Vulnerabilities
Vulnerable Software
Virtualenv:  >> Virtualenv  Security Vulnerabilities
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
CVSS Score
7.8
EPSS Score
0.006
Published
2024-11-24
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
CVSS Score
5.9
EPSS Score
0.129
Published
2019-11-05


Contact Us

Shodan ® - All rights reserved