VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2025-59842Low
1y ago

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute

▾ Sunlitjupyterlab · jupyterlabEPSS 0.24%via OSV
CVE-2025-10952Medium· 5.3PoC
1y ago

ml-logger file handler allows reading arbitrary files

ml-logger file handler allows reading arbitrary files

▾ Twilightml-logger · ml-loggerEPSS 0.45%via OSV
CVE-2025-10951High· 7.3PoC
1y ago

ml-logger has path traversal in the file argument

ml-logger has path traversal in the file argument

▾ Midnightml-logger · ml-loggerEPSS 0.61%via OSV
CVE-2025-10950Medium· 6.3
1y ago

ml-logger deserialization vulnerability

ml-logger deserialization vulnerability

▾ Sunlitml-logger · ml-loggerEPSS 0.31%via OSV
CVE-2025-55178Medium· 5.3
1y ago

Llama Stack could potentially allow for remote code execution

Llama Stack could potentially allow for remote code execution

▾ Sunlitllama-stack · llama-stackEPSS 0.50%via OSV
CVE-2025-8869Medium
1y ago

When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known…

When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known…

▾ Sunlitpip · pipEPSS 0.47%via NVD
CVE-2025-6921Medium· 5.3
1y ago

Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer

Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer

▾ Sunlittransformers · transformersEPSS 0.51%via OSV
CVE-2025-59420High· 7.5
1y ago

authlib: Authlib RFC violation (CVE-2025-59420)

Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 “must‑understand” semantics. An attacker can craft a signed token with a critical header (for example, bork or cnf) that s…

▾ TwilightRed Hat · Red Hat Quay 3.10EPSS 0.26%via CSAF
CVE-2025-9905High
1y ago

The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file i…

The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.

▾ Twilightkeras · kerasEPSS 0.22%via OSV
CVE-2025-9906High· 7.3
1y ago

Keras is vulnerable to Deserialization of Untrusted Data

Keras is vulnerable to Deserialization of Untrusted Data

▾ Twilightkeras · kerasEPSS 0.20%via OSV
CVE-2025-47906Medium· 6.5
1y ago

os/exec: Unexpected paths returned from LookPath in os/exec (CVE-2025-47906)

A path handling flaw has been discovered in the os/exec go package. If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result i…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2025-59341HighPoC
1y ago

esm.sh has File Inclusion issue

esm.sh has File Inclusion issue

▾ Midnightesm-dev · github.com/esm-dev/esm.shEPSS 1.6%via OSV
CVE-2025-59376Medium· 5.3PoC
1y ago

mcp-kubernetes-server has a Command Injection vulnerability

mcp-kubernetes-server has a Command Injection vulnerability

▾ Twilightmcp-kubernetes-server · mcp-kubernetes-serverEPSS 0.30%via OSV
CVE-2025-6051Medium· 5.3
1y ago

Hugging Face Transformers library has Regular Expression Denial of Service

Hugging Face Transformers library has Regular Expression Denial of Service

▾ Sunlittransformers · transformersEPSS 0.38%via OSV
CVE-2025-6638Medium· 5.3
1y ago

Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer

Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer

▾ Sunlittransformers · transformersEPSS 0.53%via OSV
CVE-2025-10193High
1y ago

Neo4j Cypher MCP server is vulnerable to DNS rebinding

Neo4j Cypher MCP server is vulnerable to DNS rebinding

▾ Twilightmcp-neo4j-cypher · mcp-neo4j-cypherEPSS 0.22%via OSV
CVE-2025-58065Medium· 6.5
1y ago

Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods

Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods

▾ Sunlitflask-appbuilder · flask-appbuilderEPSS 0.40%via OSV
CVE-2025-59036Medium· 5.5
1y ago

Infrahub: Deleted and expired API tokens can still authenticate

Infrahub: Deleted and expired API tokens can still authenticate

▾ Sunlitinfrahub-server · infrahub-serverEPSS 0.19%via OSV
CVE-2025-59042High
1y ago

PyInstaller has local privilege escalation vulnerability

PyInstaller has local privilege escalation vulnerability

▾ Twilightpyinstaller · pyinstallerEPSS 0.13%via OSV
CVE-2025-11059High
1y ago

xml2rfc is vulnerable to arbitrary file reads through prepped files

xml2rfc is vulnerable to arbitrary file reads through prepped files

▾ Twilightxml2rfc · xml2rfcvia OSV
CVE-2025-59035Medium· 4.6
1y ago

Indico vulnerable to Cross-Site Scripting via LaTeX math code

Indico vulnerable to Cross-Site Scripting via LaTeX math code

▾ Sunlitindico · indicoEPSS 0.20%via OSV
CVE-2025-59034Medium· 4.3
1y ago

Indico may disclose unauthorized user details access via legacy API

Indico may disclose unauthorized user details access via legacy API

▾ Sunlitindico · indicoEPSS 0.25%via OSV
CVE-2025-58753Medium
1y ago

copyparty: Sharing a single file does not fully restrict access to other files in source folder

copyparty: Sharing a single file does not fully restrict access to other files in source folder

▾ Sunlitcopyparty · copypartyEPSS 0.38%via OSV
CVE-2025-10164High· 7.3
1y ago

SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor

SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor

▾ Twilightsglang · sglangEPSS 0.40%via OSV
CVE-2025-58180High· 8.8PoC
1y ago

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

▾ Midnightoctoprint · octoprintEPSS 21%via OSV
CVE-2025-57833High· 7.1PoC
1y ago

Django is subject to SQL injection through its column aliases

Django is subject to SQL injection through its column aliases

▾ Midnightdjango · djangoEPSS 17%via OSV
CVE-2025-57766Medium· 4.8
1y ago

Fides' Admin UI User Password Change Does Not Invalidate Current Session

Fides' Admin UI User Password Change Does Not Invalidate Current Session

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.30%via OSV
CVE-2025-57817High· 7.2
1y ago

Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation

Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.42%via OSV
CVE-2025-57816High· 7.5
1y ago

Fides Webserver API Rate Limiting Vulnerability in Proxied Environments

Fides Webserver API Rate Limiting Vulnerability in Proxied Environments

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.43%via OSV
CVE-2025-57815Medium· 6.5
1y ago

Fides has a Lack of Brute-Force Protections on Authentication Endpoints

Fides has a Lack of Brute-Force Protections on Authentication Endpoints

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.29%via OSV
CVEs tagged “osv” — page 104 · VulnSea