Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2024-35198Critical· 9.8TorchServe vulnerable to bypass of allowed_urls configuration
TorchServe vulnerable to bypass of allowed_urls configuration
CVE-2024-35199High· 8.2TorchServe gRPC Port Exposure
TorchServe gRPC Port Exposure
CVE-2024-40647Low· 2.5Sentry's Python SDK unintentionally exposes environment variables to subprocesses
Sentry's Python SDK unintentionally exposes environment variables to subprocesses
CVE-2024-40637Medium· 4.2dbt has an implicit override for built-in materializations from installed packages
dbt has an implicit override for built-in materializations from installed packages
CVE-2024-39863Medium· 5.4Apache Airflow Potential Cross-site Scripting Vulnerability
Apache Airflow Potential Cross-site Scripting Vulnerability
CVE-2024-39877High· 8.8Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
CVE-2024-39700Critical· 9.8PoCJupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` opt…
JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension author…
CVE-2024-39887Medium· 4.3PoCApache Superset vulnerable to improper SQL authorization
Apache Superset vulnerable to improper SQL authorization
CVE-2024-6345High· 8.8setuptools vulnerable to Command Injection via package URL
setuptools vulnerable to Command Injection via package URL
CVE-2024-40627Medium· 5.8OpaMiddleware does not filter HTTP OPTIONS requests
OpaMiddleware does not filter HTTP OPTIONS requests
CVE-2024-39909Medium· 6.5SQL Injection in the KubeClarity REST API
SQL Injection in the KubeClarity REST API
CVE-2024-39903High· 8.6PoCLocal File Inclusion in Solara
Local File Inclusion in Solara
CVE-2024-6468High· 7.5Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
CVE-2024-39905Medium· 5.3Red-DiscordBot vulnerable to Incorrect Authorization in commands API
Red-DiscordBot vulnerable to Incorrect Authorization in commands API
CVE-2024-38875High· 7.5Django vulnerable to Denial of Service
Django vulnerable to Denial of Service
CVE-2024-39614High· 7.5PoCDjango vulnerable to Denial of Service
Django vulnerable to Denial of Service
CVE-2024-39330High· 7.5Django Path Traversal vulnerability
Django Path Traversal vulnerability
CVE-2024-6037Critical· 9.1A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the serv…
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resul…
CVE-2024-39897Medium· 4.3Cache driver GetBlob() allows read access to any blob without access control check
Cache driver GetBlob() allows read access to any blob without access control check
CVE-2024-5569Medium· 6.2zipp Denial of Service vulnerability
zipp Denial of Service vulnerability
CVE-2024-6227High· 7.5Aim denial of service vulnerability
Aim denial of service vulnerability
CVE-2024-39689LowPoCCertifi removes GLOBALTRUST root certificate
Certifi removes GLOBALTRUST root certificate
CVE-2024-32498Medium· 6.5OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
CVE-2024-5753High· 7.5Vanna vulnerable to SQL Injection
Vanna vulnerable to SQL Injection
CVE-2024-31223Medium· 5.3PoCInformation Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
CVE-2024-38537None· 0.0PoCInclusion of Untrusted polyfill.io Code Vulnerability in fides.js
Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js
CVE-2024-38519High· 7.8yt-dlp File system modification and RCE through improper file-extension sanitization
yt-dlp File system modification and RCE through improper file-extension sanitization
CVE-2024-37298High· 7.5Potential memory exhaustion attack due to sparse slice deserialization
Potential memory exhaustion attack due to sparse slice deserialization
CVE-2024-39303Medium· 4.4Weblate vulnerable to improper sanitization of project backups
Weblate vulnerable to improper sanitization of project backups
CVE-2024-39705High· 7.5ntlk unsafe deserialization vulnerability
ntlk unsafe deserialization vulnerability