Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2024-42447Medium· 4.2Apache Airflow Providers FAB Insufficient Session Expiration vulnerability
Apache Airflow Providers FAB Insufficient Session Expiration vulnerability
CVE-2024-37286Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
APM Server vulnerable to Insertion of Sensitive Information into Log File
CVE-2024-7319Medium· 5.0openstack-heat may disclose sensitive information
openstack-heat may disclose sensitive information
CVE-2024-41255Medium· 5.9Filestash configured to skip TLS certificate verification when using the FTPS protocol
Filestash configured to skip TLS certificate verification when using the FTPS protocol
CVE-2024-7340High· 8.8PoCWeave server API vulnerable to arbitrary file leak
Weave server API vulnerable to arbitrary file leak
CVE-2024-41950High· 7.5Insecure Jinja2 templates rendered in Haystack Components can lead to RCE
Insecure Jinja2 templates rendered in Haystack Components can lead to RCE
CVE-2024-41955Medium· 5.2PoCMobSF vulnerable to Open Redirect in Login Redirect
MobSF vulnerable to Open Redirect in Login Redirect
CVE-2024-41951Medium· 4.4PheonixAppAPI has visible Encoding Maps
PheonixAppAPI has visible Encoding Maps
CVE-2023-33976High· 7.5TensorFlow has segfault in array_ops.upper_bound
TensorFlow has segfault in array_ops.upper_bound
CVE-2024-6578Medium· 6.1Aim Stored Cross-site Scripting Vulnerability
Aim Stored Cross-site Scripting Vulnerability
CVE-2024-41671High· 8.3twisted.web has disordered HTTP pipeline response
twisted.web has disordered HTTP pipeline response
MAL-2024-12279Critical⚠ ExploitedMalicious code in google-cloud-datacatalog-lineage-producer-client (PyPI)
Malicious code in google-cloud-datacatalog-lineage-producer-client (PyPI)
CVE-2024-29069Medium· 4.8snapd failed to properly check the destination of symbolic links when extracting a snap
snapd failed to properly check the destination of symbolic links when extracting a snap
CVE-2024-29068Medium· 5.8snapd failed to properly check the file type when extracting a snap
snapd failed to properly check the file type when extracting a snap
CVE-2024-1724Medium· 6.3snapd failed to restrict writes to the $HOME/bin path
snapd failed to restrict writes to the $HOME/bin path
CVE-2024-41666Medium· 4.7The Argo CD web terminal session does not handle the revocation of user permissions properly
The Argo CD web terminal session does not handle the revocation of user permissions properly
CVE-2024-40767Medium· 6.5OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
CVE-2024-41656High· 7.1Sentry vulnerable to stored Cross-Site Scripting (XSS)
Sentry vulnerable to stored Cross-Site Scripting (XSS)
CVE-2024-29073Medium· 5.3Anki Latex Incomplete Blocklist Vulnerability
Anki Latex Incomplete Blocklist Vulnerability
CVE-2024-32152Low· 3.1Ankitects Anki LaTeX Blocklist Bypass vulnerability
Ankitects Anki LaTeX Blocklist Bypass vulnerability
CVE-2024-41129Medium· 4.4ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command
ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command
CVE-2024-26020Critical· 9.6Ankitects Anki arbitrary script execution vulnerability
Ankitects Anki arbitrary script execution vulnerability
CVE-2024-6961Medium· 5.9Guardrails AI vulnerable to Improper Restriction of XML External Entity Reference
Guardrails AI vulnerable to Improper Restriction of XML External Entity Reference
CVE-2024-6281High· 7.3LoLLMS vulnerable to Expected Behavior Violation
LoLLMS vulnerable to Expected Behavior Violation
CVE-2024-41122High· 7.5Woodpecker's custom environment variables allow to alter execution flow of plugins
Woodpecker's custom environment variables allow to alter execution flow of plugins
CVE-2024-41124Low· 3.8[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`
[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`
CVE-2024-39123Medium· 5.4PoCCalibre-Web Cross Site Scripting (XSS)
Calibre-Web Cross Site Scripting (XSS)
CVE-2024-5321Medium· 6.1Kubernetes sets incorrect permissions on Windows containers logs
Kubernetes sets incorrect permissions on Windows containers logs
CVE-2024-39907Critical· 9.8PoC1Panel has an SQL injection issue related to the orderBy clause
1Panel has an SQL injection issue related to the orderBy clause
CVE-2024-35198Critical· 9.8TorchServe vulnerable to bypass of allowed_urls configuration
TorchServe vulnerable to bypass of allowed_urls configuration