Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2025-49134Medium· 5.3Weblate exposes personal IP address via e-mail
Weblate exposes personal IP address via e-mail
CVE-2025-28388Critical· 9.8OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
CVE-2025-28384Critical· 9.1An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
CVE-2025-28382High· 7.5An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
CVE-2025-28381High· 7.5A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all co…
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.
CVE-2025-28380Medium· 6.1A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via i…
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter.
CVE-2025-22240Medium· 6.3Salt allows arbitrary directory creation or file deletion
Salt allows arbitrary directory creation or file deletion
CVE-2025-22238Medium· 4.2Salt vulnerable to directory traversal attack in minion file cache creation
Salt vulnerable to directory traversal attack in minion file cache creation
CVE-2025-22236High· 8.1Salt has minion event bus authorization bypass vulnerability
Salt has minion event bus authorization bypass vulnerability
CVE-2025-22237Medium· 6.7Salt's on demand pillar functionality vulnerable to arbitrary command injections
Salt's on demand pillar functionality vulnerable to arbitrary command injections
CVE-2025-22239High· 8.1Salt vulnerable to arbitrary event injection
Salt vulnerable to arbitrary event injection
CVE-2025-22242Medium· 5.6Salt's worker process vulnerable to denial of service through file read operation
Salt's worker process vulnerable to denial of service through file read operation
CVE-2025-22241Medium· 5.6Salt's file contents overwrite the VirtKey class
Salt's file contents overwrite the VirtKey class
CVE-2024-38825Medium· 6.4Salt's salt.auth.pki module does not properly authenticate callers
Salt's salt.auth.pki module does not properly authenticate callers
CVE-2024-44905Medium· 6.5go-pg SQL injection vulnerability via the component /types/append_value.go
go-pg SQL injection vulnerability via the component /types/append_value.go
CVE-2025-22874High· 7.5crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509 (CVE-2025-22874)
A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.
CVE-2025-8556Low· 3.7CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
CVE-2025-49143MediumNautobot may allows uploaded media files to be accessible without authentication
Nautobot may allows uploaded media files to be accessible without authentication
CVE-2025-48067Medium· 5.4OctoPrint vulnerable to possible file extraction via upload endpoints
OctoPrint vulnerable to possible file extraction via upload endpoints
CVE-2025-48879Medium· 6.5OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint
OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint
CVE-2025-49653High· 8.0BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-49651High· 8.1Backend.AI Missing Authorization vulnerability
Backend.AI Missing Authorization vulnerability
CVE-2024-47081Medium· 5.3Requests vulnerable to .netrc credentials leak via malicious URLs
Requests vulnerable to .netrc credentials leak via malicious URLs
CVE-2025-49619High· 8.5PoCSkyvern has a Jinja runtime leak
Skyvern has a Jinja runtime leak
CVE-2025-48432Medium· 4.0Django Improper Output Neutralization for Logs vulnerability
Django Improper Output Neutralization for Logs vulnerability
CVE-2025-1793Critical· 9.8llama_index vulnerable to SQL Injection
llama_index vulnerable to SQL Injection
CVE-2025-48995MediumSignXML's signature verification with HMAC is vulnerable to a timing attack
SignXML's signature verification with HMAC is vulnerable to a timing attack
CVE-2025-48994MediumSignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
CVE-2025-48957High· 7.5AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
CVE-2025-30167High· 7.3Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability