VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

GO-2024-2941None
2y ago

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik

▾ Sunlittraefik · github.com/traefik/traefikvia OSV
CVE-2024-5899None
2y ago

Improper trust check in Bazel Build intellij plugin in github.com/bazelbuild/intellij

Improper trust check in Bazel Build intellij plugin in github.com/bazelbuild/intellij

▾ Sunlitbazelbuild · github.com/bazelbuild/intellijEPSS 0.11%via OSV
CVE-2024-5980Critical· 9.1
2y ago

pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

▾ Midnightlightning · lightningEPSS 1.3%via OSV
CVE-2024-6090High· 7.5
2y ago

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histo…

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target s…

▾ Twilightchuanhuchatgpt · chuanhuchatgptEPSS 0.86%via OSV
CVE-2024-6038High· 7.5
2y ago

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerabilit…

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-p…

▾ Twilightchuanhuchatgpt · chuanhuchatgptEPSS 0.66%via OSV
CVE-2024-6139High· 7.3
2y ago

lollms vulnerable to dot-dot-slash path traversal in XTTS server

lollms vulnerable to dot-dot-slash path traversal in XTTS server

▾ Twilightlollms · lollmsEPSS 0.52%via OSV
CVE-2024-5710Medium· 5.3
2y ago

litellm vulnerable to improper access control in team management

litellm vulnerable to improper access control in team management

▾ Sunlitlitellm · litellmEPSS 0.41%via OSV
CVE-2024-22231Medium· 5.0
2y ago

Directory creation by malicious user in saltstack

Directory creation by malicious user in saltstack

▾ Sunlitsalt · saltEPSS 0.69%via OSV
CVE-2024-5824High· 7.4
2y ago

lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE

lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE

▾ Twilightlollms · lollmsEPSS 0.45%via OSV
CVE-2024-6085High· 8.6
2y ago

lollms vulnerable to path traversal due to unauthenticated root folder settings change

lollms vulnerable to path traversal due to unauthenticated root folder settings change

▾ Twilightlollms · lollmsEPSS 0.64%via OSV
CVE-2024-5979High· 7.5
2y ago

h2o vulnerable to unexpected POST request shutting down server

h2o vulnerable to unexpected POST request shutting down server

▾ Twilighth2o · h2oEPSS 0.79%via OSV
CVE-2024-22232High· 7.7
2y ago

Path traversal in saltstack

Path traversal in saltstack

▾ Twilightsalt · saltEPSS 0.84%via OSV
CVE-2024-21520Medium· 6.1PoC
2y ago

Cross-site Scripting in djangorestframework

Cross-site Scripting in djangorestframework

▾ Twilightdjangorestframework · djangorestframeworkEPSS 1.1%via OSV
CVE-2024-37820Medium· 5.4
2y ago

PingCAP TiDB nil pointer dereference

PingCAP TiDB nil pointer dereference

▾ Sunlitpingcap · github.com/pingcap/tidbEPSS 0.38%via OSV
CVE-2024-38526High· 7.2PoC
2y ago

pdoc embeds link to malicious CDN if math mode is enabled

pdoc embeds link to malicious CDN if math mode is enabled

▾ Midnightpdoc · pdocEPSS 3.8%via OSV
CVE-2024-4460Medium· 4.3
2y ago

Improper line feed handling in zenml

Improper line feed handling in zenml

▾ Sunlitzenml · zenmlvia OSV
CVE-2024-3121Medium· 6.8PoC
2y ago

Remote Code Execution in create_conda_env function in lollms

Remote Code Execution in create_conda_env function in lollms

▾ Twilightlollms · lollmsEPSS 0.45%via OSV
CVE-2024-4940Medium· 5.4PoC
2y ago

Open redirect in gradio

Open redirect in gradio

▾ Twilightgradio · gradioEPSS 1.0%via OSV
GHSA-rvj4-q8q5-8grfMedium· 5.5
2y ago

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability

▾ Sunlittraefik · github.com/traefik/traefik/v3via OSV
CVE-2024-34693Medium· 6.8PoC
2y ago

Apache Superset server arbitrary file read

Apache Superset server arbitrary file read

▾ Twilightapache-superset · apache-supersetEPSS 1.6%via OSV
CVE-2024-28397High· 8.8PoC
2y ago

js2py allows remote code execution

js2py allows remote code execution

▾ Midnightjs2py · js2pyEPSS 4.5%via OSV
CVE-2024-38357Medium· 6.1
2y ago

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

▾ Sunlittinymce · tinymceEPSS 0.53%via OSV
CVE-2024-38356Medium· 6.1
2y ago

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

▾ Sunlittinymce · tinymceEPSS 0.53%via OSV
CVE-2024-34694High· 8.1
2y ago

LNbits improperly handles potential network and payment failures when using Eclair backend

LNbits improperly handles potential network and payment failures when using Eclair backend

▾ Twilightlnbits · lnbitsEPSS 0.60%via OSV
CVE-2024-37891Medium· 4.4
2y ago

urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects

urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects

▾ Sunliturllib3 · urllib3EPSS 1.1%via OSV
CVE-2024-25142Low
2y ago

Apache Airflow does not return the "Cache-Control" header for dynamic content

Apache Airflow does not return the "Cache-Control" header for dynamic content

▾ Sunlitapache-airflow · apache-airflowEPSS 0.32%via OSV
GO-2024-2917None
2y ago

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik

▾ Sunlittraefik · github.com/traefik/traefikvia OSV
CVE-2024-36586High· 8.8
2y ago

AdGuardHome privilege escalation vulnerability

AdGuardHome privilege escalation vulnerability

▾ TwilightAdguardTeam · github.com/AdguardTeam/AdGuardHomeEPSS 0.21%via OSV
CVE-2023-49559Medium· 5.3
2y ago

gqlparser denial of service vulnerability via the parserDirectives function

gqlparser denial of service vulnerability via the parserDirectives function

▾ Sunlitvektah · github.com/vektah/gqlparser/v2EPSS 0.60%via OSV
CVE-2024-5798Low· 2.6
2y ago

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

▾ Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.34%via OSV
CVEs tagged “osv” — page 128 · VulnSea