VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2025-49134Medium· 5.3
1y ago

Weblate exposes personal IP address via e-mail

Weblate exposes personal IP address via e-mail

▾ Sunlitweblate · weblateEPSS 0.32%via OSV
CVE-2025-28388Critical· 9.8
1y ago

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

▾ Midnightopenc3 · openc3EPSS 0.61%via OSV
CVE-2025-28384Critical· 9.1
1y ago

An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

▾ Midnightopenc3 · openc3EPSS 0.89%via OSV
CVE-2025-28382High· 7.5
1y ago

An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

▾ Twilightopenc3 · openc3EPSS 0.89%via OSV
CVE-2025-28381High· 7.5
1y ago

A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all co…

A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.

▾ Twilightopenc3 · openc3EPSS 0.52%via OSV
CVE-2025-28380Medium· 6.1
1y ago

A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via i…

A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter.

▾ Sunlitopenc3 · openc3EPSS 0.34%via OSV
CVE-2025-22240Medium· 6.3
1y ago

Salt allows arbitrary directory creation or file deletion

Salt allows arbitrary directory creation or file deletion

▾ Sunlitsalt · saltEPSS 0.16%via OSV
CVE-2025-22238Medium· 4.2
1y ago

Salt vulnerable to directory traversal attack in minion file cache creation

Salt vulnerable to directory traversal attack in minion file cache creation

▾ Sunlitsalt · saltEPSS 0.29%via OSV
CVE-2025-22236High· 8.1
1y ago

Salt has minion event bus authorization bypass vulnerability

Salt has minion event bus authorization bypass vulnerability

▾ Twilightsalt · saltEPSS 0.17%via OSV
CVE-2025-22237Medium· 6.7
1y ago

Salt's on demand pillar functionality vulnerable to arbitrary command injections

Salt's on demand pillar functionality vulnerable to arbitrary command injections

▾ Sunlitsalt · saltEPSS 0.18%via OSV
CVE-2025-22239High· 8.1
1y ago

Salt vulnerable to arbitrary event injection

Salt vulnerable to arbitrary event injection

▾ Twilightsalt · saltEPSS 0.18%via OSV
CVE-2025-22242Medium· 5.6
1y ago

Salt's worker process vulnerable to denial of service through file read operation

Salt's worker process vulnerable to denial of service through file read operation

▾ Sunlitsalt · saltEPSS 0.14%via OSV
CVE-2025-22241Medium· 5.6
1y ago

Salt's file contents overwrite the VirtKey class

Salt's file contents overwrite the VirtKey class

▾ Sunlitsalt · saltEPSS 0.18%via OSV
CVE-2024-38825Medium· 6.4
1y ago

Salt's salt.auth.pki module does not properly authenticate callers

Salt's salt.auth.pki module does not properly authenticate callers

▾ Sunlitsalt · saltEPSS 0.15%via OSV
CVE-2024-44905Medium· 6.5
1y ago

go-pg SQL injection vulnerability via the component /types/append_value.go

go-pg SQL injection vulnerability via the component /types/append_value.go

▾ Sunlitgo-pg · github.com/go-pg/pg/v10EPSS 0.44%via OSV
CVE-2025-22874High· 7.5
1y ago

crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509 (CVE-2025-22874)

A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.20EPSS 0.37%via CSAF
CVE-2025-8556Low· 3.7
1y ago

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

▾ Sunlitcloudflare · github.com/cloudflare/circlEPSS 0.48%via OSV
CVE-2025-49143Medium
1y ago

Nautobot may allows uploaded media files to be accessible without authentication

Nautobot may allows uploaded media files to be accessible without authentication

▾ Sunlitnautobot · nautobotEPSS 0.44%via OSV
CVE-2025-48067Medium· 5.4
1y ago

OctoPrint vulnerable to possible file extraction via upload endpoints

OctoPrint vulnerable to possible file extraction via upload endpoints

▾ Sunlitoctoprint · octoprintEPSS 0.29%via OSV
CVE-2025-48879Medium· 6.5
1y ago

OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint

OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint

▾ Sunlitoctoprint · octoprintEPSS 0.26%via OSV
CVE-2025-49653High· 8.0
1y ago

BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

▾ Twilightbackend-ai · backend-aiEPSS 0.35%via OSV
CVE-2025-49651High· 8.1
1y ago

Backend.AI Missing Authorization vulnerability

Backend.AI Missing Authorization vulnerability

▾ Twilightbackend-ai · backend-aiEPSS 0.34%via OSV
CVE-2024-47081Medium· 5.3
1y ago

Requests vulnerable to .netrc credentials leak via malicious URLs

Requests vulnerable to .netrc credentials leak via malicious URLs

▾ Sunlitrequests · requestsEPSS 0.98%via OSV
CVE-2025-49619High· 8.5PoC
1y ago

Skyvern has a Jinja runtime leak

Skyvern has a Jinja runtime leak

▾ Midnightskyvern · skyvernEPSS 20%via OSV
CVE-2025-48432Medium· 4.0
1y ago

Django Improper Output Neutralization for Logs vulnerability

Django Improper Output Neutralization for Logs vulnerability

▾ Sunlitdjango · djangoEPSS 0.75%via OSV
CVE-2025-1793Critical· 9.8
1y ago

llama_index vulnerable to SQL Injection

llama_index vulnerable to SQL Injection

▾ Midnightllama-index · llama-indexEPSS 0.66%via OSV
CVE-2025-48995Medium
1y ago

SignXML's signature verification with HMAC is vulnerable to a timing attack

SignXML's signature verification with HMAC is vulnerable to a timing attack

▾ Sunlitsignxml · signxmlEPSS 0.23%via OSV
CVE-2025-48994Medium
1y ago

SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack

SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack

▾ Sunlitsignxml · signxmlEPSS 0.22%via OSV
CVE-2025-48957High· 7.5
1y ago

AstrBot Has Path Traversal Vulnerability in /api/chat/get_file

AstrBot Has Path Traversal Vulnerability in /api/chat/get_file

▾ Twilightastrbot · astrbotEPSS 0.74%via OSV
CVE-2025-30167High· 7.3
1y ago

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

▾ Twilightjupyter-core · jupyter-coreEPSS 0.19%via OSV
CVEs tagged “osv” — page 110 · VulnSea