VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2024-53526Medium· 6.4
1y ago

Composio Command Execution vulnerability

Composio Command Execution vulnerability

▾ Sunlitcomposio-claude · composio-claudeEPSS 0.59%via OSV
CVE-2024-45033Low
1y ago

Apache Airflow Fab Provider Insufficient Session Expiration vulnerability

Apache Airflow Fab Provider Insufficient Session Expiration vulnerability

▾ Sunlitapache-airflow-providers-fab · apache-airflow-providers-fabEPSS 0.95%via OSV
CVE-2024-53995LowPoC
1y ago

GHSL-2024-288: SickChill open redirect in login

GHSL-2024-288: SickChill open redirect in login

▾ Twilightsickchill · sickchillEPSS 0.97%via OSV
CVE-2025-21613None
1y ago

Argument Injection via the URL field in github.com/go-git/go-git

Argument Injection via the URL field in github.com/go-git/go-git

▾ Sunlitgo-git · github.com/go-git/go-git/v4EPSS 1.3%via OSV
CVE-2025-21618High· 7.5
1y ago

NiceGUI On Air authentication issue

NiceGUI On Air authentication issue

▾ Twilightnicegui · niceguiEPSS 0.38%via OSV
CVE-2024-52294Medium· 4.3
1y ago

khoj has an IDOR in subscription management allows unauthorized subscription modifications

khoj has an IDOR in subscription management allows unauthorized subscription modifications

▾ Sunlitkhoj · khojEPSS 0.38%via OSV
CVE-2024-9774Medium· 6.5
1y ago

python-sql SQL injection vulnerability

python-sql SQL injection vulnerability

▾ Sunlitpython-sql · python-sqlEPSS 0.70%via OSV
CVE-2024-56509High· 8.6
1y ago

changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal

changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.70%via OSV
CVE-2024-39025High· 7.5
1y ago

Letta (previously MemGPT) incorrect access control vulnerability

Letta (previously MemGPT) incorrect access control vulnerability

▾ Twilightletta · lettaEPSS 0.40%via OSV
CVE-2024-12745High· 8.0
1y ago

Amazon Redshift Python Connector vulnerable to SQL Injection

Amazon Redshift Python Connector vulnerable to SQL Injection

▾ Twilightredshift-connector · redshift-connectorEPSS 0.53%via OSV
MAL-2025-923None
1y ago

Malicious code in fflask (PyPI)

Malicious code in fflask (PyPI)

▾ Sunlitfflask · fflaskvia OSV
CVE-2024-9427Medium· 5.4
1y ago

Koji Cross-site Scripting

Koji Cross-site Scripting

▾ Sunlitkoji · kojiEPSS 0.30%via OSV
CVE-2024-56326High· 7.8
1y ago

Jinja has a sandbox breakout through indirect reference to format method

Jinja has a sandbox breakout through indirect reference to format method

▾ Twilightjinja2 · jinja2EPSS 0.52%via OSV
CVE-2024-56201High· 8.8
1y ago

Jinja has a sandbox breakout through malicious filenames

Jinja has a sandbox breakout through malicious filenames

▾ Twilightjinja2 · jinja2EPSS 0.31%via OSV
CVE-2024-56327Critical· 9.8
1y ago

pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

▾ Midnightpyrage · pyrageEPSS 0.50%via OSV
GHSA-32gq-x56h-299cMedium
1y ago

age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

▾ Sunlitage · filippo.io/agevia OSV
CVE-2024-56142Medium· 6.5
1y ago

PGHoard Path Traversal vulnerability

PGHoard Path Traversal vulnerability

▾ Sunlitpghoard · pghoardEPSS 0.41%via OSV
CVE-2024-55890MediumPoC
1y ago

D-Tale allows Remote Code Execution through the Custom Filter Input

D-Tale allows Remote Code Execution through the Custom Filter Input

▾ Twilightdtale · dtaleEPSS 2.4%via OSV
CVE-2024-55633Medium· 6.5
1y ago

Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access

Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access

▾ Sunlitapache-superset · apache-supersetEPSS 2.8%via OSV
CVE-2024-55587High· 8.8PoC
1y ago

python-libarchive directory traversal

python-libarchive directory traversal

▾ Midnightpython-libarchive · python-libarchiveEPSS 2.1%via OSV
CVE-2024-45337NonePoC
1y ago

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto

▾ Twilightx · golang.org/x/cryptoEPSS 3.2%via OSV
CVE-2024-55655Low
1y ago

sigstore has insufficient validation of integration timestamp during verification

sigstore has insufficient validation of integration timestamp during verification

▾ Sunlitsigstore · sigstoreEPSS 0.25%via OSV
CVE-2024-53947Critical· 9.8
1y ago

Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions

Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions

▾ Midnightapache-superset · apache-supersetEPSS 0.84%via OSV
CVE-2024-53949Medium· 6.5
1y ago

Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled

Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled

▾ Sunlitapache-superset · apache-supersetEPSS 0.72%via OSV
CVE-2024-46455Medium
1y ago

unstructured XML External Entity (XXE)

unstructured XML External Entity (XXE)

▾ Sunlitunstructured · unstructuredEPSS 0.57%via OSV
CVE-2024-53948Medium· 5.3
1y ago

Apache Superset: Error verbosity exposes metadata in analytics databases

Apache Superset: Error verbosity exposes metadata in analytics databases

▾ Sunlitapache-superset · apache-supersetEPSS 0.85%via OSV
CVE-2024-53908Critical· 9.8
1y ago

Django SQL injection in HasKey(lhs, rhs) on Oracle

Django SQL injection in HasKey(lhs, rhs) on Oracle

▾ Midnightdjango · djangoEPSS 1.4%via OSV
CVE-2024-53907High· 7.5
1y ago

Django denial-of-service in django.utils.html.strip_tags()

Django denial-of-service in django.utils.html.strip_tags()

▾ Twilightdjango · djangoEPSS 1.4%via OSV
CVE-2024-54132Medium
1y ago

Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability

Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability

▾ Sunlitcli · github.com/cli/cli/v2EPSS 0.63%via OSV
CVE-2024-39163High· 8.8
1y ago

pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints

pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints

▾ Twilightpyspider · pyspiderEPSS 0.23%via OSV
CVEs tagged “osv” — page 120 · VulnSea