Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2025-61912Mediumpython-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
CVE-2025-62706Medium· 6.5Authlib : JWE zip=DEF decompression bomb enables DoS
Authlib : JWE zip=DEF decompression bomb enables DoS
CVE-2025-61783MediumPython Social Auth - Django has unsafe account association
Python Social Auth - Django has unsafe account association
CVE-2025-61773High· 8.1pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
CVE-2025-10281Medium· 4.7BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
CVE-2025-61672MediumSynapse's invalid device keys degrade federation functionality
Synapse's invalid device keys degrade federation functionality
CVE-2025-61670Low· 3.3Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref`…
Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref` or `externref` WebAssembly values. This is caused by a regression introduced during the development…
CVE-2025-59425High· 7.5vllm: Timing Attack in vLLM API Token Verification Leading to Authentication Bypass (CVE-2025-59425)
A flaw was found in vLLM’s API token authentication logic, where token comparisons were not performed in constant time. This weakness could allow an attacker to exploit timing differences to guess valid tokens and bypass authentication.
CVE-2025-61765Medium· 6.4PoCpython-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server depl…
python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments
CVE-2025-61620Medium· 6.5vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
CVE-2025-61784High· 7.6LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities
LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities
CVE-2025-6242High· 7.1vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
CVE-2025-6985High· 7.5LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing
LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing
CVE-2025-59152High· 7.5Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
CVE-2025-8406Medium· 6.3ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
CVE-2025-8917Medium· 5.8clearml is vulnerable to Path Traversal through its `safe_extract` function
clearml is vulnerable to Path Traversal through its `safe_extract` function
CVE-2025-53354Medium· 6.1NiceGUI has a Reflected XSS
NiceGUI has a Reflected XSS
CVE-2025-54287Medium· 6.5Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns
Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns
CVE-2025-54286High· 8.3Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
CVE-2025-54288Medium· 4.1Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
CVE-2025-54293Medium· 6.5Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
CVE-2025-54289Medium· 6.8Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
CVE-2025-61677Low· 2.5DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables
DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables
GHSA-xjv7-6w92-42r7Mediummarimo vulnerable to proxy abuse of /mpl/{port}/
marimo vulnerable to proxy abuse of /mpl/{port}/
CVE-2025-61587Medium· 6.1Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website…
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL…
CVE-2025-59682High· 8.8⚖ disputeddjango: Potential partial directory-traversal via archive.extract() (CVE-2025-59682)
A flaw was found in Django. The django.utils.archive.extract() function, used by startapp --templateand startproject --template, allowed partial directory-traversal via an archive with file paths sharing a common prefix with the target dir…
CVE-2025-57275Medium· 5.5SPDK is vulnerable to buffer overflow in the NVMe-oF target component
SPDK is vulnerable to buffer overflow in the NVMe-oF target component
CVE-2025-55191Medium· 4.3⚖ disputedgithub.com/argoproj/argo-cd/v2: github.com/argoproj/argo-cd/v3: Argo CD race condition leading to crash (CVE-2025-55191)
A race condition has been discovered in the Argo CD GitOps tool. This race condition is located in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same…
CVE-2025-59940Medium· 6.5mkdocs-include-markdown-plugin: mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders (C…
There is an improper input validation flaw in the python `mkdocs-include-markdown-plugin` package. Under certain conditions placeholders are not properly validated and may collide with other data elements resulting in inconsistent output.
CVE-2025-7647High· 7.3llama-index-core insecurely handles temporary files
llama-index-core insecurely handles temporary files