VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4643 CVEsRSS

CVE-2024-10829High· 7.5PoC
1y ago

DB-GPT Uncontrolled Resource Consumption vulnerability

DB-GPT Uncontrolled Resource Consumption vulnerability

▾ Midnightdbgpt · dbgptEPSS 0.72%via OSV
CVE-2024-8061High· 7.5
1y ago

Aim allows denial of service due to no timeouts for some tracking server endpoints

Aim allows denial of service due to no timeouts for some tracking server endpoints

▾ Twilightaim · aimEPSS 0.47%via OSV
CVE-2024-7765High· 7.5
1y ago

H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing

H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing

▾ Twilighth2o · h2oEPSS 0.76%via OSV
CVE-2024-12720Medium· 5.3
1y ago

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

▾ Sunlittransformers · transformersEPSS 0.73%via OSV
CVE-2024-8556Medium· 6.1
1y ago

AgentScope stored cross-site scripting (XSS) vulnerability

AgentScope stored cross-site scripting (XSS) vulnerability

▾ Sunlitagentscope · agentscopeEPSS 0.42%via OSV
CVE-2024-10821High· 7.5PoC
1y ago

InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`

InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`

▾ Midnightinvokeai · invokeaiEPSS 0.63%via OSV
CVE-2024-8953High· 7.2
1y ago

Composio Eval Injection Vulnerability

Composio Eval Injection Vulnerability

▾ Twilightcomposio-core · composio-coreEPSS 1.2%via OSV
CVE-2024-7983High· 7.5
1y ago

Open WebUI denial of service through endpoint for converting markdown

Open WebUI denial of service through endpoint for converting markdown

▾ Twilightopen-webui · open-webuiEPSS 0.86%via OSV
CVE-2024-8966High· 7.5
1y ago

Gradio DOS in multipart boundry while uploading the file

Gradio DOS in multipart boundry while uploading the file

▾ Twilightgradio · gradioEPSS 0.79%via OSV
CVE-2024-10940Medium· 5.3
1y ago

langchain-core allows unauthorized users to read arbitrary files from the host file system

langchain-core allows unauthorized users to read arbitrary files from the host file system

▾ Sunlitlangchain-core · langchain-coreEPSS 0.39%via OSV
CVE-2024-8062High· 7.5
1y ago

H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request

H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request

▾ Twilighth2o · h2oEPSS 0.47%via OSV
CVE-2024-6825High· 8.8
1y ago

LiteLLM Vulnerable to Remote Code Execution (RCE)

LiteLLM Vulnerable to Remote Code Execution (RCE)

▾ Twilightlitellm · litellmEPSS 1.7%via OSV
CVE-2024-8183High· 7.6
1y ago

Prefect CORS (Cross-Origin Resource Sharing) misconfiguration

Prefect CORS (Cross-Origin Resource Sharing) misconfiguration

▾ Twilightprefect · prefectEPSS 0.18%via OSV
CVE-2024-8859High· 7.5PoC
1y ago

MLflow has a Local File Read/Path Traversal in dbfs

MLflow has a Local File Read/Path Traversal in dbfs

▾ Midnightmlflow · mlflowEPSS 2.7%via OSV
CVE-2025-0453Medium· 5.9
1y ago

MLflow Uncontrolled Resource Consumption vulnerability

MLflow Uncontrolled Resource Consumption vulnerability

▾ Sunlitmlflow · mlflowEPSS 11%via OSV
CVE-2024-6854High· 7.1
1y ago

H2O Vulnerable to Arbitrary File Overwrite via File Export

H2O Vulnerable to Arbitrary File Overwrite via File Export

▾ Twilighth2o · h2oEPSS 0.76%via OSV
CVE-2024-6866Medium· 5.3
1y ago

Flask-CORS vulnerable to Improper Handling of Case Sensitivity

Flask-CORS vulnerable to Improper Handling of Case Sensitivity

▾ Sunlitflask-cors · flask-corsEPSS 0.71%via OSV
CVE-2024-7053High· 7.6
1y ago

Open WebUI Vulnerable to a Session Fixation Attack

Open WebUI Vulnerable to a Session Fixation Attack

▾ Twilightopen-webui · open-webuiEPSS 0.68%via OSV
CVE-2024-7033Medium· 6.5
1y ago

Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint

Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint

▾ Sunlitopen-webui · open-webuiEPSS 1.1%via OSV
CVE-2024-7760High· 7.4
1y ago

Aim vulnerable to Cross-Site Request Forgery

Aim vulnerable to Cross-Site Request Forgery

▾ Twilightaim · aimEPSS 0.52%via OSV
CVE-2024-8955Medium· 6.8
1y ago

composio allows Server-Side Request Forgery (SSRF) in BROWSERTOOL

composio allows Server-Side Request Forgery (SSRF) in BROWSERTOOL

▾ Sunlitcomposio-core · composio-coreEPSS 0.73%via OSV
CVE-2024-12778High· 7.5
1y ago

Aim Uncontrolled Resource Consumption vulnerability

Aim Uncontrolled Resource Consumption vulnerability

▾ Twilightaim · aimEPSS 0.78%via OSV
CVE-2025-0508Medium· 5.9
1y ago

SageMaker Workflow component allows possibility of MD5 hash collisions

SageMaker Workflow component allows possibility of MD5 hash collisions

▾ Sunlitsagemaker · sagemakerEPSS 0.26%via OSV
CVE-2024-10906High· 7.1
1y ago

DB-GPT vulnerable to Cross-Site Request Forgery

DB-GPT vulnerable to Cross-Site Request Forgery

▾ Twilightdbgpt · dbgptEPSS 0.24%via OSV
CVE-2025-29783Critical· 9.0
1y ago

vLLM Allows Remote Code Execution via Mooncake Integration

vLLM Allows Remote Code Execution via Mooncake Integration

▾ Midnightvllm · vllmEPSS 0.73%via OSV
CVE-2025-29770Medium· 6.5
1y ago

vLLM denial of service via outlines unbounded cache on disk

vLLM denial of service via outlines unbounded cache on disk

▾ Sunlitvllm · vllmEPSS 0.46%via OSV
CVE-2025-27018Medium· 6.3
1y ago

Apache Airflow MySQL Provider is Vulnerable to SQL Injection

Apache Airflow MySQL Provider is Vulnerable to SQL Injection

▾ Sunlitapache-airflow-providers-mysql · apache-airflow-providers-mysqlEPSS 0.89%via OSV
GHSA-v432-7f47-9g94High
1y ago

PostQuantum-Feldman-VSS'S Dependency Vulnerability in gmpy2 Leading to Interpreter Crash

PostQuantum-Feldman-VSS'S Dependency Vulnerability in gmpy2 Leading to Interpreter Crash

▾ Twilightpostquantum-feldman-vss · postquantum-feldman-vssvia OSV
CVE-2025-29779Medium
1y ago

Post-Quantum Secure Feldman's Verifiable Secret Sharing has Inadequate Fault Injection Countermeasures in `secure_redundant_execution`

Post-Quantum Secure Feldman's Verifiable Secret Sharing has Inadequate Fault Injection Countermeasures in `secure_redundant_execution`

▾ Sunlitpostquantum-feldman-vss · postquantum-feldman-vssEPSS 0.18%via OSV
CVE-2025-29780Medium
1y ago

Post-Quantum Secure Feldman's Verifiable Secret Sharing has Timing Side-Channels in Matrix Operations

Post-Quantum Secure Feldman's Verifiable Secret Sharing has Timing Side-Channels in Matrix Operations

▾ Sunlitpostquantum-feldman-vss · postquantum-feldman-vssEPSS 0.23%via OSV
CVEs tagged “pip” — page 99 · VulnSea