VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2024-53863High
1y ago

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

▾ Twilightmatrix-synapse · matrix-synapseEPSS 0.61%via OSV
CVE-2024-52805High
1y ago

Synapse allows unsupported content types to lead to memory exhaustion

Synapse allows unsupported content types to lead to memory exhaustion

▾ Twilightmatrix-synapse · matrix-synapseEPSS 0.74%via OSV
CVE-2024-52815High
1y ago

Synapse allows a a malformed invite to break the invitee's `/sync`

Synapse allows a a malformed invite to break the invitee's `/sync`

▾ Twilightmatrix-synapse · matrix-synapseEPSS 0.57%via OSV
CVE-2024-53999Medium· 6.1
1y ago

Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality

Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality

▾ Sunlitmobsf · mobsfEPSS 0.52%via OSV
CVE-2024-53867Medium· 4.3
1y ago

Synapse Matrix has a partial room state leak via Sliding Sync

Synapse Matrix has a partial room state leak via Sliding Sync

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.44%via OSV
CVE-2024-53848High· 7.1
1y ago

check-jsonschema default caching for remote schemas allows for cache confusion

check-jsonschema default caching for remote schemas allows for cache confusion

▾ Twilightcheck-jsonschema · check-jsonschemaEPSS 0.14%via OSV
CVE-2024-53865High· 8.2
1y ago

Python package "zhmcclient" stores passwords in clear text in its HMC and API logs

Python package "zhmcclient" stores passwords in clear text in its HMC and API logs

▾ Twilightzhmcclient · zhmcclientEPSS 0.14%via OSV
CVE-2024-53861Low· 2.2
1y ago

PyJWT Issuer field partial matches allowed

PyJWT Issuer field partial matches allowed

▾ Sunlitpyjwt · pyjwtEPSS 0.83%via OSV
CVE-2024-53981High· 7.5
1y ago

Denial of service (DoS) via deformation `multipart/form-data` boundary

Denial of service (DoS) via deformation `multipart/form-data` boundary

▾ Twilightpython-multipart · python-multipartEPSS 0.64%via OSV
CVE-2024-36621Medium· 6.5
1y ago

Moby Race Condition vulnerability

Moby Race Condition vulnerability

▾ Sunlitmoby · github.com/moby/mobyEPSS 0.63%via OSV
CVE-2024-39162Medium· 6.1
1y ago

pyspider Cross-site Scripting vulnerability

pyspider Cross-site Scripting vulnerability

▾ Sunlitpyspider · pyspiderEPSS 0.41%via OSV
CVE-2024-53859Medium· 6.5
1y ago

`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace

`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace

▾ Sunlitcli · github.com/cli/go-gh/v2EPSS 0.53%via OSV
CVE-2024-52008Medium· 5.7
1y ago

Password Policy Bypass Vulnerability in Fides Webserver User Accept Invite API

Password Policy Bypass Vulnerability in Fides Webserver User Accept Invite API

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.56%via OSV
CVE-2024-53916High· 7.5
1y ago

OpenStack Neutron can use an incorrect ID during policy enforcement

OpenStack Neutron can use an incorrect ID during policy enforcement

▾ Twilightneutron · neutronEPSS 0.71%via OSV
CVE-2024-52787Critical· 9.1
1y ago

libre-chat Path Traversal vulnerability

libre-chat Path Traversal vulnerability

▾ Midnightlibre-chat · libre-chatEPSS 0.77%via OSV
CVE-2024-53899High· 8.4
1y ago

virtualenv allows command injection through activation scripts for a virtual environment

virtualenv allows command injection through activation scripts for a virtual environment

▾ Twilightvirtualenv · virtualenvEPSS 1.6%via OSV
CVE-2024-11393High· 8.80dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 3.1%via OSV
CVE-2024-11392High· 7.50dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 7.3%via OSV
CVE-2024-11394High· 8.80dayPoC
1y ago

Deserialization of Untrusted Data in Hugging Face Transformers

Deserialization of Untrusted Data in Hugging Face Transformers

▾ Abyssaltransformers · transformersEPSS 2.6%via OSV
CVE-2024-10220High· 8.1PoC
1y ago

Kubernetes kubelet arbitrary command execution

Kubernetes kubelet arbitrary command execution

▾ Midnightkubernetes · k8s.io/kubernetesEPSS 3.0%via OSV
CVE-2024-52804High· 7.5
1y ago

Tornado has an HTTP cookie parsing DoS vulnerability

Tornado has an HTTP cookie parsing DoS vulnerability

▾ Twilighttornado · tornadoEPSS 1.0%via OSV
CVE-2023-40017High· 7.5
1y ago

GeoNode Server Side Request forgery

GeoNode Server Side Request forgery

▾ Twilightgeonode · geonodeEPSS 0.76%via OSV
CVE-2024-52803High· 7.5
1y ago

LLama Factory Remote OS Command Injection Vulnerability

LLama Factory Remote OS Command Injection Vulnerability

▾ Twilightllamafactory · llamafactoryEPSS 2.3%via OSV
CVE-2024-11406Medium· 6.9
1y ago

django CMS Attributes Field Cross-site Scripting

django CMS Attributes Field Cross-site Scripting

▾ Sunlitdjangocms-attributes-field · djangocms-attributes-fieldEPSS 0.47%via OSV
CVE-2024-11404Medium· 5.5
1y ago

Django Filer Unrestricted Upload of File with Dangerous Type

Django Filer Unrestricted Upload of File with Dangerous Type

▾ Sunlitdjango-filer · django-filerEPSS 0.36%via OSV
CVE-2024-52581High· 7.5
1y ago

Litestar allows unbounded resource consumption (DoS vulnerability)

Litestar allows unbounded resource consumption (DoS vulnerability)

▾ Twilightlitestar · litestarEPSS 0.79%via OSV
CVE-2024-52304Medium
1y ago

aiohttp allows request smuggling due to incorrect parsing of chunk extensions

aiohttp allows request smuggling due to incorrect parsing of chunk extensions

▾ Sunlitaiohttp · aiohttpEPSS 0.56%via OSV
CVE-2024-52303High· 7.5
1y ago

aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method

aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method

▾ Twilightaiohttp · aiohttpEPSS 0.59%via OSV
CVE-2023-6110Medium· 5.5
1y ago

OpenStack improperly deletes access rules

OpenStack improperly deletes access rules

▾ Sunlitpython-openstackclient · python-openstackclientEPSS 0.49%via OSV
CVE-2021-3988Medium· 6.1
1y ago

Cross-site Scripting (XSS) - DOM in janeczku/calibre-web

Cross-site Scripting (XSS) - DOM in janeczku/calibre-web

▾ Sunlitcalibreweb · calibrewebEPSS 0.36%via OSV
CVEs tagged “osv” — page 121 · VulnSea