Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2025-54412HighSkops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
CVE-2025-55013Medium· 4.2Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code
Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code
CVE-2025-54413HighSkops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
CVE-2025-54379High· 9.8eKuiper API endpoints handling SQL queries with user-controlled table names.
eKuiper API endpoints handling SQL queries with user-controlled table names.
CVE-2025-7404MediumPoCCalibre Web and Autocaliweb have OS Command Injection vulnerability
Calibre Web and Autocaliweb have OS Command Injection vulnerability
CVE-2025-6998HighPoCCalibre Web and Autocaliweb have a ReDoS vulnerability
Calibre Web and Autocaliweb have a ReDoS vulnerability
CVE-2025-54365HighFastAPI Guard has a regex bypass
FastAPI Guard has a regex bypass
CVE-2025-51481Medium· 6.6Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read a…
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookD…
CVE-2025-51464MediumAim vulnerable to Cross-site Scripting
Aim vulnerable to Cross-site Scripting
CVE-2025-54140High· 7.5`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
CVE-2025-54121Medium· 5.3Starlette has possible denial-of-service vector when parsing large files in multipart forms
Starlette has possible denial-of-service vector when parsing large files in multipart forms
CVE-2025-22868High· 7.5golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability
golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability
CVE-2025-54059Medium· 4.4melange's world-writable permissions expose SBOM files to potential image tampering
melange's world-writable permissions expose SBOM files to potential image tampering
CVE-2025-3415Medium· 4.3PoCGrafana's insecure DingDing Alert integration exposes sensitive information
Grafana's insecure DingDing Alert integration exposes sensitive information
CVE-2025-53893HighFile Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
CVE-2025-53826HighFile Browser’s insecure JWT handling can lead to session replay attacks after logout
File Browser’s insecure JWT handling can lead to session replay attacks after logout
RUSTSEC-2025-0172None`zip-extract` is unmaintained; use the `zip >= 2.4.0` crate instead
`zip-extract` is unmaintained; use the `zip >= 2.4.0` crate instead
CVE-2025-53890Critical· 9.8pyLoad vulnerable to XSS through insecure CAPTCHA
pyLoad vulnerable to XSS through insecure CAPTCHA
CVE-2025-29606Medium· 4.3py-libp2p is vulnerable to DoS attacks through use of large RSA keys
py-libp2p is vulnerable to DoS attacks through use of large RSA keys
CVE-2025-53640MediumPoCIndico vulnerability allows attackers to bulk dump user details
Indico vulnerability allows attackers to bulk dump user details
CVE-2025-53643LowAIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
CVE-2025-7453Low· 3.7ZPan Uses Hard-Coded Password
ZPan Uses Hard-Coded Password
CVE-2025-30402High· 8.1ExecuTorch vulnerable to Heap-based Buffer Overflow attack
ExecuTorch vulnerable to Heap-based Buffer Overflow attack
CVE-2025-3933Medium· 5.3Transformers is vulnerable to ReDoS attack through its DonutProcessor class
Transformers is vulnerable to ReDoS attack through its DonutProcessor class
CVE-2025-6211Medium· 6.5LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
CVE-2025-53513High· 8.8Juju zip slip vulnerability via authenticated endpoint
Juju zip slip vulnerability via authenticated endpoint
CVE-2025-53547High· 8.5PoChelm.sh/helm/v3: Helm Chart Code Execution (CVE-2025-53547)
A command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symboli…
CVE-2025-7346High· 7.5pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
CVE-2025-3225High· 7.5LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser
LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser
CVE-2023-51232High· 7.5Dagster vulnerable to Path Traversal attack through its /logs endpoint
Dagster vulnerable to Path Traversal attack through its /logs endpoint