Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2025-62800MediumFastMCP vulnerable to reflected XSS in client's callback page
FastMCP vulnerable to reflected XSS in client's callback page
CVE-2025-12058MediumKeras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
CVE-2025-64104High· 7.3LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
CVE-2025-11200High· 8.10dayMLflow Weak Password Requirements Authentication Bypass Vulnerability
MLflow Weak Password Requirements Authentication Bypass Vulnerability
CVE-2025-11201High· 8.10dayPoCMLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
CVE-2025-54384Medium· 6.3CKAN vulnerable to stored XSS in resource description
CKAN vulnerable to stored XSS in resource description
CVE-2025-64100Medium· 6.1CKAN vulnerable to fixed session IDs
CKAN vulnerable to fixed session IDs
CVE-2025-11374Medium· 6.5github.com/hashicorp/consul: Consul's KV endpoint is vulnerable to denial of service (CVE-2025-11374)
A denial of service flaw has been discovered in Hashicorp Consul. The key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation.
MAL-2025-191876NoneMalicious code in speedd-testing-bot (PyPI)
Malicious code in speedd-testing-bot (PyPI)
CVE-2025-62727High· 7.5PoCStarlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
CVE-2025-61385Highpg8000 SQL injection vulnerability via a specially crafted Python list input
pg8000 SQL injection vulnerability via a specially crafted Python list input
CVE-2025-10282Medium· 4.7BBOT's gitlab.py exposes globally configured "gitlab" API key
BBOT's gitlab.py exposes globally configured "gitlab" API key
CVE-2025-8709High· 7.3LangGraph's SQLite store implementation has a SQL Injection Vulnerability
LangGraph's SQLite store implementation has a SQL Injection Vulnerability
CVE-2025-62705MediumOpenBao and Vault Leak []byte Fields in Audit Logs
OpenBao and Vault Leak []byte Fields in Audit Logs
CVE-2025-62513MediumOpenBao leaks HTTPRawBody in Audit Logs
OpenBao leaks HTTPRawBody in Audit Logs
CVE-2025-62707Mediumpypdf possibly loops infinitely when reading DCT inline images without EOF marker
pypdf possibly loops infinitely when reading DCT inline images without EOF marker
CVE-2025-62611Highaiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
CVE-2025-62708Mediumpypdf can exhaust RAM via manipulated LZWDecode streams
pypdf can exhaust RAM via manipulated LZWDecode streams
CVE-2025-11844Medium· 5.4PoCHugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function
Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function
CVE-2025-62607Medium· 5.3Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
CVE-2025-59043High· 7.5OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
CVE-2025-11849Critical· 9.3Mammoth is vulnerable to Directory Traversal
Mammoth is vulnerable to Directory Traversal
CVE-2025-62375Mediumgo-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents
go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents
CVE-2025-62379Low· 3.1reflex-dev/reflex has an Open Redirect vulnerability
reflex-dev/reflex has an Open Redirect vulnerability
CVE-2025-62172HighHome Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
CVE-2025-7707High· 7.1llama-index has Insecure Temporary File
llama-index has Insecure Temporary File
CVE-2025-11579Medium· 5.3PoCgithub.com/nwaples/rardecode: RarDecode Out Of Memory Crash (CVE-2025-11579)
A memory exhaustion flaw has been discovered in the golang Rar Decode library (github.com/nwaples/rardecode). Affected versions did not limit the size of an archive and so an attacker could provide a crafted archive to a tool or service bu…
CVE-2025-59530Medium· 5.3⚖ disputedgithub.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE Frame (CVE-2025-59530)
A denial of service flaw has been discovered in the quic-go golang library. A misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. …
CVE-2025-61911Mediumpython-ldap has sanitization bypass in ldap.filter.escape_filter_chars
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
CVE-2025-61920High· 7.5Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments