRF) vulnerability
CVE-2024-6844Medium· 5.3Flask-CORS allows for inconsistent CORS matching
Flask-CORS allows for inconsistent CORS matching
CVE-2024-10830High· 8.2DB-GPT Path Traversal vulnerability
DB-GPT Path Traversal vulnerability
CVE-2025-0330High· 7.5LiteLLM Has a Leakage of Langfuse API Keys
LiteLLM Has a Leakage of Langfuse API Keys
CVE-2024-7806High· 8.0Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability
Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability
CVE-2024-10569High· 7.5Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
CVE-2024-8021Medium· 5.4PoCGradio Vulnerable to Open Redirect
Gradio Vulnerable to Open Redirect
CVE-2024-6839Medium· 4.3Flask-CORS improper regex path matching vulnerability
Flask-CORS improper regex path matching vulnerability
CVE-2024-10550High· 7.5H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
CVE-2024-10912High· 7.5FastChat Denial of Service vulnerability
FastChat Denial of Service vulnerability
CVE-2024-10908Medium· 6.1PoCFastChat open redirect vulnerability
FastChat open redirect vulnerability
CVE-2024-9701Critical· 9.8Kedro deserialization vulnerability
Kedro deserialization vulnerability