VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5666 CVEsRSS

CVE-2026-53715Medium· 5.3
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map…

▾ Sunlitenvoyproxy · gatewayEPSS 0.47%via NVD
CVE-2026-53713Critical· 9.1
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not col…

▾ Midnightenvoyproxy · gatewayEPSS 0.43%via NVD
CVE-2026-53714High· 7.4
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deplo…

▾ Twilightenvoyproxy · gatewayEPSS 0.35%via NVD
CVE-2026-54334Critical· 9.8
2w ago

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT …

▾ Midnighttheopolis · uefi-firmware-parserEPSS 0.80%via NVD
CVE-2026-54333Critical· 9.8
2w ago

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that bit-length values read…

▾ Midnighttheopolis · uefi-firmware-parserEPSS 0.80%via NVD
RUSTSEC-2026-0283None
2w ago

clear_on_drop is unmaintained

clear_on_drop is unmaintained

▾ Sunlitclear_on_drop · clear_on_dropvia OSV
MAL-2026-16143Critical⚠ Exploited
2w ago

Malicious code in chroma-client (PyPI)

Malicious code in chroma-client (PyPI)

▾ Abyssalchroma-client · chroma-clientvia OSV
RUSTSEC-2026-0298None
2w ago

Use-after-free when a future's `Drop` panics while the container is dropped

Use-after-free when a future's `Drop` panics while the container is dropped

▾ Sunlitunicycle · unicyclevia OSV
CVE-2026-90553High· 7.8
2w ago

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbi…

▾ Twilightvllm · vllmEPSS 0.31%via NVD
MAL-2026-16142Critical⚠ Exploited
2w ago

Malicious code in python-fork (PyPI)

Malicious code in python-fork (PyPI)

▾ Abyssalpython-fork · python-forkvia OSV
MAL-2026-16164Critical⚠ Exploited
2w ago

Malicious code in logs_update (crates.io)

Malicious code in logs_update (crates.io)

▾ Abyssallogs-update · logs-updatevia OSV
CVE-2026-89090Medium· 5.9
2w ago

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …

▾ SunlitAWS · AWS SDK for Go v2EPSS 0.30%via NVD
MAL-2026-16141Critical⚠ Exploited
2w ago

Malicious code in platform-telemetry-client (PyPI)

Malicious code in platform-telemetry-client (PyPI)

▾ Abyssalplatform-telemetry-client · platform-telemetry-clientvia OSV
MAL-2026-16136Critical⚠ Exploited
2w ago

Malicious code in transfomers (PyPI)

Malicious code in transfomers (PyPI)

▾ Abyssaltransfomers · transfomersvia OSV
MAL-2026-16135Critical⚠ Exploited
2w ago

Malicious code in openaii (PyPI)

Malicious code in openaii (PyPI)

▾ Abyssalopenaii · openaiivia OSV
MAL-2026-16134Critical⚠ Exploited
2w ago

Malicious code in ollamaa (PyPI)

Malicious code in ollamaa (PyPI)

▾ Abyssalollamaa · ollamaavia OSV
MAL-2026-16133Critical⚠ Exploited
2w ago

Malicious code in langgrap (PyPI)

Malicious code in langgrap (PyPI)

▾ Abyssallanggrap · langgrapvia OSV
MAL-2026-16131Critical⚠ Exploited
2w ago

Malicious code in aitextutils-py (PyPI)

Malicious code in aitextutils-py (PyPI)

▾ Abyssalaitextutils-py · aitextutils-pyvia OSV
MAL-2026-16130Critical⚠ Exploited
2w ago

Malicious code in aitextkit-py (PyPI)

Malicious code in aitextkit-py (PyPI)

▾ Abyssalaitextkit-py · aitextkit-pyvia OSV
MAL-2026-16129Critical⚠ Exploited
2w ago

Malicious code in web3-eth-account (PyPI)

Malicious code in web3-eth-account (PyPI)

▾ Abyssalweb3-eth-account · web3-eth-accountvia OSV
MAL-2026-16128Critical⚠ Exploited
2w ago

Malicious code in pymem-win (PyPI)

Malicious code in pymem-win (PyPI)

▾ Abyssalpymem-win · pymem-winvia OSV
MAL-2026-16127Critical⚠ Exploited
2w ago

Malicious code in eth-account-web3 (PyPI)

Malicious code in eth-account-web3 (PyPI)

▾ Abyssaleth-account-web3 · eth-account-web3via OSV
CVE-2026-56665Medium· 4.2
2w ago

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.27%via OSV
CVE-2026-59151Critical· 9.6
2w ago

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

▾ Midnightprowler-cloud · prowler-cloudEPSS 0.53%via OSV
CVE-2026-88046Medium· 5.3
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject parent-directory segments in source Object.Remote() values before fs/list, fs/walk…

▾ Sunlitrclone · rcloneEPSS 0.37%via NVD
CVE-2026-88018Critical· 9.8PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any …

▾ Abyssalrclone · rcloneEPSS 0.75%via NVD
CVE-2026-88017High· 7.3
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in the se…

▾ Twilightrclone · rcloneEPSS 0.43%via NVD
CVE-2026-88012Medium· 5.3
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the timeout is enforced on a TCP connectio…

▾ Sunlittraefik · traefikEPSS 0.52%via NVD
CVE-2026-88044Critical· 9.1PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 const…

▾ Abyssalrclone · rcloneEPSS 0.56%via NVD
CVE-2026-88015Medium· 5.3PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.De…

▾ Twilightrclone · rcloneEPSS 0.51%via NVD
CVEs tagged “osv” — page 12 · VulnSea