Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2025-29787Highzip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
CVE-2025-29779MediumPost-Quantum Secure Feldman's Verifiable Secret Sharing has Inadequate Fault Injection Countermeasures in `secure_redundant_execution`
Post-Quantum Secure Feldman's Verifiable Secret Sharing has Inadequate Fault Injection Countermeasures in `secure_redundant_execution`
CVE-2025-29780MediumPost-Quantum Secure Feldman's Verifiable Secret Sharing has Timing Side-Channels in Matrix Operations
Post-Quantum Secure Feldman's Verifiable Secret Sharing has Timing Side-Channels in Matrix Operations
CVE-2025-1767Medium· 6.5Kubernetes GitRepo Volume Inadvertent Local Repository Access
Kubernetes GitRepo Volume Inadvertent Local Repository Access
CVE-2024-27763Medium· 5.3XPixelGroup BasicSR Command Injection
XPixelGroup BasicSR Command Injection
CVE-2025-1550HighPoCArbitrary Code Execution via Crafted Keras Config for Model Loading
Arbitrary Code Execution via Crafted Keras Config for Model Loading
CVE-2025-24986Medium· 6.5Azure PromptFlow remote code execution related to Jinja templates
Azure PromptFlow remote code execution related to Jinja templates
CVE-2025-26699Medium· 5.0Django vulnerable to Allocation of Resources Without Limits or Throttling
Django vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2025-1979Medium· 6.4ray vulnerable to Insertion of Sensitive Information into Log File
ray vulnerable to Insertion of Sensitive Information into Log File
CVE-2025-27516Medium· 7.3Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
CVE-2025-25362Critical· 9.8Spacy-LLM Server-Side Template Injection (SSTI) vulnerability
Spacy-LLM Server-Side Template Injection (SSTI) vulnerability
CVE-2025-24023Low· 3.7Flask-AppBuilder Observable Response Discrepancy
Flask-AppBuilder Observable Response Discrepancy
CVE-2025-1716Critical· 9.8PoCpicklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft …
picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and include a malicious pickle file with a non-standard file exte…
CVE-2025-1300Medium· 6.1CodeChecker open redirect when URL contains multiple slashes after the product name
CodeChecker open redirect when URL contains multiple slashes after the product name
CVE-2025-27154HighSpotipy's cache file, containing spotify auth token, is created with overly broad permissions
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
CVE-2025-23387Medium· 5.3Rancher's SAML-based login via CLI can be denied by unauthenticated users
Rancher's SAML-based login via CLI can be denied by unauthenticated users
CVE-2025-27145Low· 3.6copyparty renders unsanitized filenames as HTML when user uploads empty files
copyparty renders unsanitized filenames as HTML when user uploads empty files
CVE-2025-25279Critical· 9.9PoCMattermost allows reading arbitrary files related to importing boards
Mattermost allows reading arbitrary files related to importing boards
CVE-2025-1403High· 8.6Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
CVE-2025-26623MediumExiv2 allows Use After Free
Exiv2 allows Use After Free
CVE-2025-25305High· 7.0Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
CVE-2025-25296Medium· 6.1PoCLabel Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
CVE-2025-25295HighLabel Studio has a Path Traversal Vulnerability via image Field
Label Studio has a Path Traversal Vulnerability via image Field
CVE-2025-25297High· 8.6Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
CVE-2024-12366Critical· 9.8PandasAI interactive prompt function Remote Code Execution (RCE)
PandasAI interactive prompt function Remote Code Execution (RCE)
CVE-2024-12797LowVulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2025-22866Medium· 5.3Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec
Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec
CVE-2025-25183Low· 2.6vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
CVE-2025-23217HighMitmweb API Authentication Bypass Using Proxy Server
Mitmweb API Authentication Bypass Using Proxy Server
CVE-2025-26260Medium· 6.5Plenti - Code Injection - Denial of Services
Plenti - Code Injection - Denial of Services