Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2025-24804Medium· 6.5MobSF Partial Denial of Service (DoS)
MobSF Partial Denial of Service (DoS)
CVE-2025-24803High· 8.1MobSF Stored Cross-Site Scripting (XSS)
MobSF Stored Cross-Site Scripting (XSS)
CVE-2025-24372High· 7.3CKAN has an XSS vector in user uploaded images in group/org and user profiles
CKAN has an XSS vector in user uploaded images in group/org and user profiles
CVE-2025-24805Medium· 6.5MobSF Local Privilege Escalation
MobSF Local Privilege Escalation
CVE-2025-23216Medium· 6.8Argo CD does not scrub secret values from patch errors
Argo CD does not scrub secret values from patch errors
GHSA-274v-mgcv-cm8jMedium· 6.8Argo CD GitOps Engine does not scrub secret values from patch errors
Argo CD GitOps Engine does not scrub secret values from patch errors
CVE-2025-24795Medium· 4.4snowflake-connector-python vulnerable to insecure cache files permissions
snowflake-connector-python vulnerable to insecure cache files permissions
CVE-2025-24794Medium· 6.7snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache
snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache
CVE-2025-24793High· 7.0snowflake-connector-python vulnerable to SQL Injection in write_pandas
snowflake-connector-python vulnerable to SQL Injection in write_pandas
CVE-2024-45339High· 7.1Insecure Temporary File usage in github.com/golang/glog
Insecure Temporary File usage in github.com/golang/glog
CVE-2025-24357High· 7.5vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
CVE-2025-24359High· 8.4ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape
ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape
CVE-2025-22153High· 7.9try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter
try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter
CVE-2024-11218High· 8.6A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it …
CVE-2025-23205Highnbgrader's `frame-ancestors: self` grants all users access to formgrader
nbgrader's `frame-ancestors: self` grants all users access to formgrader
CVE-2024-5138Medium· 4.0CVE-2024-5138: snapd snapctl auth bypass
CVE-2024-5138: snapd snapctl auth bypass
CVE-2024-50633None· 0.0PoCIndico Insecure Access
Indico Insecure Access
CVE-2025-20086Medium· 6.5Mattermost fails to properly validate post props
Mattermost fails to properly validate post props
CVE-2025-20088Medium· 6.5Mattermost fails to properly validate post props
Mattermost fails to properly validate post props
CVE-2025-5791High· 7.1users: `root` appended to group listings (CVE-2025-5791)
A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in th…
CVE-2024-52281High· 8.9Rancher UI has Stored Cross-site Scripting vulnerability
Rancher UI has Stored Cross-site Scripting vulnerability
CVE-2025-21607LowVyper Does Not Check the Success of Certain Precompile Calls
Vyper Does Not Check the Success of Certain Precompile Calls
CVE-2024-56374Medium· 5.8Django has a potential denial-of-service vulnerability in IPv6 validation
Django has a potential denial-of-service vulnerability in IPv6 validation
CVE-2024-56138Medium· 4.0notation-go's timestamp signature generation lacks certificate revocation check
notation-go's timestamp signature generation lacks certificate revocation check
CVE-2024-56323MediumOpenFGA Authorization Bypass
OpenFGA Authorization Bypass
CVE-2025-22445Low· 3.5Mattermost has Improper Check for Unusual or Exceptional Conditions
Mattermost has Improper Check for Unusual or Exceptional Conditions
CVE-2025-20033Medium· 4.3Mattermost Improper Validation of Specified Type of Input vulnerability
Mattermost Improper Validation of Specified Type of Input vulnerability
CVE-2023-1907High· 8.0pgAdmin has Incorrect Default Permissions
pgAdmin has Incorrect Default Permissions
CVE-2025-22151Low· 3.7Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
CVE-2024-55459Mediumkeras Path Traversal vulnerability
keras Path Traversal vulnerability