Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
GO-2024-2941NoneACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik
ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik
CVE-2024-5899NoneImproper trust check in Bazel Build intellij plugin in github.com/bazelbuild/intellij
Improper trust check in Bazel Build intellij plugin in github.com/bazelbuild/intellij
CVE-2024-5980Critical· 9.1pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
CVE-2024-6090High· 7.5A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histo…
A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target s…
CVE-2024-6038High· 7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerabilit…
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-p…
CVE-2024-6139High· 7.3lollms vulnerable to dot-dot-slash path traversal in XTTS server
lollms vulnerable to dot-dot-slash path traversal in XTTS server
CVE-2024-5710Medium· 5.3litellm vulnerable to improper access control in team management
litellm vulnerable to improper access control in team management
CVE-2024-22231Medium· 5.0Directory creation by malicious user in saltstack
Directory creation by malicious user in saltstack
CVE-2024-5824High· 7.4lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE
lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE
CVE-2024-6085High· 8.6lollms vulnerable to path traversal due to unauthenticated root folder settings change
lollms vulnerable to path traversal due to unauthenticated root folder settings change
CVE-2024-5979High· 7.5h2o vulnerable to unexpected POST request shutting down server
h2o vulnerable to unexpected POST request shutting down server
CVE-2024-22232High· 7.7Path traversal in saltstack
Path traversal in saltstack
CVE-2024-21520Medium· 6.1PoCCross-site Scripting in djangorestframework
Cross-site Scripting in djangorestframework
CVE-2024-37820Medium· 5.4PingCAP TiDB nil pointer dereference
PingCAP TiDB nil pointer dereference
CVE-2024-38526High· 7.2PoCpdoc embeds link to malicious CDN if math mode is enabled
pdoc embeds link to malicious CDN if math mode is enabled
CVE-2024-4460Medium· 4.3Improper line feed handling in zenml
Improper line feed handling in zenml
CVE-2024-3121Medium· 6.8PoCRemote Code Execution in create_conda_env function in lollms
Remote Code Execution in create_conda_env function in lollms
CVE-2024-4940Medium· 5.4PoCOpen redirect in gradio
Open redirect in gradio
GHSA-rvj4-q8q5-8grfMedium· 5.5ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability
ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability
CVE-2024-34693Medium· 6.8PoCApache Superset server arbitrary file read
Apache Superset server arbitrary file read
CVE-2024-28397High· 8.8PoCjs2py allows remote code execution
js2py allows remote code execution
CVE-2024-38357Medium· 6.1TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements
TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements
CVE-2024-38356Medium· 6.1TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option
TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option
CVE-2024-34694High· 8.1LNbits improperly handles potential network and payment failures when using Eclair backend
LNbits improperly handles potential network and payment failures when using Eclair backend
CVE-2024-37891Medium· 4.4urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
CVE-2024-25142LowApache Airflow does not return the "Cache-Control" header for dynamic content
Apache Airflow does not return the "Cache-Control" header for dynamic content
GO-2024-2917NoneTraefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik
CVE-2024-36586High· 8.8AdGuardHome privilege escalation vulnerability
AdGuardHome privilege escalation vulnerability
CVE-2023-49559Medium· 5.3gqlparser denial of service vulnerability via the parserDirectives function
gqlparser denial of service vulnerability via the parserDirectives function
CVE-2024-5798Low· 2.6HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims