Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2025-3000Medium· 5.3PyTorch is vulnerable to memory corruption through its torch.jit.script function
PyTorch is vulnerable to memory corruption through its torch.jit.script function
CVE-2025-2999NoneA vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpa…
A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The ex…
CVE-2025-3047Medium· 6.5PoCAWS SAM CLI Path Traversal allows file copy to build container
AWS SAM CLI Path Traversal allows file copy to build container
CVE-2025-3048Medium· 6.5AWS SAM CLI Path Traversal allows file copy to local cache
AWS SAM CLI Path Traversal allows file copy to local cache
CVE-2025-2953Low· 3.3PyTorch susceptible to local Denial of Service
PyTorch susceptible to local Denial of Service
CVE-2025-30355High· 7.1Synapse vulnerable to federation denial of service via malformed events
Synapse vulnerable to federation denial of service via malformed events
CVE-2025-30358High· 8.1Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
CVE-2025-30204NoneExcessive memory allocation during header parsing in github.com/golang-jwt/jwt
Excessive memory allocation during header parsing in github.com/golang-jwt/jwt
CVE-2025-30217MediumFrappe has possibility of SQL injection due to improper validations
Frappe has possibility of SQL injection due to improper validations
CVE-2025-1097High· 8.8PoCngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
CVE-2025-24513Medium· 4.8ingress-nginx controller - auth secret file path traversal vulnerability
ingress-nginx controller - auth secret file path traversal vulnerability
CVE-2025-30213MediumFrappe has Possibility of Remote Code Execution due to improper validation
Frappe has Possibility of Remote Code Execution due to improper validation
CVE-2025-30214HighFrappe vulnerable to information disclosure leading to account takeover
Frappe vulnerable to information disclosure leading to account takeover
CVE-2025-30212MediumFrappe has possibility of SQL injection due to improper validations
Frappe has possibility of SQL injection due to improper validations
CVE-2025-29778Medium· 5.8Kyverno ignores subjectRegExp and IssuerRegExp
Kyverno ignores subjectRegExp and IssuerRegExp
CVE-2025-30162Low· 3.2Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
CVE-2025-2592High· 8.8A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the funct…
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads …
CVE-2025-45286LowReflected XSS in go-httpbin due to unrestricted client control over Content-Type
Reflected XSS in go-httpbin due to unrestricted client control over Content-Type
CVE-2024-8063High· 7.5Ollama Divide by Zero Vulnerability
Ollama Divide by Zero Vulnerability
CVE-2024-8769Critical· 9.1Aim path traversal in LockManager.release_locks
Aim path traversal in LockManager.release_locks
CVE-2024-8019Critical· 9.1PyTorch Lightning path traversal vulnerability
PyTorch Lightning path traversal vulnerability
CVE-2024-7598Low· 3.1Kubernetes kube-apiserver Vulnerable to Race Condition
Kubernetes kube-apiserver Vulnerable to Race Condition
CVE-2024-9052Critical· 9.8vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
CVE-2024-9053Critical· 9.8vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
CVE-2024-11041Critical· 9.8vLLM Deserialization of Untrusted Data vulnerability
vLLM Deserialization of Untrusted Data vulnerability
CVE-2024-11958Critical· 9.8LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection
LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection
CVE-2024-8613High· 8.8A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. …
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, en…
CVE-2024-6577Medium· 6.3TorchServe script references S3 bucket without ensuring ownership or confirming accessibility
TorchServe script references S3 bucket without ensuring ownership or confirming accessibility
CVE-2024-7959High· 7.7Open WebUI has SSRF in /openai/models
Open WebUI has SSRF in /openai/models
CVE-2024-12761High· 7.5imaginAIry Denial of Service (DoS) vulnerability
imaginAIry Denial of Service (DoS) vulnerability