virtualenv records
3 published records for vendor virtualenv.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2024-53899No exploit | virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment.virtualenv · virtualenv · CWE-77 | High7.8 | — | 1.6% | Nov 24, 2024 |
25Monitor | CVE-2013-5123Proof of concept | The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackerspypa · pip · CWE-287 | Medium5.9 | — | 8.0% | Nov 5, 2019 |
18Monitor | CVE-2026-22702No exploit | virtualenv Has TOCTOU Vulnerabilities in Directory Creationvirtualenv · virtualenv · CWE-59 | Medium4.5 | — | 0.1% | Jan 10, 2026 |
- CVE-2024-5389931Monitor
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment.
HighCVSS 7.8No exploitEPSS 2%virtualenv · virtualenvNov 24, 2024
- CVE-2013-512325Monitor
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers
MediumCVSS 5.9Proof of conceptEPSS 8%pypa · pipNov 5, 2019
- CVE-2026-2270218Monitor
virtualenv Has TOCTOU Vulnerabilities in Directory Creation
MediumCVSS 4.5No exploitEPSS 0%virtualenv · virtualenvJan 10, 2026