VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2024-35198Critical· 9.8
2y ago

TorchServe vulnerable to bypass of allowed_urls configuration

TorchServe vulnerable to bypass of allowed_urls configuration

▾ Midnighttorchserve · torchserveEPSS 0.80%via OSV
CVE-2024-35199High· 8.2
2y ago

TorchServe gRPC Port Exposure

TorchServe gRPC Port Exposure

▾ Twilighttorchserve · torchserveEPSS 0.64%via OSV
CVE-2024-40647Low· 2.5
2y ago

Sentry's Python SDK unintentionally exposes environment variables to subprocesses

Sentry's Python SDK unintentionally exposes environment variables to subprocesses

▾ Sunlitsentry-sdk · sentry-sdkEPSS 0.20%via OSV
CVE-2024-40637Medium· 4.2
2y ago

dbt has an implicit override for built-in materializations from installed packages

dbt has an implicit override for built-in materializations from installed packages

▾ Sunlitdbt-core · dbt-coreEPSS 0.37%via OSV
CVE-2024-39863Medium· 5.4
2y ago

Apache Airflow Potential Cross-site Scripting Vulnerability

Apache Airflow Potential Cross-site Scripting Vulnerability

▾ Sunlitapache-airflow · apache-airflowEPSS 1.00%via OSV
CVE-2024-39877High· 8.8
2y ago

Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler

Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler

▾ Twilightapache-airflow · apache-airflowEPSS 1.7%via OSV
CVE-2024-39700Critical· 9.8PoC
2y ago

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` opt…

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension author…

▾ Abyssaljupyterlab · jupyterlabEPSS 1.1%via OSV
CVE-2024-39887Medium· 4.3PoC
2y ago

Apache Superset vulnerable to improper SQL authorization

Apache Superset vulnerable to improper SQL authorization

▾ Twilightapache-superset · apache-supersetEPSS 4.4%via OSV
CVE-2024-6345High· 8.8
2y ago

setuptools vulnerable to Command Injection via package URL

setuptools vulnerable to Command Injection via package URL

▾ Twilightsetuptools · setuptoolsEPSS 1.9%via OSV
CVE-2024-40627Medium· 5.8
2y ago

OpaMiddleware does not filter HTTP OPTIONS requests

OpaMiddleware does not filter HTTP OPTIONS requests

▾ Sunlitfastapi-opa · fastapi-opaEPSS 0.56%via OSV
CVE-2024-39909Medium· 6.5
2y ago

SQL Injection in the KubeClarity REST API

SQL Injection in the KubeClarity REST API

▾ Sunlitopenclarity · github.com/openclarity/kubeclarity/backendEPSS 0.44%via OSV
CVE-2024-39903High· 8.6PoC
2y ago

Local File Inclusion in Solara

Local File Inclusion in Solara

▾ Midnightsolara · solaraEPSS 2.9%via OSV
CVE-2024-6468High· 7.5
2y ago

Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions

Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.49%via OSV
CVE-2024-39905Medium· 5.3
2y ago

Red-DiscordBot vulnerable to Incorrect Authorization in commands API

Red-DiscordBot vulnerable to Incorrect Authorization in commands API

▾ Sunlitred-discordbot · red-discordbotEPSS 0.41%via OSV
CVE-2024-38875High· 7.5
2y ago

Django vulnerable to Denial of Service

Django vulnerable to Denial of Service

▾ Twilightdjango · djangoEPSS 1.2%via OSV
CVE-2024-39614High· 7.5PoC
2y ago

Django vulnerable to Denial of Service

Django vulnerable to Denial of Service

▾ Midnightdjango · djangoEPSS 29%via OSV
CVE-2024-39330High· 7.5
2y ago

Django Path Traversal vulnerability

Django Path Traversal vulnerability

▾ Twilightdjango · djangoEPSS 1.0%via OSV
CVE-2024-6037Critical· 9.1
2y ago

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the serv…

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resul…

▾ Midnightchuanhuchatgpt · chuanhuchatgptEPSS 11%via OSV
CVE-2024-39897Medium· 4.3
2y ago

Cache driver GetBlob() allows read access to any blob without access control check

Cache driver GetBlob() allows read access to any blob without access control check

▾ Sunlitzot · zotregistry.io/zotEPSS 0.30%via OSV
CVE-2024-5569Medium· 6.2
2y ago

zipp Denial of Service vulnerability

zipp Denial of Service vulnerability

▾ Sunlitzipp · zippEPSS 0.24%via OSV
CVE-2024-6227High· 7.5
2y ago

Aim denial of service vulnerability

Aim denial of service vulnerability

▾ Twilightaim · aimEPSS 0.58%via OSV
CVE-2024-39689LowPoC
2y ago

Certifi removes GLOBALTRUST root certificate

Certifi removes GLOBALTRUST root certificate

▾ Twilightcertifi · certifiEPSS 1.0%via OSV
CVE-2024-32498Medium· 6.5
2y ago

OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access

OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access

▾ Sunlitcinder · cinderEPSS 0.83%via OSV
CVE-2024-5753High· 7.5
2y ago

Vanna vulnerable to SQL Injection

Vanna vulnerable to SQL Injection

▾ Twilightvanna · vannaEPSS 0.60%via OSV
CVE-2024-31223Medium· 5.3PoC
2y ago

Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL

Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL

▾ Twilightethyca-fides · ethyca-fidesEPSS 1.1%via OSV
CVE-2024-38537None· 0.0PoC
2y ago

Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js

Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js

▾ Twilightethyca-fides · ethyca-fidesEPSS 1.4%via OSV
CVE-2024-38519High· 7.8
2y ago

yt-dlp File system modification and RCE through improper file-extension sanitization

yt-dlp File system modification and RCE through improper file-extension sanitization

▾ Twilightyt-dlp · yt-dlpEPSS 0.33%via OSV
CVE-2024-37298High· 7.5
2y ago

Potential memory exhaustion attack due to sparse slice deserialization

Potential memory exhaustion attack due to sparse slice deserialization

▾ Twilightgorilla · github.com/gorilla/schemaEPSS 1.1%via OSV
CVE-2024-39303Medium· 4.4
2y ago

Weblate vulnerable to improper sanitization of project backups

Weblate vulnerable to improper sanitization of project backups

▾ Sunlitweblate · weblateEPSS 0.32%via OSV
CVE-2024-39705High· 7.5
2y ago

ntlk unsafe deserialization vulnerability

ntlk unsafe deserialization vulnerability

▾ Twilightnltk · nltkEPSS 1.3%via OSV
CVEs tagged “osv” — page 127 · VulnSea