Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2024-49767High· 7.5Werkzeug possible resource exhaustion when parsing file data in forms
Werkzeug possible resource exhaustion when parsing file data in forms
CVE-2024-49766MediumWerkzeug safe_join not safe on Windows
Werkzeug safe_join not safe on Windows
CVE-2024-49750Medium· 5.5The Snowflake Connector for Python stores sensitive data in logs
The Snowflake Connector for Python stores sensitive data in logs
CVE-2024-47825Medium· 4.0Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
CVE-2024-24826Medium· 5.5Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder
Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder
CVE-2024-25112Medium· 5.5Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder
Exiv2 has a denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder
CVE-2024-10073Medium· 5.0Flair allows arbitrary code execution
Flair allows arbitrary code execution
CVE-2024-32651Critical· 10.0PoCchangedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
CVE-2024-21272High· 7.5MySQL Connector/Python connector takeover vulnerability
MySQL Connector/Python connector takeover vulnerability
CVE-2024-47874None· 0.0Starlette Denial of service (DoS) via multipart/form-data
Starlette Denial of service (DoS) via multipart/form-data
CVE-2024-6971Low· 3.4Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py
Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py
GHSA-26jh-r8g2-6fprMedium· 5.3Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
CVE-2024-9180High· 7.2Vault Community Edition privilege escalation vulnerability
Vault Community Edition privilege escalation vulnerability
CVE-2024-7041Medium· 6.5open-webui Insecure Direct Object Reference (IDOR) vulnerability
open-webui Insecure Direct Object Reference (IDOR) vulnerability
CVE-2024-7038Low· 2.7open-webui allows enumeration of file names and traversal of directories by observing the error messages
open-webui allows enumeration of file names and traversal of directories by observing the error messages
CVE-2024-7037Medium· 6.5open-webui allows writing and deleting arbitrary files
open-webui allows writing and deleting arbitrary files
CVE-2024-9675High· 7.8⚖ disputedA vulnerability was found in Buildah
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the…
CVE-2024-45231Low· 3.7Django allows enumeration of user e-mail addresses
Django allows enumeration of user e-mail addresses
CVE-2024-25885Medium· 5.3xhtml2pdf Denial of Service via crafted string
xhtml2pdf Denial of Service via crafted string
CVE-2024-47211Medium· 5.3OpenStack Ironic fails to verify checksums of supplied image_source URLs
OpenStack Ironic fails to verify checksums of supplied image_source URLs
CVE-2024-47534High· 7.5Incorrect delegation lookups can make go-tuf download the wrong artifact
Incorrect delegation lookups can make go-tuf download the wrong artifact
CVE-2024-9355Medium· 6.5A vulnerability was found in Golang FIPS OpenSSL
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false posi…
CVE-2024-9277Low· 3.5Inefficient Regular Expression Complexity in langflow
Inefficient Regular Expression Complexity in langflow
CVE-2024-47003Medium· 5.4Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
CVE-2024-7594High· 7.5Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
CVE-2024-46488Critical· 9.1Heap-based Buffer Overflow in sqlite-vec
Heap-based Buffer Overflow in sqlite-vec
CVE-2024-9014High· 8.6PoCOAuth2 client ID and secret exposed through the web browser
OAuth2 client ID and secret exposed through the web browser
CVE-2024-47226Medium· 5.4A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel …
A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or H…
CVE-2024-45793Medium· 4.8Prevent XSS from Confidant API call
Prevent XSS from Confidant API call
CVE-2024-8375Medium· 6.1Reverb use after free vulnerability
Reverb use after free vulnerability