VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2025-61912Medium
11mo ago

python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination

python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination

▾ Sunlitpython-ldap · python-ldapEPSS 0.46%via OSV
CVE-2025-62706Medium· 6.5
11mo ago

Authlib : JWE zip=DEF decompression bomb enables DoS

Authlib : JWE zip=DEF decompression bomb enables DoS

▾ Sunlitauthlib · authlibEPSS 0.46%via OSV
CVE-2025-61783Medium
11mo ago

Python Social Auth - Django has unsafe account association

Python Social Auth - Django has unsafe account association

▾ Sunlitsocial-auth-app-django · social-auth-app-djangoEPSS 0.42%via OSV
CVE-2025-61773High· 8.1
11mo ago

pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters

pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters

▾ Twilightpyload-ng · pyload-ngEPSS 0.41%via OSV
CVE-2025-10281Medium· 4.7
11mo ago

BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver

BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver

▾ Sunlitbbot · bbotEPSS 0.23%via OSV
CVE-2025-61672Medium
11mo ago

Synapse's invalid device keys degrade federation functionality

Synapse's invalid device keys degrade federation functionality

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.47%via OSV
CVE-2025-61670Low· 3.3
11mo ago

Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref`…

Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref` or `externref` WebAssembly values. This is caused by a regression introduced during the development…

▾ Sunlitwasmtime-bin · wasmtime-binEPSS 0.19%via OSV
CVE-2025-59425High· 7.5
11mo ago

vllm: Timing Attack in vLLM API Token Verification Leading to Authentication Bypass (CVE-2025-59425)

A flaw was found in vLLM’s API token authentication logic, where token comparisons were not performed in constant time. This weakness could allow an attacker to exploit timing differences to guess valid tokens and bypass authentication.

▾ TwilightRed Hat · Red Hat OpenShift AI 3.3EPSS 0.57%via CSAF
CVE-2025-61765Medium· 6.4PoC
11mo ago

python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server depl…

python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments

▾ Twilightpython-socketio · python-socketioEPSS 0.48%via OSV
CVE-2025-61620Medium· 6.5
11mo ago

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server

▾ Sunlitvllm · vllmvia OSV
CVE-2025-61784High· 7.6
11mo ago

LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities

LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities

▾ Twilightllamafactory · llamafactoryEPSS 0.38%via OSV
CVE-2025-6242High· 7.1
11mo ago

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

▾ Twilightvllm · vllmEPSS 0.25%via OSV
CVE-2025-6985High· 7.5
11mo ago

LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing

LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing

▾ Twilightlangchain-text-splitters · langchain-text-splittersEPSS 0.51%via OSV
CVE-2025-59152High· 7.5
11mo ago

Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion

Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion

▾ Twilightlitestar · litestarEPSS 0.48%via OSV
CVE-2025-8406Medium· 6.3
12mo ago

ZenML is vulnerable to Path Traversal through its `PathMaterializer` class

ZenML is vulnerable to Path Traversal through its `PathMaterializer` class

▾ Sunlitzenml · zenmlEPSS 0.36%via OSV
CVE-2025-8917Medium· 5.8
12mo ago

clearml is vulnerable to Path Traversal through its `safe_extract` function

clearml is vulnerable to Path Traversal through its `safe_extract` function

▾ Sunlitclearml · clearmlEPSS 0.30%via OSV
CVE-2025-53354Medium· 6.1
12mo ago

NiceGUI has a Reflected XSS

NiceGUI has a Reflected XSS

▾ Sunlitnicegui · niceguiEPSS 0.20%via OSV
CVE-2025-54287Medium· 6.5
12mo ago

Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns

Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns

▾ Sunlitlxc · github.com/lxc/lxdEPSS 0.37%via OSV
CVE-2025-54286High· 8.3
12mo ago

Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI

Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI

▾ Twilightcanonical · github.com/canonical/lxdEPSS 0.13%via OSV
CVE-2025-54288Medium· 4.1
12mo ago

Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server

Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server

▾ Sunlitcanonical · github.com/canonical/lxdEPSS 0.35%via OSV
CVE-2025-54293Medium· 6.5
12mo ago

Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function

Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function

▾ Sunlitcanonical · github.com/canonical/lxdEPSS 0.58%via OSV
CVE-2025-54289Medium· 6.8
12mo ago

Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API

Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API

▾ Sunlitcanonical · github.com/canonical/lxdEPSS 0.21%via OSV
CVE-2025-61677Low· 2.5
12mo ago

DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables

DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables

▾ Sunlitdatachain · datachainEPSS 0.16%via OSV
GHSA-xjv7-6w92-42r7Medium
12mo ago

marimo vulnerable to proxy abuse of /mpl/{port}/

marimo vulnerable to proxy abuse of /mpl/{port}/

▾ Sunlitmarimo · marimovia OSV
CVE-2025-61587Medium· 6.1
12mo ago

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website…

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL…

▾ Sunlitweblate · weblateEPSS 0.39%via OSV
CVE-2025-59682High· 8.8⚖ disputed
12mo ago

django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682)

A flaw was found in Django. The django.utils.archive.extract() function, used by startapp --templateand startproject --template, allowed partial directory-traversal via an archive with file paths sharing a common prefix with the target dir…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2.5 for RHEL 8EPSS 0.91%via CSAF
CVE-2025-57275Medium· 5.5
12mo ago

SPDK is vulnerable to buffer overflow in the NVMe-oF target component

SPDK is vulnerable to buffer overflow in the NVMe-oF target component

▾ Sunlitspdk · spdkEPSS 0.33%via OSV
CVE-2025-55191Medium· 4.3⚖ disputed
1y ago

github.com/argoproj/argo-cd/v2: github.com/argoproj/argo-cd/v3: Argo CD race condition leading to crash (CVE-2025-55191)

A race condition has been discovered in the Argo CD GitOps tool. This race condition is located in the repository credentials handler that can cause the Argo CD server to panic and crash when concurrent operations are performed on the same…

▾ SunlitRed Hat · Red Hat OpenShift GitOps 1.16EPSS 0.47%via CSAF
CVE-2025-59940Medium· 6.5
1y ago

mkdocs-include-markdown-plugin: mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders (C…

There is an improper input validation flaw in the python `mkdocs-include-markdown-plugin` package. Under certain conditions placeholders are not properly validated and may collide with other data elements resulting in inconsistent output.

▾ SunlitRed Hat · Multicluster Engine for KubernetesEPSS 0.34%via CSAF
CVE-2025-7647High· 7.3
1y ago

llama-index-core insecurely handles temporary files

llama-index-core insecurely handles temporary files

▾ Twilightllama-index-core · llama-index-coreEPSS 0.15%via OSV
CVEs tagged “osv” — page 103 · VulnSea