Vulnerabilities > Virtualenv

DATE CVE VULNERABILITY TITLE RISK
2024-11-24 CVE-2024-53899 Command Injection vulnerability in Virtualenv
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment.
network
low complexity
virtualenv CWE-77
critical
9.8
2019-11-05 CVE-2013-5123 Improper Authentication vulnerability in multiple products
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
network
high complexity
pypa virtualenv fedoraproject redhat debian CWE-287
5.9