VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2025-64324High· 7.7
10mo ago

KubeVirt Vulnerable to Arbitrary Host File Read and Write

KubeVirt Vulnerable to Arbitrary Host File Read and Write

▾ Twilightkubevirt · kubevirt.io/kubevirtEPSS 0.22%via OSV
CVE-2025-57698High
10mo ago

AstrBot contains a directory traversal vulnerability

AstrBot contains a directory traversal vulnerability

▾ Twilightastrbot · astrbotEPSS 0.78%via OSV
CVE-2025-64512High· 8.6PoC
10mo ago

Arbitrary Code Execution in pdfminer.six via Crafted PDF Input

Arbitrary Code Execution in pdfminer.six via Crafted PDF Input

▾ Midnightpdfminer-six · pdfminer-sixEPSS 0.31%via OSV
CVE-2025-64495High· 8.7PoC
10mo ago

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

▾ Midnightopen-webui · open-webuiEPSS 0.46%via OSV
CVE-2025-57697Medium
10mo ago

AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64

AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64

▾ Sunlitastrbot · astrbotEPSS 0.32%via OSV
CVE-2025-70559High· 7.8PoC
10mo ago

Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc

Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc

▾ Midnightpdfminer-six · pdfminer-sixEPSS 0.30%via OSV
CVE-2025-64496High· 7.3
10mo ago

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

▾ Twilightopen-webui · open-webuiEPSS 7.8%via OSV
CVE-2025-64436Medium· 5.3
10mo ago

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

▾ Sunlitkubevirt · kubevirt.io/kubevirtEPSS 0.26%via OSV
CVE-2025-64437Medium· 5.0
10mo ago

KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes

KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes

▾ Sunlitkubevirt · kubevirt.io/kubevirtEPSS 0.21%via OSV
CVE-2025-64458High· 7.5PoC
10mo ago

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows

▾ Midnightdjango · djangoEPSS 1.9%via OSV
CVE-2025-64439High
10mo ago

LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer

LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer

▾ Twilightlanggraph-checkpoint · langgraph-checkpointEPSS 0.88%via OSV
CVE-2025-58337Medium
10mo ago

Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode

Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode

▾ Sunlitdoris-mcp-server · doris-mcp-serverEPSS 0.35%via OSV
RUSTSEC-2025-0154None
11mo ago

`replit_ruspty` was removed from crates.io for malicious code

`replit_ruspty` was removed from crates.io for malicious code

▾ Sunlitreplit_ruspty · replit_rusptyvia OSV
MAL-2025-49350None
11mo ago

Malicious code in replit_ruspty (crates.io)

Malicious code in replit_ruspty (crates.io)

▾ Sunlitreplit_ruspty · replit_rusptyvia OSV
CVE-2025-12695Medium· 5.9
11mo ago

DSPy does not properly restrict file reads

DSPy does not properly restrict file reads

▾ Sunlitdspy · dspyEPSS 0.32%via OSV
CVE-2025-64187Medium
11mo ago

OctoPrint vulnerable to XSS in Action Commands Notification and Prompt

OctoPrint vulnerable to XSS in Action Commands Notification and Prompt

▾ Sunlitoctoprint · octoprintEPSS 0.16%via OSV
CVE-2025-64184High· 8.8
11mo ago

Dosage vulnerable to a Directory Traversal through crafted HTTP responses

Dosage vulnerable to a Directory Traversal through crafted HTTP responses

▾ Twilightdosage · dosageEPSS 0.45%via OSV
CVE-2025-60787High· 7.2PoC
11mo ago

motionEye vulnerable to RCE via unsanitized motion config parameter

motionEye vulnerable to RCE via unsanitized motion config parameter

▾ Midnightmotioneye · motioneyeEPSS 18%via OSV
MAL-2025-191874None
11mo ago

Malicious code in speed-testing-nt (PyPI)

Malicious code in speed-testing-nt (PyPI)

▾ Sunlitspeed-testing-nt · speed-testing-ntvia OSV
CVE-2025-64168High· 7.1
11mo ago

Agno session state overwrites between different sessions/users

Agno session state overwrites between different sessions/users

▾ Twilightagno · agnoEPSS 0.15%via OSV
CVE-2025-63675Medium· 6.9
11mo ago

cryptidy allows code execution via untrusted data due to pickle.loads

cryptidy allows code execution via untrusted data due to pickle.loads

▾ Sunlitcryptidy · cryptidyEPSS 0.24%via OSV
CVE-2025-6176High· 7.5
11mo ago

Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

▾ Twilightbrotli · brotliEPSS 0.50%via OSV
CVE-2025-54941Medium
11mo ago

Apache Airflow has a command injection vulnerability in "example_dag_decorator"

Apache Airflow has a command injection vulnerability in "example_dag_decorator"

▾ Sunlitapache-airflow · apache-airflowEPSS 0.46%via OSV
CVE-2025-50736Low
11mo ago

Byaidu PDFMathTranslate vulnerable to open redirect

Byaidu PDFMathTranslate vulnerable to open redirect

▾ Sunlitpdf2zh · pdf2zhEPSS 0.21%via OSV
CVE-2025-62503Medium· 4.6
11mo ago

Apache Airflow's create action can upsert existing Pools/Connections/Variables

Apache Airflow's create action can upsert existing Pools/Connections/Variables

▾ Sunlitapache-airflow · apache-airflowEPSS 0.40%via OSV
CVE-2025-62402Medium· 5.4
11mo ago

Apache Airflow `/api/v2/dagReports` executes DAG Python in API

Apache Airflow `/api/v2/dagReports` executes DAG Python in API

▾ Sunlitapache-airflow · apache-airflowEPSS 0.49%via OSV
CVE-2025-58188Medium
11mo ago

crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 (CVE-2025-58188)

A denial of service vector has been discovered in the golang crypto/x509 module. An attacker could craft an intermediate X.509 certificate containing a DSA public key and can crash a remote host with an unauthenticated call to any endpoint…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.38%via CSAF
CVE-2025-58183None
11mo ago

Unbounded allocation when parsing GNU sparse map in archive/tar

Unbounded allocation when parsing GNU sparse map in archive/tar

▾ Sunlitstdlib · stdlibEPSS 0.44%via OSV
CVE-2025-13327Medium
11mo ago

uv allows ZIP payload obfuscation through parsing differentials

uv allows ZIP payload obfuscation through parsing differentials

▾ Sunlituv · uvEPSS 0.15%via OSV
CVE-2025-62801Medium
11mo ago

FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name

FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name

▾ Sunlitfastmcp · fastmcpEPSS 0.23%via OSV
CVEs tagged “osv” — page 101 · VulnSea