Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2023-26043Medium· 6.5GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection
GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection
GHSA-jh2j-j4j9-crg3High· 8.8opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
GHSA-cxjf-x6jp-p7mcHigh· 8.8opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
CVE-2023-23611Low· 3.7LTI 1.3 Grade Pass Back Implementation has Missing Authorization Vulnerability
LTI 1.3 Grade Pass Back Implementation has Missing Authorization Vulnerability
CVE-2020-11093High· 7.5Hyperledger Indy's update process of a DID does not check who signs the request
Hyperledger Indy's update process of a DID does not check who signs the request
CVE-2020-15100Low· 2.8freewvs vulnerable to denial of service through large files
freewvs vulnerable to denial of service through large files
CVE-2020-15101Low· 2.8freewvs's nested directory structure can interrupt scan
freewvs's nested directory structure can interrupt scan
CVE-2021-21401High· 7.1PoCnanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC
nanopb vulnerable to invalid free() call with oneofs and PB_ENABLE_MALLOC
CVE-2024-43805High· 7.6HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
CVE-2024-42818Medium· 6.1FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function
FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function
CVE-2024-42816Medium· 6.1FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function
FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function
CVE-2024-45188Medium· 6.5Mage AI Path Traversal vulnerability
Mage AI Path Traversal vulnerability
CVE-2024-45187High· 7.1Mage AI incorrectly gives privileges to users with deleted accounts
Mage AI incorrectly gives privileges to users with deleted accounts
CVE-2024-45189Medium· 6.5Mage AI Path Traversal vulnerability
Mage AI Path Traversal vulnerability
CVE-2024-45190Medium· 6.5Mage AI Path Traversal vulnerability
Mage AI Path Traversal vulnerability
CVE-2024-8072Medium· 5.3Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
CVE-2024-41937Medium· 6.1Apache Airflow Cross-site Scripting Vulnerability
Apache Airflow Cross-site Scripting Vulnerability
GO-2022-0920NoneIncorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper
Incorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper
CVE-2024-41675Medium· 6.8CKAN has Cross-site Scripting vector in the Datatables view plugin
CKAN has Cross-site Scripting vector in the Datatables view plugin
CVE-2024-43371Medium· 4.5Potential access to sensitive URLs via CKAN extensions (SSRF)
Potential access to sensitive URLs via CKAN extensions (SSRF)
CVE-2024-41674Medium· 5.3CKAN may leak Solr credentials via error message in package_search action
CKAN may leak Solr credentials via error message in package_search action
CVE-2024-43406High· 8.8LF Edge eKuiper has a SQL Injection in sqlKvStore
LF Edge eKuiper has a SQL Injection in sqlKvStore
GO-2023-1804NoneKyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
CVE-2024-43396Medium· 5.4Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)
Khoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)
CVE-2024-43399High· 8.0Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
CVE-2024-6221High· 7.5Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
CVE-2024-42367Medium· 4.8In aiohttp, compressed files as symlinks are not protected from path traversal
In aiohttp, compressed files as symlinks are not protected from path traversal
CVE-2024-41942High· 7.2JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
CVE-2024-6706Medium· 6.1Open WebUI Stored Cross-Site Scripting Vulnerability
Open WebUI Stored Cross-Site Scripting Vulnerability
CVE-2024-7143Medium· 6.7Pulp incorrectly assigns RBAC permissions in tasks that create objects
Pulp incorrectly assigns RBAC permissions in tasks that create objects