VYPR

Vendor CVEs

Pypi

All CVEs

67 total · sorted by risk
  • CVE-2026-48099HigAug 13, 2026
    risk 0.39cvss 7.1epss 0.00

    WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.

  • CVE-2026-13705HigJul 6, 2026
    risk 0.39cvss 7.1epss 0.00

    Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle. read_rgb_16_rle guards each literal run with if (count > data_left), but count is a pixel count while every 16-bit…

  • CVE-2026-54567higJul 17, 2026
    risk 0.38cvss epss

    ## 1. Header | Field | Value | |---|---| | **Title** | Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641) | | **Project** | Flask-Reuploaded (`flask_uploads`) | | **Affected** | `<= 1.5.0` (latest release;…

  • CVE-2026-48782MedJun 17, 2026
    risk 0.37cvss 6.8epss 0.00

    Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form that the previous…

  • CVE-2026-59820MedJul 8, 2026
    risk 0.35cvss 6.5epss 0.00

    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authenticated user with access to LiteLLM LLM…

  • CVE-2026-55699MedJun 25, 2026
    risk 0.35cvss 6.5epss 0.00

    pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malicious package was installed globally, later global remove, update, or add-replacement flows could re-derive those names from the…

  • CVE-2026-9641MedJun 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm,…

  • CVE-2026-13484MedJun 28, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack…

  • CVE-2026-12799MedJun 21, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_view_users of the file litellm/proxy/management_endpoints/internal_user_endpoints.py of the component Incomplete Fix CVE-2025-0628. Such manipulation leads to…

  • CVE-2026-54503medJul 17, 2026
    risk 0.26cvss epss

    ### Impact A stored XSS affecting RichText fields. RichTextValue.output returns the raw, unsanitized stored value whenever the stored mimeType equals the outputMimeType. Because the safe-HTML output type (`text/x-html-safe`) is the type that signifies "already sanitized", any…

  • CVE-2026-59819MedJul 8, 2026
    risk 0.25cvss 4.9epss 0.00

    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, allowing a proxy administrator or another…

  • CVE-2020-37118LowFeb 5, 2026
    risk 0.23cvss 3.5epss 0.00

    P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user interaction. Attackers can craft malicious web pages to add new admin users, change passwords, and modify system configurations…

  • CVE-2026-14742LowJul 5, 2026
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the component Task Result Cache. This manipulation of the argument default_cache_key causes use of weak…

  • CVE-2026-17039LowJul 24, 2026
    risk 0.13cvss 3.1epss 0.00

    A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to…

  • CVE-2026-65477HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.

  • CVE-2026-49297HigJul 6, 2026
    risk 0.00cvss 8.1epss 0.01

    Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the…

  • CVE-2005-0017May 2, 2005
    risk 0.00cvss epss 0.00

    The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.

Page 2 of 2