Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2025-3777Low· 3.5Transformers's Improper Input Validation vulnerability can be exploited through username injection
Transformers's Improper Input Validation vulnerability can be exploited through username injection
CVE-2025-3044Medium· 5.3LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions
LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions
CVE-2025-3108Medium· 5.0LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
CVE-2025-3264Medium· 5.3Transformers vulnerable to ReDoS attack through its get_imports() function
Transformers vulnerable to ReDoS attack through its get_imports() function
CVE-2025-6386High· 7.5Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
CVE-2025-53539Mediumfastapi-guard is vulnerable to ReDoS through inefficient regex
fastapi-guard is vulnerable to ReDoS through inefficient regex
CVE-2025-3046High· 7.5LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class
LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class
CVE-2025-3262Medium· 5.3Transformers vulnerable to ReDoS attack through its SETTING_RE variable
Transformers vulnerable to ReDoS attack through its SETTING_RE variable
CVE-2025-5472Medium· 6.5LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
CVE-2025-6210Medium· 6.2LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit
LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit
CVE-2025-6209High· 7.5LlamaIndex vulnerable to Path Traversal attack through its encode_image function
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
CVE-2025-53365HighMCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
CVE-2025-53366HighMCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
CVE-2025-52996Low· 3.1File Browser's password protection of links is bypassable
File Browser's password protection of links is bypassable
CVE-2025-6853Medium· 6.3Langchain-Chatchat has a Path Traversal vulnerability
Langchain-Chatchat has a Path Traversal vulnerability
CVE-2025-6855Medium· 5.5Langchain-Chatchat vulnerable to path traversal
Langchain-Chatchat vulnerable to path traversal
CVE-2025-6854Medium· 4.3Langchain-Chatchat vulnerable to path traversal
Langchain-Chatchat vulnerable to path traversal
CVE-2025-53002High· 8.3LLaMA-Factory allows Code Injection through improper vhead_file safeguards
LLaMA-Factory allows Code Injection through improper vhead_file safeguards
CVE-2025-6773Medium· 5.3HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
CVE-2025-52894MediumOpenBao allows cancellation of root rekey and recovery rekey operations without authentication
OpenBao allows cancellation of root rekey and recovery rekey operations without authentication
CVE-2025-52893Medium· 4.5OpenBao Inserts Sensitive Information into Log File when processing malformed data
OpenBao Inserts Sensitive Information into Log File when processing malformed data
CVE-2025-6032High· 8.3A flaw was found in Podman
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
CVE-2025-52558HighChangeDetection.io XSS in watch overview
ChangeDetection.io XSS in watch overview
CVE-2025-6518Medium· 6.3pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode function
pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode function
CVE-2025-50181Medium· 5.3urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation (CVE-2025-50181)
A flaw was found in urllib3. The `PoolManager` class allows redirects to be disabled by configuring retries in a specific manner, effectively bypassing intended HTTP redirection behavior. A network attacker can leverage this configuration …
CVE-2025-50182Medium· 5.3urllib3: urllib3 does not control redirects in browsers and Node.js (CVE-2025-50182)
A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can en…
CVE-2025-6050Medium· 4.8Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnera…
Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the "displayable_links_js" function, which fails to properly sanitize blog post tit…
CVE-2025-48945Mediumpycares has a Use-After-Free Vulnerability
pycares has a Use-After-Free Vulnerability
CVE-2025-4565Highprotobuf-python has a potential Denial of Service issue
protobuf-python has a potential Denial of Service issue
CVE-2025-47951Medium· 4.9Weblate lacks rate limiting when verifying second factor
Weblate lacks rate limiting when verifying second factor