VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2024-49767High· 7.5
1y ago

Werkzeug possible resource exhaustion when parsing file data in forms

Werkzeug possible resource exhaustion when parsing file data in forms

▾ Twilightwerkzeug · werkzeugEPSS 1.1%via OSV
CVE-2024-49766Medium
1y ago

Werkzeug safe_join not safe on Windows

Werkzeug safe_join not safe on Windows

▾ Sunlitwerkzeug · werkzeugEPSS 0.78%via OSV
CVE-2024-49750Medium· 5.5
1y ago

The Snowflake Connector for Python stores sensitive data in logs

The Snowflake Connector for Python stores sensitive data in logs

▾ Sunlitsnowflake-connector-python · snowflake-connector-pythonEPSS 0.20%via OSV
CVE-2024-47825Medium· 4.0
1y ago

Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present

Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.40%via OSV
CVE-2024-24826Medium· 5.5
1y ago

Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder

Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder

▾ Sunlitexiv2 · exiv2EPSS 0.24%via OSV
CVE-2024-25112Medium· 5.5
1y ago

Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder

Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder

▾ Sunlitexiv2 · exiv2EPSS 0.22%via OSV
CVE-2024-10073Medium· 5.0
1y ago

Flair allows arbitrary code execution

Flair allows arbitrary code execution

▾ Sunlitflair · flairEPSS 0.61%via OSV
CVE-2024-32651Critical· 10.0PoC
1y ago

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution

▾ Abyssalchangedetection-io · changedetection-ioEPSS 84%via OSV
CVE-2024-21272High· 7.5
1y ago

MySQL Connector/Python connector takeover vulnerability

MySQL Connector/Python connector takeover vulnerability

▾ Twilightmysql-connector-python · mysql-connector-pythonEPSS 0.51%via OSV
CVE-2024-47874None· 0.0
1y ago

Starlette Denial of service (DoS) via multipart/form-data

Starlette Denial of service (DoS) via multipart/form-data

▾ Sunlitstarlette · starletteEPSS 0.65%via OSV
CVE-2024-6971Low· 3.4
1y ago

Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py

Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py

▾ Sunlitlollms · lollmsEPSS 0.32%via OSV
GHSA-26jh-r8g2-6fprMedium· 5.3
1y ago

Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list

Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list

▾ Sunlitgradio · gradiovia OSV
CVE-2024-9180High· 7.2
1y ago

Vault Community Edition privilege escalation vulnerability

Vault Community Edition privilege escalation vulnerability

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.53%via OSV
CVE-2024-7041Medium· 6.5
1y ago

open-webui Insecure Direct Object Reference (IDOR) vulnerability

open-webui Insecure Direct Object Reference (IDOR) vulnerability

▾ Sunlitopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2024-7038Low· 2.7
1y ago

open-webui allows enumeration of file names and traversal of directories by observing the error messages

open-webui allows enumeration of file names and traversal of directories by observing the error messages

▾ Sunlitopen-webui · open-webuiEPSS 0.34%via OSV
CVE-2024-7037Medium· 6.5
1y ago

open-webui allows writing and deleting arbitrary files

open-webui allows writing and deleting arbitrary files

▾ Sunlitopen-webui · open-webuivia OSV
CVE-2024-9675High· 7.8⚖ disputed
1y ago

A vulnerability was found in Buildah

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the…

▾ Twilightbuildah_project · buildahEPSS 0.39%via NVD
CVE-2024-45231Low· 3.7
1y ago

Django allows enumeration of user e-mail addresses

Django allows enumeration of user e-mail addresses

▾ Sunlitdjango · djangoEPSS 0.79%via OSV
CVE-2024-25885Medium· 5.3
1y ago

xhtml2pdf Denial of Service via crafted string

xhtml2pdf Denial of Service via crafted string

▾ Sunlitxhtml2pdf · xhtml2pdfEPSS 0.64%via OSV
CVE-2024-47211Medium· 5.3
1y ago

OpenStack Ironic fails to verify checksums of supplied image_source URLs

OpenStack Ironic fails to verify checksums of supplied image_source URLs

▾ Sunlitironic · ironicEPSS 0.66%via OSV
CVE-2024-47534High· 7.5
1y ago

Incorrect delegation lookups can make go-tuf download the wrong artifact

Incorrect delegation lookups can make go-tuf download the wrong artifact

▾ Twilighttheupdateframework · github.com/theupdateframework/go-tuf/v2EPSS 0.51%via OSV
CVE-2024-9355Medium· 6.5
1y ago

A vulnerability was found in Golang FIPS OpenSSL

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false posi…

▾ Sunlitgolang-fips · github.com/golang-fips/opensslEPSS 0.30%via NVD
CVE-2024-9277Low· 3.5
2y ago

Inefficient Regular Expression Complexity in langflow

Inefficient Regular Expression Complexity in langflow

▾ Sunlitlangflow · langflowEPSS 0.96%via OSV
CVE-2024-47003Medium· 5.4
2y ago

Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events

Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.58%via OSV
CVE-2024-7594High· 7.5
2y ago

Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default

Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.27%via OSV
CVE-2024-46488Critical· 9.1
2y ago

Heap-based Buffer Overflow in sqlite-vec

Heap-based Buffer Overflow in sqlite-vec

▾ Midnightsqlite-vec · sqlite-vecEPSS 0.44%via OSV
CVE-2024-9014High· 8.6PoC
2y ago

OAuth2 client ID and secret exposed through the web browser

OAuth2 client ID and secret exposed through the web browser

▾ Midnightpgadmin4 · pgadmin4EPSS 9.7%via OSV
CVE-2024-47226Medium· 5.4
2y ago

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel …

A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or H…

▾ Sunlitpynetbox · pynetboxEPSS 0.31%via OSV
CVE-2024-45793Medium· 4.8
2y ago

Prevent XSS from Confidant API call

Prevent XSS from Confidant API call

▾ Sunlitconfidant · confidantEPSS 0.36%via OSV
CVE-2024-8375Medium· 6.1
2y ago

Reverb use after free vulnerability

Reverb use after free vulnerability

▾ Sunlitdm-reverb · dm-reverbEPSS 0.12%via OSV
CVEs tagged “osv” — page 123 · VulnSea