Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2025-71349MediumPicklescan has a missing detection when calling built-in python trace.Trace.run
Picklescan has a missing detection when calling built-in python trace.Trace.run
CVE-2025-71363MediumPicklescan is missing detection when calling built-in python cProfile.run
Picklescan is missing detection when calling built-in python cProfile.run
CVE-2025-71354MediumPicklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem
Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem
CVE-2025-71340MediumPicklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode
Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode
GHSA-63cx-g855-hvv4Mediummitmproxy binaries embed a vulnerable python-hyper/h2 dependency
mitmproxy binaries embed a vulnerable python-hyper/h2 dependency
CVE-2025-57804Mediumh2 allows HTTP Request Smuggling due to illegal characters in headers
h2 allows HTTP Request Smuggling due to illegal characters in headers
CVE-2025-57809High· 7.5xgrammar: XGrammar affected by Denial of Service by infinite recursion grammars (CVE-2025-57809)
A flaw was found in xgrammar. Recursive grammar definitions could trigger infinite recursion during parsing in GrammarMatcherBase::ExpandEquivalentStackElements, leading to unbounded stack growth and a segmentation fault. This vulnerabilit…
CVE-2025-57760High· 8.8Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
CVE-2025-71370High· 8.1Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
CVE-2025-71350MediumPicklescan missing detection when calling pytorch function torch.utils.collect_env.run
Picklescan missing detection when calling pytorch function torch.utils.collect_env.run
CVE-2025-57751HighDenial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
CVE-2025-9141High· 8.8vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
CVE-2025-55214MediumCopier's safe template has filesystem write access outside destination path
Copier's safe template has filesystem write access outside destination path
CVE-2025-55201HighCopier's safe template has arbitrary filesystem read/write access
Copier's safe template has arbitrary filesystem read/write access
CVE-2025-55675MediumApache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
CVE-2025-55674MediumApache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
CVE-2025-55672MediumApache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
CVE-2025-55673MediumApache Superset data query improperly discloses database schema information to low-privileged guest user
Apache Superset data query improperly discloses database schema information to low-privileged guest user
CVE-2025-54791Medium· 5.3OMERO.web displays unecessary user information when requesting password reset
OMERO.web displays unecessary user information when requesting password reset
CVE-2025-55197MediumPyPDF's Manipulated FlateDecode streams can exhaust RAM
PyPDF's Manipulated FlateDecode streams can exhaust RAM
CVE-2025-5187Medium· 6.7kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)
A vulnerability was found in the kube-apiserver's NodeRestriction admission controller, where node users can delete their corresponding node object by setting their own OwnerReference to a cluster-scoped resource. This flaw allows an attac…
CVE-2025-8747High· 8.8Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-55156HighPyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
CVE-2025-71325HighPicklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
CVE-2025-55149MediumTinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)
TinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)
CVE-2025-54997Critical· 9.1Privileged OpenBao Operator May Execute Code on the Underlying Host
Privileged OpenBao Operator May Execute Code on the Underlying Host
CVE-2025-54996High· 7.2OpenBao Root Namespace Operator May Elevate Token Privileges
OpenBao Root Namespace Operator May Elevate Token Privileges
CVE-2025-55003Medium· 5.7OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
CVE-2025-54998Medium· 5.3OpenBao Userpass and LDAP User Lockout Bypass
OpenBao Userpass and LDAP User Lockout Bypass
CVE-2025-54999Low· 3.7OpenBao has a Timing Side-Channel in the Userpass Auth Method
OpenBao has a Timing Side-Channel in the Userpass Auth Method