VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2025-71349Medium
1y ago

Picklescan has a missing detection when calling built-in python trace.Trace.run

Picklescan has a missing detection when calling built-in python trace.Trace.run

▾ Sunlitpicklescan · picklescanEPSS 0.61%via OSV
CVE-2025-71363Medium
1y ago

Picklescan is missing detection when calling built-in python cProfile.run

Picklescan is missing detection when calling built-in python cProfile.run

▾ Sunlitpicklescan · picklescanEPSS 0.64%via OSV
CVE-2025-71354Medium
1y ago

Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem

Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem

▾ Sunlitpicklescan · picklescanEPSS 0.45%via OSV
CVE-2025-71340Medium
1y ago

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode

▾ Sunlitpicklescan · picklescanEPSS 0.43%via OSV
GHSA-63cx-g855-hvv4Medium
1y ago

mitmproxy binaries embed a vulnerable python-hyper/h2 dependency

mitmproxy binaries embed a vulnerable python-hyper/h2 dependency

▾ Sunlitmitmproxy · mitmproxyvia OSV
CVE-2025-57804Medium
1y ago

h2 allows HTTP Request Smuggling due to illegal characters in headers

h2 allows HTTP Request Smuggling due to illegal characters in headers

▾ Sunlith2 · h2EPSS 1.7%via OSV
CVE-2025-57809High· 7.5
1y ago

xgrammar: XGrammar affected by Denial of Service by infinite recursion grammars (CVE-2025-57809)

A flaw was found in xgrammar. Recursive grammar definitions could trigger infinite recursion during parsing in GrammarMatcherBase::ExpandEquivalentStackElements, leading to unbounded stack growth and a segmentation fault. This vulnerabilit…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI 1.5EPSS 0.47%via CSAF
CVE-2025-57760High· 8.8
1y ago

Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)

Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)

▾ Twilightlangflow · langflowEPSS 0.52%via OSV
CVE-2025-71370High· 8.1
1y ago

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

▾ Twilightpicklescan · picklescanEPSS 0.54%via OSV
CVE-2025-71350Medium
1y ago

Picklescan missing detection when calling pytorch function torch.utils.collect_env.run

Picklescan missing detection when calling pytorch function torch.utils.collect_env.run

▾ Sunlitpicklescan · picklescanEPSS 0.43%via OSV
CVE-2025-57751High
1y ago

Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs

Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs

▾ Twilightpyload-ng · pyload-ngEPSS 0.33%via OSV
CVE-2025-9141High· 8.8
1y ago

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

▾ Twilightvllm · vllmvia OSV
CVE-2025-55214Medium
1y ago

Copier's safe template has filesystem write access outside destination path

Copier's safe template has filesystem write access outside destination path

▾ Sunlitcopier · copierEPSS 0.26%via OSV
CVE-2025-55201High
1y ago

Copier's safe template has arbitrary filesystem read/write access

Copier's safe template has arbitrary filesystem read/write access

▾ Twilightcopier · copierEPSS 0.26%via OSV
CVE-2025-55675Medium
1y ago

Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access

Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access

▾ Sunlitapache-superset · apache-supersetEPSS 0.53%via OSV
CVE-2025-55674Medium
1y ago

Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions

Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions

▾ Sunlitapache-superset · apache-supersetEPSS 0.69%via OSV
CVE-2025-55672Medium
1y ago

Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability

Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 0.74%via OSV
CVE-2025-55673Medium
1y ago

Apache Superset data query improperly discloses database schema information to low-privileged guest user

Apache Superset data query improperly discloses database schema information to low-privileged guest user

▾ Sunlitapache-superset · apache-supersetEPSS 0.57%via OSV
CVE-2025-54791Medium· 5.3
1y ago

OMERO.web displays unecessary user information when requesting password reset

OMERO.web displays unecessary user information when requesting password reset

▾ Sunlitomero-web · omero-webEPSS 0.26%via OSV
CVE-2025-55197Medium
1y ago

PyPDF's Manipulated FlateDecode streams can exhaust RAM

PyPDF's Manipulated FlateDecode streams can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.46%via OSV
CVE-2025-5187Medium· 6.7
1y ago

kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)

A vulnerability was found in the kube-apiserver's NodeRestriction admission controller, where node users can delete their corresponding node object by setting their own OwnerReference to a cluster-scoped resource. This flaw allows an attac…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.55%via CSAF
CVE-2025-8747High· 8.8
1y ago

Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality

Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality

▾ Twilightkeras · kerasEPSS 0.12%via OSV
CVE-2025-55156High
1y ago

PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter

PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter

▾ Twilightpyload-ng · pyload-ngEPSS 0.33%via OSV
CVE-2025-71325High
1y ago

Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

▾ Twilightpicklescan · picklescanEPSS 0.47%via OSV
CVE-2025-55149Medium
1y ago

TinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)

TinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)

▾ Sunlittiny-scientist · tiny-scientistEPSS 0.65%via OSV
CVE-2025-54997Critical· 9.1
1y ago

Privileged OpenBao Operator May Execute Code on the Underlying Host

Privileged OpenBao Operator May Execute Code on the Underlying Host

▾ Midnightopenbao · github.com/openbao/openbaoEPSS 0.38%via OSV
CVE-2025-54996High· 7.2
1y ago

OpenBao Root Namespace Operator May Elevate Token Privileges

OpenBao Root Namespace Operator May Elevate Token Privileges

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.32%via OSV
CVE-2025-55003Medium· 5.7
1y ago

OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse

OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.24%via OSV
CVE-2025-54998Medium· 5.3
1y ago

OpenBao Userpass and LDAP User Lockout Bypass

OpenBao Userpass and LDAP User Lockout Bypass

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.21%via OSV
CVE-2025-54999Low· 3.7
1y ago

OpenBao has a Timing Side-Channel in the Userpass Auth Method

OpenBao has a Timing Side-Channel in the Userpass Auth Method

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.19%via OSV
CVEs tagged “osv” — page 106 · VulnSea