Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2024-53863HighSynapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
CVE-2024-52805HighSynapse allows unsupported content types to lead to memory exhaustion
Synapse allows unsupported content types to lead to memory exhaustion
CVE-2024-52815HighSynapse allows a a malformed invite to break the invitee's `/sync`
Synapse allows a a malformed invite to break the invitee's `/sync`
CVE-2024-53999Medium· 6.1Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality
Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality
CVE-2024-53867Medium· 4.3Synapse Matrix has a partial room state leak via Sliding Sync
Synapse Matrix has a partial room state leak via Sliding Sync
CVE-2024-53848High· 7.1check-jsonschema default caching for remote schemas allows for cache confusion
check-jsonschema default caching for remote schemas allows for cache confusion
CVE-2024-53865High· 8.2Python package "zhmcclient" stores passwords in clear text in its HMC and API logs
Python package "zhmcclient" stores passwords in clear text in its HMC and API logs
CVE-2024-53861Low· 2.2PyJWT Issuer field partial matches allowed
PyJWT Issuer field partial matches allowed
CVE-2024-53981High· 7.5Denial of service (DoS) via deformation `multipart/form-data` boundary
Denial of service (DoS) via deformation `multipart/form-data` boundary
CVE-2024-36621Medium· 6.5Moby Race Condition vulnerability
Moby Race Condition vulnerability
CVE-2024-39162Medium· 6.1pyspider Cross-site Scripting vulnerability
pyspider Cross-site Scripting vulnerability
CVE-2024-53859Medium· 6.5`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace
`auth.TokenForHost` violates GitHub host security boundary when sourcing authentication token within a codespace
CVE-2024-52008Medium· 5.7Password Policy Bypass Vulnerability in Fides Webserver User Accept Invite API
Password Policy Bypass Vulnerability in Fides Webserver User Accept Invite API
CVE-2024-53916High· 7.5OpenStack Neutron can use an incorrect ID during policy enforcement
OpenStack Neutron can use an incorrect ID during policy enforcement
CVE-2024-52787Critical· 9.1libre-chat Path Traversal vulnerability
libre-chat Path Traversal vulnerability
CVE-2024-53899High· 8.4virtualenv allows command injection through activation scripts for a virtual environment
virtualenv allows command injection through activation scripts for a virtual environment
CVE-2024-11393High· 8.80dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11392High· 7.50dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11394High· 8.80dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-10220High· 8.1PoCKubernetes kubelet arbitrary command execution
Kubernetes kubelet arbitrary command execution
CVE-2024-52804High· 7.5Tornado has an HTTP cookie parsing DoS vulnerability
Tornado has an HTTP cookie parsing DoS vulnerability
CVE-2023-40017High· 7.5GeoNode Server Side Request forgery
GeoNode Server Side Request forgery
CVE-2024-52803High· 7.5LLama Factory Remote OS Command Injection Vulnerability
LLama Factory Remote OS Command Injection Vulnerability
CVE-2024-11406Medium· 6.9django CMS Attributes Field Cross-site Scripting
django CMS Attributes Field Cross-site Scripting
CVE-2024-11404Medium· 5.5Django Filer Unrestricted Upload of File with Dangerous Type
Django Filer Unrestricted Upload of File with Dangerous Type
CVE-2024-52581High· 7.5Litestar allows unbounded resource consumption (DoS vulnerability)
Litestar allows unbounded resource consumption (DoS vulnerability)
CVE-2024-52304Mediumaiohttp allows request smuggling due to incorrect parsing of chunk extensions
aiohttp allows request smuggling due to incorrect parsing of chunk extensions
CVE-2024-52303High· 7.5aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
CVE-2023-6110Medium· 5.5OpenStack improperly deletes access rules
OpenStack improperly deletes access rules
CVE-2021-3988Medium· 6.1Cross-site Scripting (XSS) - DOM in janeczku/calibre-web
Cross-site Scripting (XSS) - DOM in janeczku/calibre-web