Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2025-59842LowJupyterLab LaTeX typesetter links did not enforce `noopener` attribute
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
CVE-2025-10952Medium· 5.3PoCml-logger file handler allows reading arbitrary files
ml-logger file handler allows reading arbitrary files
CVE-2025-10951High· 7.3PoCml-logger has path traversal in the file argument
ml-logger has path traversal in the file argument
CVE-2025-10950Medium· 6.3ml-logger deserialization vulnerability
ml-logger deserialization vulnerability
CVE-2025-55178Medium· 5.3Llama Stack could potentially allow for remote code execution
Llama Stack could potentially allow for remote code execution
CVE-2025-8869MediumWhen extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known…
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known…
CVE-2025-6921Medium· 5.3Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
CVE-2025-59420High· 7.5authlib: Authlib RFC violation (CVE-2025-59420)
Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 “must‑understand” semantics. An attacker can craft a signed token with a critical header (for example, bork or cnf) that s…
CVE-2025-9905HighThe Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file i…
The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
CVE-2025-9906High· 7.3Keras is vulnerable to Deserialization of Untrusted Data
Keras is vulnerable to Deserialization of Untrusted Data
CVE-2025-47906Medium· 6.5os/exec: Unexpected paths returned from LookPath in os/exec (CVE-2025-47906)
A path handling flaw has been discovered in the os/exec go package. If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result i…
CVE-2025-59341HighPoCesm.sh has File Inclusion issue
esm.sh has File Inclusion issue
CVE-2025-59376Medium· 5.3PoCmcp-kubernetes-server has a Command Injection vulnerability
mcp-kubernetes-server has a Command Injection vulnerability
CVE-2025-6051Medium· 5.3Hugging Face Transformers library has Regular Expression Denial of Service
Hugging Face Transformers library has Regular Expression Denial of Service
CVE-2025-6638Medium· 5.3Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
CVE-2025-10193HighNeo4j Cypher MCP server is vulnerable to DNS rebinding
Neo4j Cypher MCP server is vulnerable to DNS rebinding
CVE-2025-58065Medium· 6.5Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods
Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods
CVE-2025-59036Medium· 5.5Infrahub: Deleted and expired API tokens can still authenticate
Infrahub: Deleted and expired API tokens can still authenticate
CVE-2025-59042HighPyInstaller has local privilege escalation vulnerability
PyInstaller has local privilege escalation vulnerability
CVE-2025-11059Highxml2rfc is vulnerable to arbitrary file reads through prepped files
xml2rfc is vulnerable to arbitrary file reads through prepped files
CVE-2025-59035Medium· 4.6Indico vulnerable to Cross-Site Scripting via LaTeX math code
Indico vulnerable to Cross-Site Scripting via LaTeX math code
CVE-2025-59034Medium· 4.3Indico may disclose unauthorized user details access via legacy API
Indico may disclose unauthorized user details access via legacy API
CVE-2025-58753Mediumcopyparty: Sharing a single file does not fully restrict access to other files in source folder
copyparty: Sharing a single file does not fully restrict access to other files in source folder
CVE-2025-10164High· 7.3SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
CVE-2025-58180High· 8.8PoCOctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
CVE-2025-57833High· 7.1PoCDjango is subject to SQL injection through its column aliases
Django is subject to SQL injection through its column aliases
CVE-2025-57766Medium· 4.8Fides' Admin UI User Password Change Does Not Invalidate Current Session
Fides' Admin UI User Password Change Does Not Invalidate Current Session
CVE-2025-57817High· 7.2Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation
Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation
CVE-2025-57816High· 7.5Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
CVE-2025-57815Medium· 6.5Fides has a Lack of Brute-Force Protections on Authentication Endpoints
Fides has a Lack of Brute-Force Protections on Authentication Endpoints