Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2021-3988Medium· 6.1Cross-site Scripting (XSS) - DOM in janeczku/calibre-web
Cross-site Scripting (XSS) - DOM in janeczku/calibre-web
CVE-2021-3986Medium· 4.3Generation of Error Message Containing Sensitive Information in janeczku/calibre-web
Generation of Error Message Containing Sensitive Information in janeczku/calibre-web
CVE-2021-3987Medium· 5.4Improper Access Control in janeczku/calibre-web
Improper Access Control in janeczku/calibre-web
CVE-2024-45784High· 7.5Apache Airflow: Sensitive configuration values are not masked in the logs by default
Apache Airflow: Sensitive configuration values are not masked in the logs by default
RUSTSEC-2024-0401Medium· 5.3Denial of service because of stack overflow with malicious decompression input
Denial of service because of stack overflow with malicious decompression input
CVE-2024-52524MediumReDoS in giskard's transformation.py (GHSL-2024-324)
ReDoS in giskard's transformation.py (GHSL-2024-324)
CVE-2024-4311Medium· 5.4Missing ratelimit on passwrod resets in zenml
Missing ratelimit on passwrod resets in zenml
CVE-2023-34049Medium· 6.7Salt preflight script could be attacker controlled
Salt preflight script could be attacker controlled
CVE-2024-11079Medium· 5.5A flaw was found in Ansible-Core
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote da…
CVE-2024-27529High· 8.4wasm3 uncontrolled memory allocation vulnerability
wasm3 uncontrolled memory allocation vulnerability
CVE-2024-50378Medium· 6.5Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
CVE-2024-51998High· 8.6changedetection.io path traversal using file URI scheme without supplying hostname
changedetection.io path traversal using file URI scheme without supplying hostname
GHSA-p7mv-53f2-4cwjHighCometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data
CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data
CVE-2024-9902Medium· 6.3PoCansible-core Incorrect Authorization vulnerability
ansible-core Incorrect Authorization vulnerability
CVE-2024-48061Critical· 9.8PoCLangflow vulnerable to remote code execution
Langflow vulnerable to remote code execution
CVE-2024-48052Medium· 6.5gradio Server Side Request Forgery vulnerability
gradio Server Side Request Forgery vulnerability
CVE-2024-51744Low· 3.1golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt (CVE-2024-517…
A flaw was found in the golang-jwt package. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are not checking errors in the way they should be. Especially, if a token is both expired and in…
CVE-2024-51734Critical· 9.1Access control vulnerable to user data deletion by anonynmous users
Access control vulnerable to user data deletion by anonynmous users
CVE-2024-51483Medium· 6.5PoCchangedetection.io Path Traversal
changedetection.io Path Traversal
CVE-2024-8185High· 7.5Hashicorp Vault vulnerable to denial of service through memory exhaustion
Hashicorp Vault vulnerable to denial of service through memory exhaustion
CVE-2024-10006High· 8.3hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass (CVE-2024-10006)
A flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).
CVE-2024-47401Medium· 4.3Mattermost Server vulnerable to application crash from attacker-generated large response
Mattermost Server vulnerable to application crash from attacker-generated large response
CVE-2024-46872Medium· 4.6Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
CVE-2024-10241Medium· 4.3Mattermost Server allows user to get private channel names
Mattermost Server allows user to get private channel names
CVE-2024-10452Low· 2.2Grafana org admin can delete pending invites in different org
Grafana org admin can delete pending invites in different org
CVE-2024-8309Medium· 4.9PoCLangchain SQL Injection vulnerability
Langchain SQL Injection vulnerability
GO-2024-3219Nonegithub.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
CVE-2024-49771Medium· 5.3MPXJ has a Potential Path Traversal Vulnerability
MPXJ has a Potential Path Traversal Vulnerability
CVE-2023-32196Critical· 9.1Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
GHSA-7h65-4p22-39j6Critical· 9.8github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses