VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2024-42447Medium· 4.2
2y ago

Apache Airflow Providers FAB Insufficient Session Expiration vulnerability

Apache Airflow Providers FAB Insufficient Session Expiration vulnerability

▾ Sunlitapache-airflow-providers-fab · apache-airflow-providers-fabEPSS 0.93%via OSV
CVE-2024-37286Medium· 5.7
2y ago

APM Server vulnerable to Insertion of Sensitive Information into Log File

APM Server vulnerable to Insertion of Sensitive Information into Log File

▾ Sunlitelastic · github.com/elastic/apm-serverEPSS 0.49%via OSV
CVE-2024-7319Medium· 5.0
2y ago

openstack-heat may disclose sensitive information

openstack-heat may disclose sensitive information

▾ Sunlitopenstack-heat · openstack-heatEPSS 0.39%via OSV
CVE-2024-41255Medium· 5.9
2y ago

Filestash configured to skip TLS certificate verification when using the FTPS protocol

Filestash configured to skip TLS certificate verification when using the FTPS protocol

▾ Sunlitmickael-kerjean · github.com/mickael-kerjean/filestashEPSS 0.26%via OSV
CVE-2024-7340High· 8.8PoC
2y ago

Weave server API vulnerable to arbitrary file leak

Weave server API vulnerable to arbitrary file leak

▾ Midnightweave · weaveEPSS 5.0%via OSV
CVE-2024-41950High· 7.5
2y ago

Insecure Jinja2 templates rendered in Haystack Components can lead to RCE

Insecure Jinja2 templates rendered in Haystack Components can lead to RCE

▾ Twilighthaystack-ai · haystack-aiEPSS 1.2%via OSV
CVE-2024-41955Medium· 5.2PoC
2y ago

MobSF vulnerable to Open Redirect in Login Redirect

MobSF vulnerable to Open Redirect in Login Redirect

▾ Twilightmobsf · mobsfEPSS 1.0%via OSV
CVE-2024-41951Medium· 4.4
2y ago

PheonixAppAPI has visible Encoding Maps

PheonixAppAPI has visible Encoding Maps

▾ Sunlitpheonixappapi · pheonixappapiEPSS 0.17%via OSV
CVE-2023-33976High· 7.5
2y ago

TensorFlow has segfault in array_ops.upper_bound

TensorFlow has segfault in array_ops.upper_bound

▾ Twilighttensorflow · tensorflowEPSS 0.43%via OSV
CVE-2024-6578Medium· 6.1
2y ago

Aim Stored Cross-site Scripting Vulnerability

Aim Stored Cross-site Scripting Vulnerability

▾ Sunlitaim · aimEPSS 0.29%via OSV
CVE-2024-41671High· 8.3
2y ago

twisted.web has disordered HTTP pipeline response

twisted.web has disordered HTTP pipeline response

▾ Twilighttwisted · twistedEPSS 0.86%via OSV
MAL-2024-12279Critical⚠ Exploited
2y ago

Malicious code in google-cloud-datacatalog-lineage-producer-client (PyPI)

Malicious code in google-cloud-datacatalog-lineage-producer-client (PyPI)

▾ Abyssalgoogle-cloud-datacatalog-lineage-producer-client · google-cloud-datacatalog-lineage-producer-clientvia OSV
CVE-2024-29069Medium· 4.8
2y ago

snapd failed to properly check the destination of symbolic links when extracting a snap

snapd failed to properly check the destination of symbolic links when extracting a snap

▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.23%via OSV
CVE-2024-29068Medium· 5.8
2y ago

snapd failed to properly check the file type when extracting a snap

snapd failed to properly check the file type when extracting a snap

▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.21%via OSV
CVE-2024-1724Medium· 6.3
2y ago

snapd failed to restrict writes to the $HOME/bin path

snapd failed to restrict writes to the $HOME/bin path

▾ Sunlitsnapcore · github.com/snapcore/snapdEPSS 0.31%via OSV
CVE-2024-41666Medium· 4.7
2y ago

The Argo CD web terminal session does not handle the revocation of user permissions properly

The Argo CD web terminal session does not handle the revocation of user permissions properly

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.69%via OSV
CVE-2024-40767Medium· 6.5
2y ago

OpenStack Nova vulnerable to unauthorized access to potentially sensitive data

OpenStack Nova vulnerable to unauthorized access to potentially sensitive data

▾ Sunlitnova · novaEPSS 0.94%via OSV
CVE-2024-41656High· 7.1
2y ago

Sentry vulnerable to stored Cross-Site Scripting (XSS)

Sentry vulnerable to stored Cross-Site Scripting (XSS)

▾ Twilightsentry · sentryEPSS 0.47%via OSV
CVE-2024-29073Medium· 5.3
2y ago

Anki Latex Incomplete Blocklist Vulnerability

Anki Latex Incomplete Blocklist Vulnerability

▾ Sunlitanki · ankiEPSS 12%via OSV
CVE-2024-32152Low· 3.1
2y ago

Ankitects Anki LaTeX Blocklist Bypass vulnerability

Ankitects Anki LaTeX Blocklist Bypass vulnerability

▾ Sunlitanki · ankiEPSS 13%via OSV
CVE-2024-41129Medium· 4.4
2y ago

ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command

ops leaking secrets if `subprocess.CalledProcessError` happens with a `secret-*` CLI command

▾ Sunlitops · opsEPSS 0.20%via OSV
CVE-2024-26020Critical· 9.6
2y ago

Ankitects Anki arbitrary script execution vulnerability

Ankitects Anki arbitrary script execution vulnerability

▾ Midnightanki · ankiEPSS 15%via OSV
CVE-2024-6961Medium· 5.9
2y ago

Guardrails AI vulnerable to Improper Restriction of XML External Entity Reference

Guardrails AI vulnerable to Improper Restriction of XML External Entity Reference

▾ Sunlitguardrails-ai · guardrails-aiEPSS 0.41%via OSV
CVE-2024-6281High· 7.3
2y ago

LoLLMS vulnerable to Expected Behavior Violation

LoLLMS vulnerable to Expected Behavior Violation

▾ Twilightlollms · lollmsEPSS 0.27%via OSV
CVE-2024-41122High· 7.5
2y ago

Woodpecker's custom environment variables allow to alter execution flow of plugins

Woodpecker's custom environment variables allow to alter execution flow of plugins

▾ Twilightwoodpecker · go.woodpecker-ci.org/woodpecker/v2EPSS 0.62%via OSV
CVE-2024-41124Low· 3.8
2y ago

[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`

[PUNCIA] [CWE-319] Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`

▾ Sunlitpuncia · punciaEPSS 0.27%via OSV
CVE-2024-39123Medium· 5.4PoC
2y ago

Calibre-Web Cross Site Scripting (XSS)

Calibre-Web Cross Site Scripting (XSS)

▾ Twilightcalibreweb · calibrewebEPSS 23%via OSV
CVE-2024-5321Medium· 6.1
2y ago

Kubernetes sets incorrect permissions on Windows containers logs

Kubernetes sets incorrect permissions on Windows containers logs

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 0.31%via OSV
CVE-2024-39907Critical· 9.8PoC
2y ago

1Panel has an SQL injection issue related to the orderBy clause

1Panel has an SQL injection issue related to the orderBy clause

▾ Abyssal1Panel-dev · github.com/1Panel-dev/1PanelEPSS 29%via OSV
CVE-2024-35198Critical· 9.8
2y ago

TorchServe vulnerable to bypass of allowed_urls configuration

TorchServe vulnerable to bypass of allowed_urls configuration

▾ Midnighttorchserve · torchserveEPSS 0.80%via OSV
CVEs tagged “osv” — page 126 · VulnSea