Vulnerabilities > Pypa > High

DATE CVE VULNERABILITY TITLE RISK
2022-01-10 CVE-2022-21668 Improper Validation of Specified Quantity in Input vulnerability in multiple products
pipenv is a Python development workflow tool.
local
low complexity
pypa fedoraproject CWE-1284
8.6
2020-09-04 CVE-2019-20916 Path Traversal vulnerability in multiple products
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file.
network
low complexity
pypa opensuse debian oracle CWE-22
7.5
2020-05-08 CVE-2018-20225 Improper Input Validation vulnerability in Pypa PIP
An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index.
local
low complexity
pypa CWE-20
7.8