Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2024-45858High· 8.8Guardrails has an arbitrary code execution vulnerability
Guardrails has an arbitrary code execution vulnerability
CVE-2024-45601High· 7.5Mesop has a local file Inclusion via static file serving functionality
Mesop has a local file Inclusion via static file serving functionality
CVE-2024-35515High· 8.8sqlitedict insecure deserialization vulnerability
sqlitedict insecure deserialization vulnerability
CVE-2024-8939Medium· 6.2vLLM Denial of Service via the best_of parameter
vLLM Denial of Service via the best_of parameter
CVE-2024-8768High· 7.5vLLM denial of service vulnerability
vLLM denial of service vulnerability
CVE-2024-45606High· 7.1Sentry improperly authorizes muting of alert rules
Sentry improperly authorizes muting of alert rules
CVE-2024-5998Medium· 5.2LangChain pickle deserialization of untrusted data
LangChain pickle deserialization of untrusted data
CVE-2024-45605Medium· 6.5Sentry improperly authorizes deletion of user issue alert notifications
Sentry improperly authorizes deletion of user issue alert notifications
CVE-2024-8863Low· 3.5Aim Stored XSS through TEXT EXPLORER
Aim Stored XSS through TEXT EXPLORER
CVE-2024-8864Medium· 5.5Composio Code Injection Vulnerability
Composio Code Injection Vulnerability
CVE-2024-8862High· 7.3D-Tale Command Execution Vulnerability
D-Tale Command Execution Vulnerability
CVE-2024-8865Low· 3.5Composio Path Traversal vulnerability
Composio Path Traversal vulnerability
CVE-2024-8775Medium· 5.5A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook
A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without se…
CVE-2024-6587High· 7.5PoCLiteLLM Server-Side Request Forgery (SSRF) vulnerability
LiteLLM Server-Side Request Forgery (SSRF) vulnerability
CVE-2024-27320High· 7.8Refuel Autolab Eval Injection vulnerability
Refuel Autolab Eval Injection vulnerability
CVE-2024-45847High· 8.8MindsDB Eval Injection vulnerability
MindsDB Eval Injection vulnerability
CVE-2024-45857High· 7.8Cleanlab Deserialization of Untrusted Data vulnerability
Cleanlab Deserialization of Untrusted Data vulnerability
CVE-2024-27321High· 7.8Refuel Autolab Eval Injection vulnerability
Refuel Autolab Eval Injection vulnerability
CVE-2024-45856Critical· 9.0MindsDB Cross-site Scripting vulnerability
MindsDB Cross-site Scripting vulnerability
CVE-2024-45595Medium· 6.1D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
RUSTSEC-2024-0404NoneUnsoundness in anstream
Unsoundness in anstream
CVE-2024-45498High· 8.8Apache Airflow vulnerable to Improper Encoding or Escaping of Output
Apache Airflow vulnerable to Improper Encoding or Escaping of Output
CVE-2024-45034High· 8.8Apache Airflow vulnerable to Execution with Unnecessary Privileges
Apache Airflow vulnerable to Execution with Unnecessary Privileges
CVE-2024-34158NoneStack exhaustion in Parse in go/build/constraint
Stack exhaustion in Parse in go/build/constraint
CVE-2024-45314Low· 3.6Flask-AppBuilder's login form allows browser to cache sensitive fields
Flask-AppBuilder's login form allows browser to cache sensitive fields
CVE-2024-45053Critical· 9.1Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine
Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine
CVE-2024-45052LowTiming-Based Username Enumeration Vulnerability in Fides Webserver Authentication
Timing-Based Username Enumeration Vulnerability in Fides Webserver Authentication
GHSA-h4gh-qq45-vh27Mediumpyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
GHSA-w2pj-9cgh-mq2cHigh· 8.8opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
GHSA-qr4w-53vh-m672High· 8.8opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863