VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2025-47782High
1y ago

motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution

motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution

▾ Twilightmotioneye · motioneyeEPSS 0.49%via OSV
CVE-2025-27696High· 8.8
1y ago

Apache Superset Allows Ownership Takeover

Apache Superset Allows Ownership Takeover

▾ Twilightapache-superset · apache-supersetEPSS 1.2%via OSV
CVE-2025-47278Low
1y ago

Flask uses fallback key instead of current signing key

Flask uses fallback key instead of current signing key

▾ Sunlitflask · flaskEPSS 0.18%via OSV
CVE-2025-1752High· 7.5
1y ago

LlamaIndex Vulnerable to Denial of Service (DoS)

LlamaIndex Vulnerable to Denial of Service (DoS)

▾ Twilightllama-index · llama-indexEPSS 0.50%via OSV
CVE-2025-32873Medium· 5.3PoC
1y ago

Django has a denial-of-service possibility in strip_tags()

Django has a denial-of-service possibility in strip_tags()

▾ Twilightdjango · djangoEPSS 14%via OSV
RUSTSEC-2025-0171None
1y ago

soundness issue

soundness issue

▾ Sunlitmod3d-base · mod3d-basevia OSV
CVE-2025-46814High· 7.5
1y ago

FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. A…

FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. An HTTP header injection vulnerability has been identified in versions prior to 2.0.0. By manipulatin…

▾ Twilightfastapi-guard · fastapi-guardEPSS 0.32%via OSV
CVE-2025-30165High· 8.0
1y ago

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

▾ Twilightvllm · vllmEPSS 0.48%via OSV
CVE-2025-46726High
1y ago

Langroid Allows XXE Injection via XMLToolMessage

Langroid Allows XXE Injection via XMLToolMessage

▾ Twilightlangroid · langroidEPSS 0.62%via OSV
CVE-2025-46335Medium
1y ago

Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload

Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload

▾ Sunlitmobsf · mobsfEPSS 0.30%via OSV
CVE-2025-46730Medium· 6.8
1y ago

Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

▾ Sunlitmobsf · mobsfEPSS 0.48%via OSV
CVE-2025-4166Medium· 4.5
1y ago

Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information

Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information

▾ Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.45%via OSV
CVE-2025-46569High
1y ago

OPA server Data API HTTP path injection of Rego

OPA server Data API HTTP path injection of Rego

▾ Twilightopen-policy-agent · github.com/open-policy-agent/opa/v1/serverEPSS 0.53%via OSV
CVE-2025-32444Critical· 10.0
1y ago

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

▾ Midnightvllm · vllmEPSS 1.8%via OSV
CVE-2025-46560Medium· 6.5
1y ago

phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

▾ Sunlitvllm · vllmEPSS 0.52%via OSV
CVE-2025-1194Medium· 4.3
1y ago

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

▾ Sunlittransformers · transformersEPSS 0.48%via OSV
CVE-2025-30202High· 7.5
1y ago

Data exposure via ZeroMQ on multi-node vLLM deployment

Data exposure via ZeroMQ on multi-node vLLM deployment

▾ Twilightvllm · vllmEPSS 0.60%via OSV
CVE-2025-46327Low· 3.3
1y ago

Go Snowflake Driver has race condition when checking access to Easy Logging configuration file

Go Snowflake Driver has race condition when checking access to Easy Logging configuration file

▾ Sunlitsnowflakedb · github.com/snowflakedb/gosnowflakeEPSS 0.14%via OSV
CVE-2025-4032Medium· 5.0
1y ago

AWorld OS Command Injection vulnerability

AWorld OS Command Injection vulnerability

▾ Sunlitaworld · aworldEPSS 3.3%via OSV
CVE-2025-46656Low· 2.9
1y ago

markdownify allows large headline prefixes such as <h9999999>, which causes memory consumption

markdownify allows large headline prefixes such as <h9999999>, which causes memory consumption

▾ Sunlitmarkdownify · markdownifyEPSS 0.22%via OSV
CVE-2025-46599Medium· 6.8
1y ago

CNCF K3s Kubernetes kubelet configuration exposes credentials

CNCF K3s Kubernetes kubelet configuration exposes credentials

▾ Sunlitk3s-io · github.com/k3s-io/k3sEPSS 0.45%via OSV
CVE-2025-35965Medium· 6.5
1y ago

Mattermost Playbooks fails to validate the uniqueness and quantity of task actions

Mattermost Playbooks fails to validate the uniqueness and quantity of task actions

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.40%via OSV
CVE-2025-41395Medium· 6.5
1y ago

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

▾ Sunlitmattermost · github.com/mattermost/mattermost-plugin-playbooksEPSS 0.49%via OSV
CVE-2025-43859Critical· 9.1
1y ago

h11 accepts some malformed Chunked-Encoding bodies

h11 accepts some malformed Chunked-Encoding bodies

▾ Midnighth11 · h11EPSS 0.58%via OSV
RUSTSEC-2025-0170None
1y ago

`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code

`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code

▾ Sunlithugepage-rs · hugepage-rsvia OSV
RUSTSEC-2025-0169None
1y ago

`FormatContext` stream accessors can cause undefined behavior from safe code

`FormatContext` stream accessors can cause undefined behavior from safe code

▾ Sunlitstainless_ffmpeg · stainless_ffmpegvia OSV
GHSA-ggpf-24jw-3fcwCritical· 9.8
1y ago

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

▾ Midnightvllm · vllmvia OSV
CVE-2025-46567Medium· 6.1
1y ago

LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py

LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py

▾ Sunlitllamafactory · llamafactoryEPSS 0.29%via OSV
CVE-2025-43971High· 8.6
1y ago

GoBGP panics due to a zero value for softwareVersionLen

GoBGP panics due to a zero value for softwareVersionLen

▾ Twilightosrg · github.com/osrg/gobgp/v3EPSS 0.55%via OSV
CVE-2025-32793Medium· 4.0
1y ago

In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters

In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.14%via OSV
CVEs tagged “osv” — page 112 · VulnSea