Skip to content
Noroxi

virtualenv records

3 published records for vendor virtualenv.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

3 records
  • virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment.

    HighCVSS 7.8No exploitEPSS 2%

    virtualenv · virtualenvNov 24, 2024

  • CVE-2013-5123
    25Monitor

    The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers

    MediumCVSS 5.9Proof of conceptEPSS 8%

    pypa · pipNov 5, 2019

  • virtualenv Has TOCTOU Vulnerabilities in Directory Creation

    MediumCVSS 4.5No exploitEPSS 0%

    virtualenv · virtualenvJan 10, 2026