VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2025-62800Medium
11mo ago

FastMCP vulnerable to reflected XSS in client's callback page

FastMCP vulnerable to reflected XSS in client's callback page

▾ Sunlitfastmcp · fastmcpEPSS 0.28%via OSV
CVE-2025-12058Medium
11mo ago

Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery

Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery

▾ Sunlitkeras · kerasEPSS 0.25%via OSV
CVE-2025-64104High· 7.3
11mo ago

LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore

LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore

▾ Twilightlanggraph-checkpoint-sqlite · langgraph-checkpoint-sqliteEPSS 0.19%via OSV
CVE-2025-11200High· 8.10day
11mo ago

MLflow Weak Password Requirements Authentication Bypass Vulnerability

MLflow Weak Password Requirements Authentication Bypass Vulnerability

▾ Abyssalmlflow · mlflowEPSS 1.4%via OSV
CVE-2025-11201High· 8.10dayPoC
11mo ago

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability

▾ Abyssalmlflow · mlflowEPSS 26%via OSV
CVE-2025-54384Medium· 6.3
11mo ago

CKAN vulnerable to stored XSS in resource description

CKAN vulnerable to stored XSS in resource description

▾ Sunlitckan · ckanEPSS 0.23%via OSV
CVE-2025-64100Medium· 6.1
11mo ago

CKAN vulnerable to fixed session IDs

CKAN vulnerable to fixed session IDs

▾ Sunlitckan · ckanEPSS 0.30%via OSV
CVE-2025-11374Medium· 6.5
11mo ago

github.com/hashicorp/consul: Consul's KV endpoint is vulnerable to denial of service (CVE-2025-11374)

A denial of service flaw has been discovered in Hashicorp Consul. The key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation.

▾ SunlitRed Hat · Red Hat OpenShift Dev SpacesEPSS 0.43%via CSAF
MAL-2025-191876None
11mo ago

Malicious code in speedd-testing-bot (PyPI)

Malicious code in speedd-testing-bot (PyPI)

▾ Sunlitspeedd-testing-bot · speedd-testing-botvia OSV
CVE-2025-62727High· 7.5PoC
11mo ago

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

▾ Midnightstarlette · starletteEPSS 0.68%via OSV
CVE-2025-61385High
11mo ago

pg8000 SQL injection vulnerability via a specially crafted Python list input

pg8000 SQL injection vulnerability via a specially crafted Python list input

▾ Twilightpg8000 · pg8000EPSS 0.36%via OSV
CVE-2025-10282Medium· 4.7
11mo ago

BBOT's gitlab.py exposes globally configured "gitlab" API key

BBOT's gitlab.py exposes globally configured "gitlab" API key

▾ Sunlitbbot · bbotEPSS 0.23%via OSV
CVE-2025-8709High· 7.3
11mo ago

LangGraph's SQLite store implementation has a SQL Injection Vulnerability

LangGraph's SQLite store implementation has a SQL Injection Vulnerability

▾ Twilightlanggraph-checkpoint-sqlite · langgraph-checkpoint-sqliteEPSS 0.18%via OSV
CVE-2025-62705Medium
11mo ago

OpenBao and Vault Leak []byte Fields in Audit Logs

OpenBao and Vault Leak []byte Fields in Audit Logs

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.33%via OSV
CVE-2025-62513Medium
11mo ago

OpenBao leaks HTTPRawBody in Audit Logs

OpenBao leaks HTTPRawBody in Audit Logs

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.32%via OSV
CVE-2025-62707Medium
11mo ago

pypdf possibly loops infinitely when reading DCT inline images without EOF marker

pypdf possibly loops infinitely when reading DCT inline images without EOF marker

▾ Sunlitpypdf · pypdfEPSS 0.44%via OSV
CVE-2025-62611High
11mo ago

aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server

aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server

▾ Twilightaiomysql · aiomysqlEPSS 0.39%via OSV
CVE-2025-62708Medium
11mo ago

pypdf can exhaust RAM via manipulated LZWDecode streams

pypdf can exhaust RAM via manipulated LZWDecode streams

▾ Sunlitpypdf · pypdfEPSS 0.44%via OSV
CVE-2025-11844Medium· 5.4PoC
11mo ago

Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function

Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function

▾ Twilightsmolagents · smolagentsEPSS 0.28%via OSV
CVE-2025-62607Medium· 5.3
11mo ago

Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL

Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL

▾ Sunlitnautobot-ssot · nautobot-ssotEPSS 0.29%via OSV
CVE-2025-59043High· 7.5
11mo ago

OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests

OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.69%via OSV
CVE-2025-11849Critical· 9.3
11mo ago

Mammoth is vulnerable to Directory Traversal

Mammoth is vulnerable to Directory Traversal

▾ Midnightmammoth · mammothEPSS 1.0%via OSV
CVE-2025-62375Medium
11mo ago

go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents

go-witness is Vulnerable to Improper Verification of AWS EC2 Identity Documents

▾ Sunlitin-toto · github.com/in-toto/go-witnessEPSS 0.20%via OSV
CVE-2025-62379Low· 3.1
11mo ago

reflex-dev/reflex has an Open Redirect vulnerability

reflex-dev/reflex has an Open Redirect vulnerability

▾ Sunlitreflex · reflexEPSS 0.25%via OSV
CVE-2025-62172High
11mo ago

Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name

Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name

▾ Twilighthomeassistant · homeassistantEPSS 0.42%via OSV
CVE-2025-7707High· 7.1
11mo ago

llama-index has Insecure Temporary File

llama-index has Insecure Temporary File

▾ Twilightllama-index · llama-indexEPSS 0.19%via OSV
CVE-2025-11579Medium· 5.3PoC
11mo ago

github.com/nwaples/rardecode: RarDecode Out Of Memory Crash (CVE-2025-11579)

A memory exhaustion flaw has been discovered in the golang Rar Decode library (github.com/nwaples/rardecode). Affected versions did not limit the size of an archive and so an attacker could provide a crafted archive to a tool or service bu…

▾ TwilightRed Hat · Red Hat Advanced Cluster Security 4EPSS 0.37%via CSAF
CVE-2025-59530Medium· 5.3⚖ disputed
11mo ago

github.com/quic-go/quic-go: quic-go Crash Due to Premature HANDSHAKE_DONE Frame (CVE-2025-59530)

A denial of service flaw has been discovered in the quic-go golang library. A misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. …

▾ SunlitRed Hat · Red Hat Ansible Automation Platform 2.5 for RHEL 8EPSS 0.46%via CSAF
CVE-2025-61911Medium
11mo ago

python-ldap has sanitization bypass in ldap.filter.escape_filter_chars

python-ldap has sanitization bypass in ldap.filter.escape_filter_chars

▾ Sunlitpython-ldap · python-ldapEPSS 0.32%via OSV
CVE-2025-61920High· 7.5
11mo ago

Authlib is vulnerable to Denial of Service via Oversized JOSE Segments

Authlib is vulnerable to Denial of Service via Oversized JOSE Segments

▾ Twilightauthlib · authlibEPSS 0.64%via OSV
CVEs tagged “osv” — page 102 · VulnSea