Записи pypa
11 опубликованных записей вендора pypa.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 90,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-287 Improper Authentication1
- CWE-36 Absolute Path Traversal1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2022-21668Proof of concept | Pipenv's requirements.txt parsing allows malicious index url in commentspypa · pipenv · CWE-20 | Высокая8,6 | — | 3,9 % | 10 янв. 2022 г. |
32Наблюдать | CVE-2018-20225Proof of concept | An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intendedpypa · pip · CWE-20 | Высокая7,8 | — | 1,8 % | 8 мая 2020 г. |
31Наблюдать | CVE-2019-20916Эксплойта нет | The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition hpypa · pip · CWE-22 | Высокая7,5 | — | 3,0 % | 4 сент. 2020 г. |
29Наблюдать | CVE-2013-1629Эксплойта нет | pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allpypa · pip · CWE-20 | Средняя6,8 | — | 6,2 % | 5 авг. 2013 г. |
25Наблюдать | CVE-2013-5123Proof of concept | The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackerspypa · pip · CWE-287 | Средняя5,9 | — | 8,0 % | 5 нояб. 2019 г. |
23Наблюдать | CVE-2021-3572Proof of concept | A flaw was found in python-pip in the way it handled Unicode separators in git references.pypa · pip · CWE-20 | Средняя5,7 | — | 1,8 % | 10 нояб. 2021 г. |
22Наблюдать | CVE-2026-13346Эксплойта нет | pip absolute path traversal during download from malicious package indexespypa · pip · CWE-36 | Средняя5,6 | — | 0,3 % | 29 июл. 2026 г. |
16Наблюдать | CVE-2026-8643Эксплойта нет | pip can extract console_scripts and gui_scripts outside installation directorypypa · pip · CWE-22 | Средняя4,1 | — | 0,5 % | 1 июн. 2026 г. |
13Наблюдать | CVE-2023-5752Эксплойта нет | Mercurial configuration injectable in repo revision when installing via pippypa · pip · CWE-77 | Низкая3,3 | — | 0,5 % | 25 окт. 2023 г. |
8Наблюдать | CVE-2014-8991Эксплойта нет | pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* fipypa · pip | Низкая2,1 | — | 0,4 % | 24 нояб. 2014 г. |
8Наблюдать | CVE-2013-1888Эксплойта нет | pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.pypa · pip · CWE-59 | Низкая2,1 | — | 0,4 % | 17 авг. 2013 г. |
- CVE-2022-2166835Наблюдать
Pipenv's requirements.txt parsing allows malicious index url in comments
ВысокаяCVSS 8,6Proof of conceptEPSS 4 %pypa · pipenv10 янв. 2022 г.
- CVE-2018-2022532Наблюдать
An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended
ВысокаяCVSS 7,8Proof of conceptEPSS 2 %pypa · pip8 мая 2020 г.
- CVE-2019-2091631Наблюдать
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition h
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %pypa · pip4 сент. 2020 г.
- CVE-2013-162929Наблюдать
pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which all
СредняяCVSS 6,8Эксплойта нетEPSS 6 %pypa · pip5 авг. 2013 г.
- CVE-2013-512325Наблюдать
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers
СредняяCVSS 5,9Proof of conceptEPSS 8 %pypa · pip5 нояб. 2019 г.
- CVE-2021-357223Наблюдать
A flaw was found in python-pip in the way it handled Unicode separators in git references.
СредняяCVSS 5,7Proof of conceptEPSS 2 %pypa · pip10 нояб. 2021 г.
- CVE-2026-1334622Наблюдать
pip absolute path traversal during download from malicious package indexes
СредняяCVSS 5,6Эксплойта нетEPSS 0 %pypa · pip29 июл. 2026 г.
- CVE-2026-864316Наблюдать
pip can extract console_scripts and gui_scripts outside installation directory
СредняяCVSS 4,1Эксплойта нетEPSS 0 %pypa · pip1 июн. 2026 г.
- CVE-2023-575213Наблюдать
Mercurial configuration injectable in repo revision when installing via pip
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %pypa · pip25 окт. 2023 г.
- CVE-2014-89918Наблюдать
pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* fi
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %pypa · pip24 нояб. 2014 г.
- CVE-2013-18888Наблюдать
pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %pypa · pip17 авг. 2013 г.