VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2025-54412High
1y ago

Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution

Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution

▾ Twilightskops · skopsEPSS 0.14%via OSV
CVE-2025-55013Medium· 4.2
1y ago

Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code

Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code

▾ Sunlitassemblyline-service-client · assemblyline-service-clientEPSS 0.58%via OSV
CVE-2025-54413High
1y ago

Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time

Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time

▾ Twilightskops · skopsEPSS 0.14%via OSV
CVE-2025-54379High· 9.8
1y ago

eKuiper API endpoints handling SQL queries with user-controlled table names.

eKuiper API endpoints handling SQL queries with user-controlled table names.

▾ Twilightlf-edge · github.com/lf-edge/ekuiper/v2EPSS 0.77%via OSV
CVE-2025-7404MediumPoC
1y ago

Calibre Web and Autocaliweb have OS Command Injection vulnerability

Calibre Web and Autocaliweb have OS Command Injection vulnerability

▾ Twilightcalibreweb · calibrewebEPSS 2.8%via OSV
CVE-2025-6998HighPoC
1y ago

Calibre Web and Autocaliweb have a ReDoS vulnerability

Calibre Web and Autocaliweb have a ReDoS vulnerability

▾ Midnightcalibreweb · calibrewebEPSS 0.84%via OSV
CVE-2025-54365High
1y ago

FastAPI Guard has a regex bypass

FastAPI Guard has a regex bypass

▾ Twilightfastapi-guard · fastapi-guardEPSS 0.76%via OSV
CVE-2025-51481Medium· 6.6
1y ago

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read a…

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookD…

▾ Sunlitdagster-ge · dagster-geEPSS 0.55%via OSV
CVE-2025-51464Medium
1y ago

Aim vulnerable to Cross-site Scripting

Aim vulnerable to Cross-site Scripting

▾ Sunlitaim · aimEPSS 0.61%via OSV
CVE-2025-54140High· 7.5
1y ago

`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write

`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write

▾ Twilightpyload-ng · pyload-ngEPSS 0.65%via OSV
CVE-2025-54121Medium· 5.3
1y ago

Starlette has possible denial-of-service vector when parsing large files in multipart forms

Starlette has possible denial-of-service vector when parsing large files in multipart forms

▾ Sunlitstarlette · starletteEPSS 0.58%via OSV
CVE-2025-22868High· 7.5
1y ago

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

▾ Twilightx · golang.org/x/oauth2EPSS 0.87%via OSV
CVE-2025-54059Medium· 4.4
1y ago

melange's world-writable permissions expose SBOM files to potential image tampering

melange's world-writable permissions expose SBOM files to potential image tampering

▾ Sunlitmelange · chainguard.dev/melangeEPSS 0.13%via OSV
CVE-2025-3415Medium· 4.3PoC
1y ago

Grafana's insecure DingDing Alert integration exposes sensitive information

Grafana's insecure DingDing Alert integration exposes sensitive information

▾ Twilightgrafana · github.com/grafana/grafanaEPSS 0.98%via OSV
CVE-2025-53893High
1y ago

File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing

File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.36%via OSV
CVE-2025-53826High
1y ago

File Browser’s insecure JWT handling can lead to session replay attacks after logout

File Browser’s insecure JWT handling can lead to session replay attacks after logout

▾ Twilightfilebrowser · github.com/filebrowser/filebrowserEPSS 0.50%via OSV
RUSTSEC-2025-0172None
1y ago

`zip-extract` is unmaintained; use the `zip >= 2.4.0` crate instead

`zip-extract` is unmaintained; use the `zip >= 2.4.0` crate instead

▾ Sunlitzip-extract · zip-extractvia OSV
CVE-2025-53890Critical· 9.8
1y ago

pyLoad vulnerable to XSS through insecure CAPTCHA

pyLoad vulnerable to XSS through insecure CAPTCHA

▾ Midnightpyload-ng · pyload-ngEPSS 1.2%via OSV
CVE-2025-29606Medium· 4.3
1y ago

py-libp2p is vulnerable to DoS attacks through use of large RSA keys

py-libp2p is vulnerable to DoS attacks through use of large RSA keys

▾ Sunlitlibp2p · libp2pEPSS 0.33%via OSV
CVE-2025-53640MediumPoC
1y ago

Indico vulnerability allows attackers to bulk dump user details

Indico vulnerability allows attackers to bulk dump user details

▾ Twilightindico · indicoEPSS 0.60%via OSV
CVE-2025-53643Low
1y ago

AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections

AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections

▾ Sunlitaiohttp · aiohttpEPSS 0.31%via OSV
CVE-2025-7453Low· 3.7
1y ago

ZPan Uses Hard-Coded Password

ZPan Uses Hard-Coded Password

▾ Sunlitsaltbo · github.com/saltbo/zpanEPSS 0.38%via OSV
CVE-2025-30402High· 8.1
1y ago

ExecuTorch vulnerable to Heap-based Buffer Overflow attack

ExecuTorch vulnerable to Heap-based Buffer Overflow attack

▾ Twilightexecutorch · executorchEPSS 0.36%via OSV
CVE-2025-3933Medium· 5.3
1y ago

Transformers is vulnerable to ReDoS attack through its DonutProcessor class

Transformers is vulnerable to ReDoS attack through its DonutProcessor class

▾ Sunlittransformers · transformersEPSS 0.43%via OSV
CVE-2025-6211Medium· 6.5
1y ago

LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class

LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class

▾ Sunlitllama-index · llama-indexEPSS 0.32%via OSV
CVE-2025-53513High· 8.8
1y ago

Juju zip slip vulnerability via authenticated endpoint

Juju zip slip vulnerability via authenticated endpoint

▾ Twilightjuju · github.com/juju/jujuEPSS 0.72%via OSV
CVE-2025-53547High· 8.5PoC
1y ago

helm.sh/helm/v3: Helm Chart Code Execution (CVE-2025-53547)

A command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symboli…

▾ MidnightRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9EPSS 0.44%via CSAF
CVE-2025-7346High· 7.5
1y ago

pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages

pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages

▾ Twilightpyload-ng · pyload-ngEPSS 0.35%via OSV
CVE-2025-3225High· 7.5
1y ago

LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser

LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser

▾ Twilightllama-index-readers-papers · llama-index-readers-papersEPSS 0.45%via OSV
CVE-2023-51232High· 7.5
1y ago

Dagster vulnerable to Path Traversal attack through its /logs endpoint

Dagster vulnerable to Path Traversal attack through its /logs endpoint

▾ Twilightdagster · dagsterEPSS 0.94%via OSV
CVEs tagged “osv” — page 108 · VulnSea