Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2025-64324High· 7.7KubeVirt Vulnerable to Arbitrary Host File Read and Write
KubeVirt Vulnerable to Arbitrary Host File Read and Write
CVE-2025-57698HighAstrBot contains a directory traversal vulnerability
AstrBot contains a directory traversal vulnerability
CVE-2025-64512High· 8.6PoCArbitrary Code Execution in pdfminer.six via Crafted PDF Input
Arbitrary Code Execution in pdfminer.six via Crafted PDF Input
CVE-2025-64495High· 8.7PoCOpen WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
CVE-2025-57697MediumAstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
CVE-2025-70559High· 7.8PoCInsecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
CVE-2025-64496High· 7.3Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
CVE-2025-64436Medium· 5.3KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
CVE-2025-64437Medium· 5.0KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
CVE-2025-64458High· 7.5PoCDjango has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-64439HighLangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
CVE-2025-58337MediumApache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
RUSTSEC-2025-0154None`replit_ruspty` was removed from crates.io for malicious code
`replit_ruspty` was removed from crates.io for malicious code
MAL-2025-49350NoneMalicious code in replit_ruspty (crates.io)
Malicious code in replit_ruspty (crates.io)
CVE-2025-12695Medium· 5.9DSPy does not properly restrict file reads
DSPy does not properly restrict file reads
CVE-2025-64187MediumOctoPrint vulnerable to XSS in Action Commands Notification and Prompt
OctoPrint vulnerable to XSS in Action Commands Notification and Prompt
CVE-2025-64184High· 8.8Dosage vulnerable to a Directory Traversal through crafted HTTP responses
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
CVE-2025-60787High· 7.2PoCmotionEye vulnerable to RCE via unsanitized motion config parameter
motionEye vulnerable to RCE via unsanitized motion config parameter
MAL-2025-191874NoneMalicious code in speed-testing-nt (PyPI)
Malicious code in speed-testing-nt (PyPI)
CVE-2025-64168High· 7.1Agno session state overwrites between different sessions/users
Agno session state overwrites between different sessions/users
CVE-2025-63675Medium· 6.9cryptidy allows code execution via untrusted data due to pickle.loads
cryptidy allows code execution via untrusted data due to pickle.loads
CVE-2025-6176High· 7.5Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
CVE-2025-54941MediumApache Airflow has a command injection vulnerability in "example_dag_decorator"
Apache Airflow has a command injection vulnerability in "example_dag_decorator"
CVE-2025-50736LowByaidu PDFMathTranslate vulnerable to open redirect
Byaidu PDFMathTranslate vulnerable to open redirect
CVE-2025-62503Medium· 4.6Apache Airflow's create action can upsert existing Pools/Connections/Variables
Apache Airflow's create action can upsert existing Pools/Connections/Variables
CVE-2025-62402Medium· 5.4Apache Airflow `/api/v2/dagReports` executes DAG Python in API
Apache Airflow `/api/v2/dagReports` executes DAG Python in API
CVE-2025-58188Mediumcrypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 (CVE-2025-58188)
A denial of service vector has been discovered in the golang crypto/x509 module. An attacker could craft an intermediate X.509 certificate containing a DSA public key and can crash a remote host with an unauthenticated call to any endpoint…
CVE-2025-58183NoneUnbounded allocation when parsing GNU sparse map in archive/tar
Unbounded allocation when parsing GNU sparse map in archive/tar
CVE-2025-13327Mediumuv allows ZIP payload obfuscation through parsing differentials
uv allows ZIP payload obfuscation through parsing differentials
CVE-2025-62801MediumFastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name