Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2025-47782HighmotionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
CVE-2025-27696High· 8.8Apache Superset Allows Ownership Takeover
Apache Superset Allows Ownership Takeover
CVE-2025-47278LowFlask uses fallback key instead of current signing key
Flask uses fallback key instead of current signing key
CVE-2025-1752High· 7.5LlamaIndex Vulnerable to Denial of Service (DoS)
LlamaIndex Vulnerable to Denial of Service (DoS)
CVE-2025-32873Medium· 5.3PoCDjango has a denial-of-service possibility in strip_tags()
Django has a denial-of-service possibility in strip_tags()
RUSTSEC-2025-0171Nonesoundness issue
soundness issue
CVE-2025-46814High· 7.5FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. A…
FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. An HTTP header injection vulnerability has been identified in versions prior to 2.0.0. By manipulatin…
CVE-2025-30165High· 8.0Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
CVE-2025-46726HighLangroid Allows XXE Injection via XMLToolMessage
Langroid Allows XXE Injection via XMLToolMessage
CVE-2025-46335MediumMobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
CVE-2025-46730Medium· 6.8Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
CVE-2025-4166Medium· 4.5Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2025-46569HighOPA server Data API HTTP path injection of Rego
OPA server Data API HTTP path injection of Rego
CVE-2025-32444Critical· 10.0vLLM Vulnerable to Remote Code Execution via Mooncake Integration
vLLM Vulnerable to Remote Code Execution via Mooncake Integration
CVE-2025-46560Medium· 6.5phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
CVE-2025-1194Medium· 4.3Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2025-30202High· 7.5Data exposure via ZeroMQ on multi-node vLLM deployment
Data exposure via ZeroMQ on multi-node vLLM deployment
CVE-2025-46327Low· 3.3Go Snowflake Driver has race condition when checking access to Easy Logging configuration file
Go Snowflake Driver has race condition when checking access to Easy Logging configuration file
CVE-2025-4032Medium· 5.0AWorld OS Command Injection vulnerability
AWorld OS Command Injection vulnerability
CVE-2025-46656Low· 2.9markdownify allows large headline prefixes such as <h9999999>, which causes memory consumption
markdownify allows large headline prefixes such as <h9999999>, which causes memory consumption
CVE-2025-46599Medium· 6.8CNCF K3s Kubernetes kubelet configuration exposes credentials
CNCF K3s Kubernetes kubelet configuration exposes credentials
CVE-2025-35965Medium· 6.5Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
CVE-2025-41395Medium· 6.5Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
CVE-2025-43859Critical· 9.1h11 accepts some malformed Chunked-Encoding bodies
h11 accepts some malformed Chunked-Encoding bodies
RUSTSEC-2025-0170None`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code
`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code
RUSTSEC-2025-0169None`FormatContext` stream accessors can cause undefined behavior from safe code
`FormatContext` stream accessors can cause undefined behavior from safe code
GHSA-ggpf-24jw-3fcwCritical· 9.8CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
CVE-2025-46567Medium· 6.1LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py
LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py
CVE-2025-43971High· 8.6GoBGP panics due to a zero value for softwareVersionLen
GoBGP panics due to a zero value for softwareVersionLen
CVE-2025-32793Medium· 4.0In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters