VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2025-3777Low· 3.5
1y ago

Transformers's Improper Input Validation vulnerability can be exploited through username injection

Transformers's Improper Input Validation vulnerability can be exploited through username injection

▾ Sunlittransformers · transformersEPSS 0.38%via OSV
CVE-2025-3044Medium· 5.3
1y ago

LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions

LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions

▾ Sunlitllama-index-readers-papers · llama-index-readers-papersEPSS 0.30%via OSV
CVE-2025-3108Medium· 5.0
1y ago

LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component

LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component

▾ Sunlitllama-index-core · llama-index-coreEPSS 0.47%via OSV
CVE-2025-3264Medium· 5.3
1y ago

Transformers vulnerable to ReDoS attack through its get_imports() function

Transformers vulnerable to ReDoS attack through its get_imports() function

▾ Sunlittransformers · transformersEPSS 0.46%via OSV
CVE-2025-6386High· 7.5
1y ago

Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function

Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function

▾ Twilightlollms · lollmsEPSS 0.39%via OSV
CVE-2025-53539Medium
1y ago

fastapi-guard is vulnerable to ReDoS through inefficient regex

fastapi-guard is vulnerable to ReDoS through inefficient regex

▾ Sunlitfastapi-guard · fastapi-guardEPSS 0.45%via OSV
CVE-2025-3046High· 7.5
1y ago

LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class

LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class

▾ Twilightllama-index-readers-obsidian · llama-index-readers-obsidianEPSS 0.59%via OSV
CVE-2025-3262Medium· 5.3
1y ago

Transformers vulnerable to ReDoS attack through its SETTING_RE variable

Transformers vulnerable to ReDoS attack through its SETTING_RE variable

▾ Sunlittransformers · transformersEPSS 0.46%via OSV
CVE-2025-5472Medium· 6.5
1y ago

LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing

LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing

▾ Sunlitllama-index-core · llama-index-coreEPSS 0.36%via OSV
CVE-2025-6210Medium· 6.2
1y ago

LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit

LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit

▾ Sunlitllama-index-readers-obsidian · llama-index-readers-obsidianEPSS 0.31%via OSV
CVE-2025-6209High· 7.5
1y ago

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

▾ Twilightllama-index-core · llama-index-coreEPSS 0.58%via OSV
CVE-2025-53365High
1y ago

MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service

MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service

▾ Twilightmcp · mcpEPSS 0.39%via OSV
CVE-2025-53366High
1y ago

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

▾ Twilightmcp · mcpEPSS 7.7%via OSV
CVE-2025-52996Low· 3.1
1y ago

File Browser's password protection of links is bypassable

File Browser's password protection of links is bypassable

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.36%via OSV
CVE-2025-6853Medium· 6.3
1y ago

Langchain-Chatchat has a Path Traversal vulnerability

Langchain-Chatchat has a Path Traversal vulnerability

▾ Sunlitlangchain-chatchat · langchain-chatchatEPSS 0.55%via OSV
CVE-2025-6855Medium· 5.5
1y ago

Langchain-Chatchat vulnerable to path traversal

Langchain-Chatchat vulnerable to path traversal

▾ Sunlitlangchain-chatchat · langchain-chatchatEPSS 0.62%via OSV
CVE-2025-6854Medium· 4.3
1y ago

Langchain-Chatchat vulnerable to path traversal

Langchain-Chatchat vulnerable to path traversal

▾ Sunlitlangchain-chatchat · langchain-chatchatEPSS 0.54%via OSV
CVE-2025-53002High· 8.3
1y ago

LLaMA-Factory allows Code Injection through improper vhead_file safeguards

LLaMA-Factory allows Code Injection through improper vhead_file safeguards

▾ Twilightllamafactory · llamafactoryEPSS 1.2%via OSV
CVE-2025-6773Medium· 5.3
1y ago

HKUDS LightRAG allows Path Traversal via function upload_to_input_dir

HKUDS LightRAG allows Path Traversal via function upload_to_input_dir

▾ Sunlitlightrag-hku · lightrag-hkuEPSS 0.21%via OSV
CVE-2025-52894Medium
1y ago

OpenBao allows cancellation of root rekey and recovery rekey operations without authentication

OpenBao allows cancellation of root rekey and recovery rekey operations without authentication

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.40%via OSV
CVE-2025-52893Medium· 4.5
1y ago

OpenBao Inserts Sensitive Information into Log File when processing malformed data

OpenBao Inserts Sensitive Information into Log File when processing malformed data

▾ Sunlitopenbao · github.com/openbao/openbao/sdk/v2EPSS 0.33%via OSV
CVE-2025-6032High· 8.3
1y ago

A flaw was found in Podman

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

▾ Twilightcontainers · github.com/containers/podman/v4EPSS 0.52%via NVD
CVE-2025-52558High
1y ago

ChangeDetection.io XSS in watch overview

ChangeDetection.io XSS in watch overview

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.59%via OSV
CVE-2025-6518Medium· 6.3
1y ago

pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode function

pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode function

▾ Sunlitpyspur · pyspurEPSS 0.39%via OSV
CVE-2025-50181Medium· 5.3
1y ago

urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation (CVE-2025-50181)

A flaw was found in urllib3. The `PoolManager` class allows redirects to be disabled by configuring retries in a specific manner, effectively bypassing intended HTTP redirection behavior. A network attacker can leverage this configuration …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.47%via CSAF
CVE-2025-50182Medium· 5.3
1y ago

urllib3: urllib3 does not control redirects in browsers and Node.js (CVE-2025-50182)

A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can en…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.39%via CSAF
CVE-2025-6050Medium· 4.8
1y ago

Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnera…

Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the "displayable_links_js" function, which fails to properly sanitize blog post tit…

▾ Sunlitmezzanine · mezzanineEPSS 0.32%via OSV
CVE-2025-48945Medium
1y ago

pycares has a Use-After-Free Vulnerability

pycares has a Use-After-Free Vulnerability

▾ Sunlitpycares · pycaresEPSS 0.48%via OSV
CVE-2025-4565High
1y ago

protobuf-python has a potential Denial of Service issue

protobuf-python has a potential Denial of Service issue

▾ Twilightprotobuf · protobufEPSS 0.26%via OSV
CVE-2025-47951Medium· 4.9
1y ago

Weblate lacks rate limiting when verifying second factor

Weblate lacks rate limiting when verifying second factor

▾ Sunlitweblate · weblateEPSS 0.27%via OSV
CVEs tagged “osv” — page 109 · VulnSea