Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
GHSA-3wqc-mwfx-672pHigh· 7.5Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
CVE-2025-32434CriticalPoCPyTorch: `torch.load` with `weights_only=True` leads to remote code execution
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
CVE-2025-28197MediumCrawl4AI SSRF vulnerability
Crawl4AI SSRF vulnerability
CVE-2025-32377Medium· 6.5Rasa Pro Missing Authentication For Voice Connector APIs
Rasa Pro Missing Authentication For Voice Connector APIs
CVE-2025-27936Medium· 5.3Mattermost vulnerable to Observable Timing Discrepancy
Mattermost vulnerable to Observable Timing Discrepancy
CVE-2025-3730Low· 3.3PyTorch Improper Resource Shutdown or Release vulnerability
PyTorch Improper Resource Shutdown or Release vulnerability
CVE-2024-53305HighWhoogle allows attackers to execute arbitrary code via supplying a crafted search query
Whoogle allows attackers to execute arbitrary code via supplying a crafted search query
CVE-2025-3445High· 8.1mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
CVE-2025-2475Medium· 5.4Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
CVE-2025-32093Medium· 4.7Mattermost Fails to Restrict Certain Operations on System Admins
Mattermost Fails to Restrict Certain Operations on System Admins
CVE-2025-1386MediumCVE-2025-1386- Query smuggling in ch-go library
CVE-2025-1386- Query smuggling in ch-go library
CVE-2025-32387Medium· 6.5Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
CVE-2025-32386Medium· 6.5Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
CVE-2025-32381Medium· 6.5xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory
xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory
CVE-2025-71351MediumPicklescan missing detection when calling built-in python library function timeit.timeit()
Picklescan missing detection when calling built-in python library function timeit.timeit()
CVE-2025-71355MediumPicklescan failed to detect to some unsafe global function in Numpy library
Picklescan failed to detect to some unsafe global function in Numpy library
CVE-2025-46417HighPicklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
CVE-2025-30473High· 8.8Apache Airflow Common SQL Provider Vulnerable to SQL Injection
Apache Airflow Common SQL Provider Vulnerable to SQL Injection
CVE-2025-27520Critical· 9.8PoCBentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
CVE-2025-31489HighPoCMinIO performs incomplete signature validation for unsigned-trailer uploads
MinIO performs incomplete signature validation for unsigned-trailer uploads
CVE-2025-30370High· 7.4jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"
jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"
CVE-2025-3160Low· 3.3A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the fu…
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the compone…
CVE-2025-3159High· 7.8A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp:…
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component…
CVE-2025-3163Medium· 5.3InternLM LMDeploy code injection vulnerability
InternLM LMDeploy code injection vulnerability
CVE-2025-3162Medium· 5.3LMDeploy Improper Input Validation Vulnerability
LMDeploy Improper Input Validation Vulnerability
CVE-2023-27591High· 7.5Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
CVE-2025-30223Critical· 9.3Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input
Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input
CVE-2025-3016Medium· 6.5A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function As…
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the …
CVE-2025-3015High· 8.8A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImp…
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE Fi…
CVE-2025-3001NoneA vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulat…
A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disc…