Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2025-54999Low· 3.7OpenBao has a Timing Side-Channel in the Userpass Auth Method
OpenBao has a Timing Side-Channel in the Userpass Auth Method
CVE-2025-55000Medium· 6.5OpenBao TOTP Secrets Engine Code Reuse
OpenBao TOTP Secrets Engine Code Reuse
CVE-2025-55001Medium· 6.5OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
CVE-2025-54952MediumExecuTorch integer overflow vulnerability leads to code execution
ExecuTorch integer overflow vulnerability leads to code execution
CVE-2025-54368Mediumuv allows ZIP payload obfuscation through parsing differentials
uv allows ZIP payload obfuscation through parsing differentials
CVE-2025-54886High· 8.4SKOPS Card.get_model happily allows arbitrary code execution
SKOPS Card.get_model happily allows arbitrary code execution
CVE-2025-6013Medium· 6.5HashiCorp Vault ldap auth method may not have correctly enforced MFA
HashiCorp Vault ldap auth method may not have correctly enforced MFA
CVE-2025-5197Medium· 5.3Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2025-54802Critical· 9.8pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
CVE-2025-54796High· 7.5copyparty allows Regex Denial of Service (ReDoS) in the upload listing
copyparty allows Regex Denial of Service (ReDoS) in the upload listing
CVE-2025-5999High· 7.2Hashicorp Vault has Privilege Escalation Vulnerability
Hashicorp Vault has Privilege Escalation Vulnerability
CVE-2025-6037Medium· 6.8Hashicorp Vault has Incorrect Validation for Non-CA Certificates
Hashicorp Vault has Incorrect Validation for Non-CA Certificates
GHSA-jxr6-qrxx-2ph2Criticalnum2words subjected to phishing attack, two versions published containing malware
num2words subjected to phishing attack, two versions published containing malware
MAL-2025-6794NoneMalicious code in num2words (PyPI)
Malicious code in num2words (PyPI)
CVE-2025-48074MediumOpenEXR Out-Of-Memory via Unbounded File Header Values
OpenEXR Out-Of-Memory via Unbounded File Header Values
CVE-2025-53009MediumMaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit
MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit
CVE-2025-48073MediumOpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode
OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode
CVE-2025-53012MediumMaterialX Lack of MTLX Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion
MaterialX Lack of MTLX Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion
CVE-2025-48071High· 7.8OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size
OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size
CVE-2025-50460Critical· 9.8PoCMS SWIFT Remote Code Execution via unsafe PyYAML deserialization
MS SWIFT Remote Code Execution via unsafe PyYAML deserialization
CVE-2025-54589Medium· 6.3PoCcopyparty Reflected XSS via Filter Parameter
copyparty Reflected XSS via Filter Parameter
CVE-2025-53011LowMaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput
MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput
CVE-2025-41419MediumMS SWIFT WEB-UI RCE Vulnerability
MS SWIFT WEB-UI RCE Vulnerability
CVE-2025-48072MediumOpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute
OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute
CVE-2025-53010LowMaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return
MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return
CVE-2025-54576High· 7.4github.com/oauth2-proxy/oauth2-proxy: OAuth2-Proxy authentication bypass (CVE-2025-54576)
An authentication bypass flaw was found in the OAuth2-Proxy project. This bypass affects systems that have configured their deployment to skip authentication on endpoints that match a deployment-defined regular expression. HTTP parameters …
CVE-2021-21411Medium· 5.5OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
CVE-2025-54381Critical· 9.9PoCBentoML SSRF Vulnerability in File Upload Processing
BentoML SSRF Vulnerability in File Upload Processing
CVE-2025-54433HighBugsink path traversal via event_id in ingestion
Bugsink path traversal via event_id in ingestion
CVE-2025-54423Medium· 5.4copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata
copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata