VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2025-54999Low· 3.7
1y ago

OpenBao has a Timing Side-Channel in the Userpass Auth Method

OpenBao has a Timing Side-Channel in the Userpass Auth Method

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.19%via OSV
CVE-2025-55000Medium· 6.5
1y ago

OpenBao TOTP Secrets Engine Code Reuse

OpenBao TOTP Secrets Engine Code Reuse

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.21%via OSV
CVE-2025-55001Medium· 6.5
1y ago

OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias

OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.22%via OSV
CVE-2025-54952Medium
1y ago

ExecuTorch integer overflow vulnerability leads to code execution

ExecuTorch integer overflow vulnerability leads to code execution

▾ Sunlitexecutorch · executorchEPSS 0.61%via OSV
CVE-2025-54368Medium
1y ago

uv allows ZIP payload obfuscation through parsing differentials

uv allows ZIP payload obfuscation through parsing differentials

▾ Sunlituv · uvEPSS 0.20%via OSV
CVE-2025-54886High· 8.4
1y ago

SKOPS Card.get_model happily allows arbitrary code execution

SKOPS Card.get_model happily allows arbitrary code execution

▾ Twilightskops · skopsEPSS 0.22%via OSV
CVE-2025-6013Medium· 6.5
1y ago

HashiCorp Vault ldap auth method may not have correctly enforced MFA

HashiCorp Vault ldap auth method may not have correctly enforced MFA

▾ Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.50%via OSV
CVE-2025-5197Medium· 5.3
1y ago

Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability

Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability

▾ Sunlittransformers · transformersEPSS 0.40%via OSV
CVE-2025-54802Critical· 9.8
1y ago

pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)

pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)

▾ Midnightpyload-ng · pyload-ngEPSS 1.2%via OSV
CVE-2025-54796High· 7.5
1y ago

copyparty allows Regex Denial of Service (ReDoS) in the upload listing

copyparty allows Regex Denial of Service (ReDoS) in the upload listing

▾ Twilightcopyparty · copypartyEPSS 0.42%via OSV
CVE-2025-5999High· 7.2
1y ago

Hashicorp Vault has Privilege Escalation Vulnerability

Hashicorp Vault has Privilege Escalation Vulnerability

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.51%via OSV
CVE-2025-6037Medium· 6.8
1y ago

Hashicorp Vault has Incorrect Validation for Non-CA Certificates

Hashicorp Vault has Incorrect Validation for Non-CA Certificates

▾ Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.25%via OSV
GHSA-jxr6-qrxx-2ph2Critical
1y ago

num2words subjected to phishing attack, two versions published containing malware

num2words subjected to phishing attack, two versions published containing malware

▾ Midnightnum2words · num2wordsvia OSV
MAL-2025-6794None
1y ago

Malicious code in num2words (PyPI)

Malicious code in num2words (PyPI)

▾ Sunlitnum2words · num2wordsvia OSV
CVE-2025-48074Medium
1y ago

OpenEXR Out-Of-Memory via Unbounded File Header Values

OpenEXR Out-Of-Memory via Unbounded File Header Values

▾ Sunlitopenexr · openexrEPSS 0.26%via OSV
CVE-2025-53009Medium
1y ago

MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit

MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit

▾ Sunlitmaterialx · materialxEPSS 0.60%via OSV
CVE-2025-48073Medium
1y ago

OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode

OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode

▾ Sunlitopenexr · openexrEPSS 0.20%via OSV
CVE-2025-53012Medium
1y ago

MaterialX Lack of MTLX Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion

MaterialX Lack of MTLX Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion

▾ Sunlitmaterialx · materialxEPSS 0.82%via OSV
CVE-2025-48071High· 7.8
1y ago

OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size

OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size

▾ Twilightopenexr · openexrEPSS 0.31%via OSV
CVE-2025-50460Critical· 9.8PoC
1y ago

MS SWIFT Remote Code Execution via unsafe PyYAML deserialization

MS SWIFT Remote Code Execution via unsafe PyYAML deserialization

▾ Abyssalms-swift · ms-swiftEPSS 2.5%via OSV
CVE-2025-54589Medium· 6.3PoC
1y ago

copyparty Reflected XSS via Filter Parameter

copyparty Reflected XSS via Filter Parameter

▾ Twilightcopyparty · copypartyEPSS 2.4%via OSV
CVE-2025-53011Low
1y ago

MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput

MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput

▾ Sunlitmaterialx · materialxEPSS 0.52%via OSV
CVE-2025-41419Medium
1y ago

MS SWIFT WEB-UI RCE Vulnerability

MS SWIFT WEB-UI RCE Vulnerability

▾ Sunlitms-swift · ms-swiftvia OSV
CVE-2025-48072Medium
1y ago

OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute

OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute

▾ Sunlitopenexr · openexrEPSS 0.49%via OSV
CVE-2025-53010Low
1y ago

MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return

MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return

▾ Sunlitmaterialx · materialxEPSS 0.46%via OSV
CVE-2025-54576High· 7.4
1y ago

github.com/oauth2-proxy/oauth2-proxy: OAuth2-Proxy authentication bypass (CVE-2025-54576)

An authentication bypass flaw was found in the OAuth2-Proxy project. This bypass affects systems that have configured their deployment to skip authentication on endpoints that match a deployment-defined regular expression. HTTP parameters …

▾ TwilightRed Hat · Red Hat Ceph Storage 8EPSS 1.2%via CSAF
CVE-2021-21411Medium· 5.5
1y ago

OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0

OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0

▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 1.1%via OSV
CVE-2025-54381Critical· 9.9PoC
1y ago

BentoML SSRF Vulnerability in File Upload Processing

BentoML SSRF Vulnerability in File Upload Processing

▾ Abyssalbentoml · bentomlEPSS 16%via OSV
CVE-2025-54433High
1y ago

Bugsink path traversal via event_id in ingestion

Bugsink path traversal via event_id in ingestion

▾ Twilightbugsink · bugsinkEPSS 0.58%via OSV
CVE-2025-54423Medium· 5.4
1y ago

copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata

copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata

▾ Sunlitcopyparty · copypartyEPSS 0.41%via OSV
CVEs tagged “osv” — page 107 · VulnSea