VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

GHSA-3wqc-mwfx-672pHigh· 7.5
1y ago

Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability

Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability

▾ Twilighttraefik · github.com/traefik/traefik/v3via OSV
CVE-2025-32434CriticalPoC
1y ago

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

▾ Abyssaltorch · torchEPSS 2.2%via OSV
CVE-2025-28197Medium
1y ago

Crawl4AI SSRF vulnerability

Crawl4AI SSRF vulnerability

▾ Sunlitcrawl4ai · crawl4aiEPSS 0.36%via OSV
CVE-2025-32377Medium· 6.5
1y ago

Rasa Pro Missing Authentication For Voice Connector APIs

Rasa Pro Missing Authentication For Voice Connector APIs

▾ Sunlitrasa-pro · rasa-proEPSS 0.46%via OSV
CVE-2025-27936Medium· 5.3
1y ago

Mattermost vulnerable to Observable Timing Discrepancy

Mattermost vulnerable to Observable Timing Discrepancy

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.34%via OSV
CVE-2025-3730Low· 3.3
1y ago

PyTorch Improper Resource Shutdown or Release vulnerability

PyTorch Improper Resource Shutdown or Release vulnerability

▾ Sunlittorch · torchEPSS 0.33%via OSV
CVE-2024-53305High
1y ago

Whoogle allows attackers to execute arbitrary code via supplying a crafted search query

Whoogle allows attackers to execute arbitrary code via supplying a crafted search query

▾ Twilightwhoogle-search · whoogle-searchEPSS 0.58%via OSV
CVE-2025-3445High· 8.1
1y ago

mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File

mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File

▾ Twilightmholt · github.com/mholt/archiverEPSS 0.50%via OSV
CVE-2025-2475Medium· 5.4
1y ago

Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm

Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.23%via OSV
CVE-2025-32093Medium· 4.7
1y ago

Mattermost Fails to Restrict Certain Operations on System Admins

Mattermost Fails to Restrict Certain Operations on System Admins

▾ Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.24%via OSV
CVE-2025-1386Medium
1y ago

CVE-2025-1386- Query smuggling in ch-go library

CVE-2025-1386- Query smuggling in ch-go library

▾ SunlitClickHouse · github.com/ClickHouse/ch-goEPSS 0.38%via OSV
CVE-2025-32387Medium· 6.5
1y ago

Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow

Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow

▾ Sunlithelm · helm.sh/helm/v3EPSS 0.48%via OSV
CVE-2025-32386Medium· 6.5
1y ago

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination

▾ Sunlithelm · helm.sh/helm/v3EPSS 0.45%via OSV
CVE-2025-32381Medium· 6.5
1y ago

xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory

xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory

▾ Sunlitxgrammar · xgrammarEPSS 0.50%via OSV
CVE-2025-71351Medium
1y ago

Picklescan missing detection when calling built-in python library function timeit.timeit()

Picklescan missing detection when calling built-in python library function timeit.timeit()

▾ Sunlitpicklescan · picklescanEPSS 0.71%via OSV
CVE-2025-71355Medium
1y ago

Picklescan failed to detect to some unsafe global function in Numpy library

Picklescan failed to detect to some unsafe global function in Numpy library

▾ Sunlitpicklescan · picklescanEPSS 0.58%via OSV
CVE-2025-46417High
1y ago

Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate

Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate

▾ Twilightpicklescan · picklescanEPSS 0.22%via OSV
CVE-2025-30473High· 8.8
1y ago

Apache Airflow Common SQL Provider Vulnerable to SQL Injection

Apache Airflow Common SQL Provider Vulnerable to SQL Injection

▾ Twilightapache-airflow-providers-common-sql · apache-airflow-providers-common-sqlEPSS 0.92%via OSV
CVE-2025-27520Critical· 9.8PoC
1y ago

BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization

BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization

▾ Abyssalbentoml · bentomlEPSS 41%via OSV
CVE-2025-31489HighPoC
1y ago

MinIO performs incomplete signature validation for unsigned-trailer uploads

MinIO performs incomplete signature validation for unsigned-trailer uploads

▾ Midnightminio · github.com/minio/minioEPSS 2.4%via OSV
CVE-2025-30370High· 7.4
1y ago

jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"

jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"

▾ Twilightjupyterlab-git · jupyterlab-gitEPSS 0.58%via OSV
CVE-2025-3160Low· 3.3
1y ago

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the fu…

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the compone…

▾ Sunlitpyassimp · pyassimpEPSS 0.28%via OSV
CVE-2025-3159High· 7.8
1y ago

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp:…

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component…

▾ Twilightpyassimp · pyassimpEPSS 0.33%via OSV
CVE-2025-3163Medium· 5.3
1y ago

InternLM LMDeploy code injection vulnerability

InternLM LMDeploy code injection vulnerability

▾ Sunlitlmdeploy · lmdeployEPSS 0.37%via OSV
CVE-2025-3162Medium· 5.3
1y ago

LMDeploy Improper Input Validation Vulnerability

LMDeploy Improper Input Validation Vulnerability

▾ Sunlitlmdeploy · lmdeployEPSS 0.32%via OSV
CVE-2023-27591High· 7.5
1y ago

Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics

Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics

▾ Twilightv2 · miniflux.app/v2EPSS 0.76%via OSV
CVE-2025-30223Critical· 9.3
1y ago

Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input

Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input

▾ Midnightbeego · github.com/beego/beego/v2EPSS 0.59%via OSV
CVE-2025-3016Medium· 6.5
1y ago

A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function As…

A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the …

▾ Sunlitpyassimp · pyassimpEPSS 0.62%via OSV
CVE-2025-3015High· 8.8
1y ago

A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImp…

A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE Fi…

▾ Twilightpyassimp · pyassimpEPSS 0.50%via OSV
CVE-2025-3001None
1y ago

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulat…

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disc…

▾ Sunlittorch · torchEPSS 0.20%via OSV
CVEs tagged “osv” — page 113 · VulnSea