VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2023-26043Medium· 6.5
2y ago

GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection

GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection

▾ Sunlitgeonode · geonodeEPSS 0.84%via OSV
GHSA-jh2j-j4j9-crg3High· 8.8
2y ago

opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

▾ Twilightopencv-python-headless · opencv-python-headlessvia OSV
GHSA-cxjf-x6jp-p7mcHigh· 8.8
2y ago

opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863

▾ Twilightopencv-contrib-python · opencv-contrib-pythonvia OSV
CVE-2023-23611Low· 3.7
2y ago

LTI 1.3 Grade Pass Back Implementation has Missing Authorization Vulnerability

LTI 1.3 Grade Pass Back Implementation has Missing Authorization Vulnerability

▾ Sunlitlti-consumer-xblock · lti-consumer-xblockEPSS 0.38%via OSV
CVE-2020-11093High· 7.5
2y ago

Hyperledger Indy's update process of a DID does not check who signs the request

Hyperledger Indy's update process of a DID does not check who signs the request

▾ Twilightindy-node · indy-nodeEPSS 1.2%via OSV
CVE-2020-15100Low· 2.8
2y ago

freewvs vulnerable to denial of service through large files

freewvs vulnerable to denial of service through large files

▾ Sunlitfreewvs · freewvsEPSS 0.34%via OSV
CVE-2020-15101Low· 2.8
2y ago

freewvs's nested directory structure can interrupt scan

freewvs's nested directory structure can interrupt scan

▾ Sunlitfreewvs · freewvsEPSS 0.69%via OSV
CVE-2021-21401High· 7.1PoC
2y ago

nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC

nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC

▾ Midnightnanopb · nanopbEPSS 1.8%via OSV
CVE-2024-43805High· 7.6
2y ago

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

▾ Twilightjupyterlab · jupyterlabEPSS 0.40%via OSV
CVE-2024-42818Medium· 6.1
2y ago

FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function

FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function

▾ Sunlitfastapi-admin · fastapi-adminEPSS 0.29%via OSV
CVE-2024-42816Medium· 6.1
2y ago

FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function

FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function

▾ Sunlitfastapi-admin · fastapi-adminEPSS 0.29%via OSV
CVE-2024-45188Medium· 6.5
2y ago

Mage AI Path Traversal vulnerability

Mage AI Path Traversal vulnerability

▾ Sunlitmage-ai · mage-aiEPSS 0.88%via OSV
CVE-2024-45187High· 7.1
2y ago

Mage AI incorrectly gives privileges to users with deleted accounts

Mage AI incorrectly gives privileges to users with deleted accounts

▾ Twilightmage-ai · mage-aiEPSS 0.50%via OSV
CVE-2024-45189Medium· 6.5
2y ago

Mage AI Path Traversal vulnerability

Mage AI Path Traversal vulnerability

▾ Sunlitmage-ai · mage-aiEPSS 0.88%via OSV
CVE-2024-45190Medium· 6.5
2y ago

Mage AI Path Traversal vulnerability

Mage AI Path Traversal vulnerability

▾ Sunlitmage-ai · mage-aiEPSS 0.86%via OSV
CVE-2024-8072Medium· 5.3
2y ago

Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users

Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users

▾ Sunlitmage-ai · mage-aiEPSS 0.60%via OSV
CVE-2024-41937Medium· 6.1
2y ago

Apache Airflow Cross-site Scripting Vulnerability

Apache Airflow Cross-site Scripting Vulnerability

▾ Sunlitapache-airflow · apache-airflowEPSS 1.7%via OSV
GO-2022-0920None
2y ago

Incorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper

Incorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper

▾ Sunlitory · github.com/ory/oathkeepervia OSV
CVE-2024-41675Medium· 6.8
2y ago

CKAN has Cross-site Scripting vector in the Datatables view plugin

CKAN has Cross-site Scripting vector in the Datatables view plugin

▾ Sunlitckan · ckanEPSS 0.40%via OSV
CVE-2024-43371Medium· 4.5
2y ago

Potential access to sensitive URLs via CKAN extensions (SSRF)

Potential access to sensitive URLs via CKAN extensions (SSRF)

▾ Sunlitckan · ckanEPSS 0.37%via OSV
CVE-2024-41674Medium· 5.3
2y ago

CKAN may leak Solr credentials via error message in package_search action

CKAN may leak Solr credentials via error message in package_search action

▾ Sunlitckan · ckanEPSS 0.38%via OSV
CVE-2024-43406High· 8.8
2y ago

LF Edge eKuiper has a SQL Injection in sqlKvStore

LF Edge eKuiper has a SQL Injection in sqlKvStore

▾ Twilightlf-edge · github.com/lf-edge/ekuiperEPSS 0.89%via OSV
GO-2023-1804None
2y ago

Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno

Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno

▾ Sunlitkyverno · github.com/kyverno/kyvernovia OSV
CVE-2024-43396Medium· 5.4
2y ago

Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)

Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)

▾ Sunlitkhoj · khojEPSS 0.55%via OSV
CVE-2024-43399High· 8.0
2y ago

Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files

Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files

▾ Twilightmobsf · mobsfEPSS 0.96%via OSV
CVE-2024-6221High· 7.5
2y ago

Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default

Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default

▾ Twilightflask-cors · flask-corsEPSS 0.72%via OSV
CVE-2024-42367Medium· 4.8
2y ago

In aiohttp, compressed files as symlinks are not protected from path traversal

In aiohttp, compressed files as symlinks are not protected from path traversal

▾ Sunlitaiohttp · aiohttpEPSS 0.65%via OSV
CVE-2024-41942High· 7.2
2y ago

JupyterHub has a privilege escalation vulnerability with the `admin:users` scope

JupyterHub has a privilege escalation vulnerability with the `admin:users` scope

▾ Twilightjupyterhub · jupyterhubEPSS 0.59%via OSV
CVE-2024-6706Medium· 6.1
2y ago

Open WebUI Stored Cross-Site Scripting Vulnerability

Open WebUI Stored Cross-Site Scripting Vulnerability

▾ Sunlitopen-webui · open-webuiEPSS 0.66%via OSV
CVE-2024-7143Medium· 6.7
2y ago

Pulp incorrectly assigns RBAC permissions in tasks that create objects

Pulp incorrectly assigns RBAC permissions in tasks that create objects

▾ Sunlitpulpcore · pulpcoreEPSS 0.61%via OSV
CVEs tagged “osv” — page 125 · VulnSea