VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2025-24804Medium· 6.5
1y ago

MobSF Partial Denial of Service (DoS)

MobSF Partial Denial of Service (DoS)

▾ Sunlitmobsf · mobsfEPSS 0.46%via OSV
CVE-2025-24803High· 8.1
1y ago

MobSF Stored Cross-Site Scripting (XSS)

MobSF Stored Cross-Site Scripting (XSS)

▾ Twilightmobsf · mobsfEPSS 0.39%via OSV
CVE-2025-24372High· 7.3
1y ago

CKAN has an XSS vector in user uploaded images in group/org and user profiles

CKAN has an XSS vector in user uploaded images in group/org and user profiles

▾ Twilightckan · ckanEPSS 0.46%via OSV
CVE-2025-24805Medium· 6.5
1y ago

MobSF Local Privilege Escalation

MobSF Local Privilege Escalation

▾ Sunlitmobsf · mobsfEPSS 0.36%via OSV
CVE-2025-23216Medium· 6.8
1y ago

Argo CD does not scrub secret values from patch errors

Argo CD does not scrub secret values from patch errors

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.47%via OSV
GHSA-274v-mgcv-cm8jMedium· 6.8
1y ago

Argo CD GitOps Engine does not scrub secret values from patch errors

Argo CD GitOps Engine does not scrub secret values from patch errors

▾ Sunlitargoproj · github.com/argoproj/gitops-enginevia OSV
CVE-2025-24795Medium· 4.4
1y ago

snowflake-connector-python vulnerable to insecure cache files permissions

snowflake-connector-python vulnerable to insecure cache files permissions

▾ Sunlitsnowflake-connector-python · snowflake-connector-pythonEPSS 0.14%via OSV
CVE-2025-24794Medium· 6.7
1y ago

snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache

snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache

▾ Sunlitsnowflake-connector-python · snowflake-connector-pythonEPSS 0.25%via OSV
CVE-2025-24793High· 7.0
1y ago

snowflake-connector-python vulnerable to SQL Injection in write_pandas

snowflake-connector-python vulnerable to SQL Injection in write_pandas

▾ Twilightsnowflake-connector-python · snowflake-connector-pythonEPSS 0.31%via OSV
CVE-2024-45339High· 7.1
1y ago

Insecure Temporary File usage in github.com/golang/glog

Insecure Temporary File usage in github.com/golang/glog

▾ Twilightgolang · github.com/golang/glogEPSS 0.32%via OSV
CVE-2025-24357High· 7.5
1y ago

vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

▾ Twilightvllm · vllmEPSS 0.70%via OSV
CVE-2025-24359High· 8.4
1y ago

ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape

ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape

▾ Twilightasteval · astevalEPSS 0.28%via OSV
CVE-2025-22153High· 7.9
1y ago

try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter

try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter

▾ Twilightrestrictedpython · restrictedpythonEPSS 0.40%via OSV
CVE-2024-11218High· 8.6
1y ago

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it …

▾ Twilightcontainers · github.com/containers/buildahEPSS 0.36%via NVD
CVE-2025-23205High
1y ago

nbgrader's `frame-ancestors: self` grants all users access to formgrader

nbgrader's `frame-ancestors: self` grants all users access to formgrader

▾ Twilightnbgrader · nbgraderEPSS 0.47%via OSV
CVE-2024-5138Medium· 4.0
1y ago

CVE-2024-5138: snapd snapctl auth bypass

CVE-2024-5138: snapd snapctl auth bypass

▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.83%via OSV
CVE-2024-50633None· 0.0PoC
1y ago

Indico Insecure Access

Indico Insecure Access

▾ Twilightindico · indicoEPSS 0.63%via OSV
CVE-2025-20086Medium· 6.5
1y ago

Mattermost fails to properly validate post props

Mattermost fails to properly validate post props

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.43%via OSV
CVE-2025-20088Medium· 6.5
1y ago

Mattermost fails to properly validate post props

Mattermost fails to properly validate post props

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.56%via OSV
CVE-2025-5791High· 7.1
1y ago

users: `root` appended to group listings (CVE-2025-5791)

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in th…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2024-52281High· 8.9
1y ago

Rancher UI has Stored Cross-site Scripting vulnerability

Rancher UI has Stored Cross-site Scripting vulnerability

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.55%via OSV
CVE-2025-21607Low
1y ago

Vyper Does Not Check the Success of Certain Precompile Calls

Vyper Does Not Check the Success of Certain Precompile Calls

▾ Sunlitvyper · vyperEPSS 0.65%via OSV
CVE-2024-56374Medium· 5.8
1y ago

Django has a potential denial-of-service vulnerability in IPv6 validation

Django has a potential denial-of-service vulnerability in IPv6 validation

▾ Sunlitdjango · djangoEPSS 1.9%via OSV
CVE-2024-56138Medium· 4.0
1y ago

notation-go's timestamp signature generation lacks certificate revocation check

notation-go's timestamp signature generation lacks certificate revocation check

▾ Sunlitnotaryproject · github.com/notaryproject/notation-goEPSS 0.13%via OSV
CVE-2024-56323Medium
1y ago

OpenFGA Authorization Bypass

OpenFGA Authorization Bypass

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.45%via OSV
CVE-2025-22445Low· 3.5
1y ago

Mattermost has Improper Check for Unusual or Exceptional Conditions

Mattermost has Improper Check for Unusual or Exceptional Conditions

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.32%via OSV
CVE-2025-20033Medium· 4.3
1y ago

Mattermost Improper Validation of Specified Type of Input vulnerability

Mattermost Improper Validation of Specified Type of Input vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.62%via OSV
CVE-2023-1907High· 8.0
1y ago

pgAdmin has Incorrect Default Permissions

pgAdmin has Incorrect Default Permissions

▾ Twilightpgadmin4 · pgadmin4EPSS 0.45%via OSV
CVE-2025-22151Low· 3.7
1y ago

Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution

Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution

▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.38%via OSV
CVE-2024-55459Medium
1y ago

keras Path Traversal vulnerability

keras Path Traversal vulnerability

▾ Sunlitkeras · kerasEPSS 0.23%via OSV
CVEs tagged “osv” — page 119 · VulnSea