Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2024-10829High· 7.5PoCDB-GPT Uncontrolled Resource Consumption vulnerability
DB-GPT Uncontrolled Resource Consumption vulnerability
CVE-2024-8061High· 7.5Aim allows denial of service due to no timeouts for some tracking server endpoints
Aim allows denial of service due to no timeouts for some tracking server endpoints
CVE-2024-7765High· 7.5H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
CVE-2024-12720Medium· 5.3Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2024-8556Medium· 6.1AgentScope stored cross-site scripting (XSS) vulnerability
AgentScope stored cross-site scripting (XSS) vulnerability
CVE-2024-10821High· 7.5PoCInvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`
InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`
CVE-2024-8953High· 7.2Composio Eval Injection Vulnerability
Composio Eval Injection Vulnerability
CVE-2024-7983High· 7.5Open WebUI denial of service through endpoint for converting markdown
Open WebUI denial of service through endpoint for converting markdown
CVE-2024-8966High· 7.5Gradio DOS in multipart boundry while uploading the file
Gradio DOS in multipart boundry while uploading the file
CVE-2024-10940Medium· 5.3langchain-core allows unauthorized users to read arbitrary files from the host file system
langchain-core allows unauthorized users to read arbitrary files from the host file system
CVE-2024-8062High· 7.5H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
CVE-2024-6825High· 8.8LiteLLM Vulnerable to Remote Code Execution (RCE)
LiteLLM Vulnerable to Remote Code Execution (RCE)
CVE-2024-8183High· 7.6Prefect CORS (Cross-Origin Resource Sharing) misconfiguration
Prefect CORS (Cross-Origin Resource Sharing) misconfiguration
CVE-2024-8859High· 7.5PoCMLflow has a Local File Read/Path Traversal in dbfs
MLflow has a Local File Read/Path Traversal in dbfs
CVE-2025-0453Medium· 5.9MLflow Uncontrolled Resource Consumption vulnerability
MLflow Uncontrolled Resource Consumption vulnerability
CVE-2024-6854High· 7.1H2O Vulnerable to Arbitrary File Overwrite via File Export
H2O Vulnerable to Arbitrary File Overwrite via File Export
CVE-2024-6866Medium· 5.3Flask-CORS vulnerable to Improper Handling of Case Sensitivity
Flask-CORS vulnerable to Improper Handling of Case Sensitivity
CVE-2024-7053High· 7.6Open WebUI Vulnerable to a Session Fixation Attack
Open WebUI Vulnerable to a Session Fixation Attack
CVE-2024-7033Medium· 6.5Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint
Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint
CVE-2024-7760High· 7.4Aim vulnerable to Cross-Site Request Forgery
Aim vulnerable to Cross-Site Request Forgery
CVE-2024-8955Medium· 6.8composio allows Server-Side Request Forgery (SSRF) in BROWSERTOOL
composio allows Server-Side Request Forgery (SSRF) in BROWSERTOOL
CVE-2024-12778High· 7.5Aim Uncontrolled Resource Consumption vulnerability
Aim Uncontrolled Resource Consumption vulnerability
CVE-2025-0508Medium· 5.9SageMaker Workflow component allows possibility of MD5 hash collisions
SageMaker Workflow component allows possibility of MD5 hash collisions
CVE-2024-10906High· 7.1DB-GPT vulnerable to Cross-Site Request Forgery
DB-GPT vulnerable to Cross-Site Request Forgery
CVE-2025-29783Critical· 9.0vLLM Allows Remote Code Execution via Mooncake Integration
vLLM Allows Remote Code Execution via Mooncake Integration
CVE-2025-29770Medium· 6.5vLLM denial of service via outlines unbounded cache on disk
vLLM denial of service via outlines unbounded cache on disk
CVE-2025-27018Medium· 6.3Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
GHSA-v432-7f47-9g94HighPostQuantum-Feldman-VSS'S Dependency Vulnerability in gmpy2 Leading to Interpreter Crash
PostQuantum-Feldman-VSS'S Dependency Vulnerability in gmpy2 Leading to Interpreter Crash
CVE-2025-29779MediumPost-Quantum Secure Feldman's Verifiable Secret Sharing has Inadequate Fault Injection Countermeasures in `secure_redundant_execution`
Post-Quantum Secure Feldman's Verifiable Secret Sharing has Inadequate Fault Injection Countermeasures in `secure_redundant_execution`
CVE-2025-29780MediumPost-Quantum Secure Feldman's Verifiable Secret Sharing has Timing Side-Channels in Matrix Operations
Post-Quantum Secure Feldman's Verifiable Secret Sharing has Timing Side-Channels in Matrix Operations