VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2021-3988Medium· 6.1
1y ago

Cross-site Scripting (XSS) - DOM in janeczku/calibre-web

Cross-site Scripting (XSS) - DOM in janeczku/calibre-web

▾ Sunlitcalibreweb · calibrewebEPSS 0.36%via OSV
CVE-2021-3986Medium· 4.3
1y ago

Generation of Error Message Containing Sensitive Information in janeczku/calibre-web

Generation of Error Message Containing Sensitive Information in janeczku/calibre-web

▾ Sunlitcalibreweb · calibrewebEPSS 0.37%via OSV
CVE-2021-3987Medium· 5.4
1y ago

Improper Access Control in janeczku/calibre-web

Improper Access Control in janeczku/calibre-web

▾ Sunlitcalibreweb · calibrewebEPSS 0.35%via OSV
CVE-2024-45784High· 7.5
1y ago

Apache Airflow: Sensitive configuration values are not masked in the logs by default

Apache Airflow: Sensitive configuration values are not masked in the logs by default

▾ Twilightairflow · airflowEPSS 1.3%via OSV
RUSTSEC-2024-0401Medium· 5.3
1y ago

Denial of service because of stack overflow with malicious decompression input

Denial of service because of stack overflow with malicious decompression input

▾ Sunlitzlib-rs · zlib-rsvia OSV
CVE-2024-52524Medium
1y ago

ReDoS in giskard's transformation.py (GHSL-2024-324)

ReDoS in giskard's transformation.py (GHSL-2024-324)

▾ Sunlitgiskard · giskardEPSS 0.82%via OSV
CVE-2024-4311Medium· 5.4
1y ago

Missing ratelimit on passwrod resets in zenml

Missing ratelimit on passwrod resets in zenml

▾ Sunlitzenml · zenmlEPSS 0.48%via OSV
CVE-2023-34049Medium· 6.7
1y ago

Salt preflight script could be attacker controlled

Salt preflight script could be attacker controlled

▾ Sunlitsalt · saltEPSS 0.19%via OSV
CVE-2024-11079Medium· 5.5
1y ago

A flaw was found in Ansible-Core

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote da…

▾ Sunlitansible-core · ansible-coreEPSS 0.50%via NVD
CVE-2024-27529High· 8.4
1y ago

wasm3 uncontrolled memory allocation vulnerability

wasm3 uncontrolled memory allocation vulnerability

▾ Twilightshareup · github.com/shareup/wasm-interpreter-appleEPSS 0.26%via OSV
CVE-2024-50378Medium· 6.5
1y ago

Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data

Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data

▾ Sunlitapache-airflow · apache-airflowEPSS 1.2%via OSV
CVE-2024-51998High· 8.6
1y ago

changedetection.io path traversal using file URI scheme without supplying hostname

changedetection.io path traversal using file URI scheme without supplying hostname

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.69%via OSV
GHSA-p7mv-53f2-4cwjHigh
1y ago

CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data

CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data

▾ Twilightcometbft · github.com/cometbft/cometbftvia OSV
CVE-2024-9902Medium· 6.3PoC
1y ago

ansible-core Incorrect Authorization vulnerability

ansible-core Incorrect Authorization vulnerability

▾ Twilightansible-core · ansible-coreEPSS 0.26%via OSV
CVE-2024-48061Critical· 9.8PoC
1y ago

Langflow vulnerable to remote code execution

Langflow vulnerable to remote code execution

▾ Abyssallangflow · langflowEPSS 1.5%via OSV
CVE-2024-48052Medium· 6.5
1y ago

gradio Server Side Request Forgery vulnerability

gradio Server Side Request Forgery vulnerability

▾ Sunlitgradio · gradioEPSS 0.47%via OSV
CVE-2024-51744Low· 3.1
1y ago

golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt (CVE-2024-517…

A flaw was found in the golang-jwt package. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are not checking errors in the way they should be. Especially, if a token is both expired and in…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4.16EPSS 0.51%via CSAF
CVE-2024-51734Critical· 9.1
1y ago

Access control vulnerable to user data deletion by anonynmous users

Access control vulnerable to user data deletion by anonynmous users

▾ Midnightaccesscontrol · accesscontrolEPSS 0.43%via OSV
CVE-2024-51483Medium· 6.5PoC
1y ago

changedetection.io Path Traversal

changedetection.io Path Traversal

▾ Twilightchangedetection-io · changedetection-ioEPSS 2.3%via OSV
CVE-2024-8185High· 7.5
1y ago

Hashicorp Vault vulnerable to denial of service through memory exhaustion

Hashicorp Vault vulnerable to denial of service through memory exhaustion

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.48%via OSV
CVE-2024-10006High· 8.3
1y ago

hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass (CVE-2024-10006)

A flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).

▾ TwilightRed Hat · Red Hat OpenShift Dev Spaces (RHOSDS) 3.23EPSS 0.47%via CSAF
CVE-2024-47401Medium· 4.3
1y ago

Mattermost Server vulnerable to application crash from attacker-generated large response

Mattermost Server vulnerable to application crash from attacker-generated large response

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.46%via OSV
CVE-2024-46872Medium· 4.6
1y ago

Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery

Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.15%via OSV
CVE-2024-10241Medium· 4.3
1y ago

Mattermost Server allows user to get private channel names

Mattermost Server allows user to get private channel names

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.29%via OSV
CVE-2024-10452Low· 2.2
1y ago

Grafana org admin can delete pending invites in different org

Grafana org admin can delete pending invites in different org

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 0.49%via OSV
CVE-2024-8309Medium· 4.9PoC
1y ago

Langchain SQL Injection vulnerability

Langchain SQL Injection vulnerability

▾ Twilightlangchain-community · langchain-communityEPSS 14%via OSV
GO-2024-3219None
1y ago

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

▾ Sunlitcrossplane · github.com/crossplane/crossplanevia OSV
CVE-2024-49771Medium· 5.3
1y ago

MPXJ has a Potential Path Traversal Vulnerability

MPXJ has a Potential Path Traversal Vulnerability

▾ Sunlitsf · net.sf.mpxj:mpxjEPSS 0.48%via OSV
CVE-2023-32196Critical· 9.1
1y ago

Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists

Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.55%via OSV
GHSA-7h65-4p22-39j6Critical· 9.8
1y ago

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses

▾ Midnightcrossplane · github.com/crossplane/crossplanevia OSV
CVEs tagged “osv” — page 122 · VulnSea