VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2024-37300High· 8.1
2y ago

Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0

Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0

▾ Twilightoauthenticator · oauthenticatorEPSS 0.40%via OSV
GHSA-7jmw-8259-q9jxMedium
2y ago

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses

▾ Sunlittraefik · github.com/traefik/traefik/v3via OSV
CVE-2024-37301High· 7.2
2y ago

document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection

document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection

▾ Twilightdocument-merge-service · document-merge-serviceEPSS 1.0%via OSV
CVE-2024-35255Medium· 5.5
2y ago

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

▾ Sunlitazure-identity · azure-identityEPSS 0.83%via OSV
GHSA-87m9-rv8p-rgmgHigh· 7.5
2y ago

go-grpc-compression has a zstd decompression bombing vulnerability

go-grpc-compression has a zstd decompression bombing vulnerability

▾ Twilightmostynb · github.com/mostynb/go-grpc-compressionvia OSV
CVE-2021-41089Low· 2.8
2y ago

`docker cp` allows unexpected chmod of host files in Moby Docker Engine

`docker cp` allows unexpected chmod of host files in Moby Docker Engine

▾ Sunlitdocker · github.com/docker/dockerEPSS 0.29%via OSV
CVE-2021-41092Medium· 5.4
2y ago

Docker CLI leaks private registry credentials to registry-1.docker.io

Docker CLI leaks private registry credentials to registry-1.docker.io

▾ Sunlitdocker · github.com/docker/cliEPSS 1.7%via OSV
CVE-2024-4680Low· 3.9
2y ago

zenml-io/zenml does not expire the session after password reset

zenml-io/zenml does not expire the session after password reset

▾ Sunlitzenml · zenmlEPSS 0.41%via OSV
CVE-2024-37388Critical· 9.1
2y ago

ebookmeta XML External Entity vulnerability

ebookmeta XML External Entity vulnerability

▾ Midnightebookmeta · ebookmetaEPSS 0.54%via OSV
CVE-2024-37152Medium· 5.3PoC
2y ago

Unauthenticated Access to sensitive settings in Argo CD

Unauthenticated Access to sensitive settings in Argo CD

▾ Twilightargoproj · github.com/argoproj/argo-cd/v2/serverEPSS 2.3%via OSV
CVE-2024-36106Medium· 4.3
2y ago

Argo-cd authenticated users can enumerate clusters by name

Argo-cd authenticated users can enumerate clusters by name

▾ Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.41%via OSV
GHSA-w235-7p84-xx57Medium· 6.5
2y ago

Tornado has a CRLF injection in CurlAsyncHTTPClient headers

Tornado has a CRLF injection in CurlAsyncHTTPClient headers

▾ Sunlittornado · tornadovia OSV
CVE-2024-5206Medium· 5.3
2y ago

scikit-learn sensitive data leakage vulnerability

scikit-learn sensitive data leakage vulnerability

▾ Sunlitscikit-learn · scikit-learnEPSS 0.19%via OSV
CVE-2024-35178High· 7.5
2y ago

Jupyter server on Windows discloses Windows user password hash

Jupyter server on Windows discloses Windows user password hash

▾ Twilightjupyter-server · jupyter-serverEPSS 0.70%via OSV
CVE-2024-5452Critical· 9.8PoC
2y ago

Remote code execution in pytorch lightning

Remote code execution in pytorch lightning

▾ Abyssallightning · lightningEPSS 27%via OSV
GHSA-753j-mpmx-qq6gMedium· 5.3
2y ago

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado

▾ Sunlittornado · tornadovia OSV
CVE-2024-2965Medium· 4.2
2y ago

Denial of service in langchain-community

Denial of service in langchain-community

▾ Sunlitlangchain-community · langchain-communityEPSS 0.30%via OSV
CVE-2024-5550Medium· 5.3
2y ago

Arbitrary system path lookup in h20

Arbitrary system path lookup in h20

▾ Sunlith2o · h2oEPSS 0.83%via OSV
CVE-2024-3095Medium· 4.8
2y ago

Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever

Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever

▾ Sunlitlangchain-community · langchain-communityEPSS 0.69%via OSV
CVE-2024-5225Medium· 6.4
2y ago

SQL injection in litellm

SQL injection in litellm

▾ Sunlitlitellm · litellmEPSS 0.43%via OSV
CVE-2024-4325High· 8.6PoC
2y ago

Server-Side Request Forgery in gradio

Server-Side Request Forgery in gradio

▾ Midnightgradio · gradioEPSS 37%via OSV
CVE-2024-4890Medium· 4.9PoC
2y ago

SQL injection in litellm

SQL injection in litellm

▾ Twilightlitellm · litellmEPSS 0.56%via OSV
CVE-2024-3099Medium· 5.4
2y ago

Undefined Behavior in mlflow

Undefined Behavior in mlflow

▾ Sunlitmlflow · mlflowEPSS 0.44%via OSV
CVE-2024-4888Medium· 6.5
2y ago

Arbitrary file deletion in litellm

Arbitrary file deletion in litellm

▾ Sunlitlitellm · litellmEPSS 0.62%via OSV
CVE-2024-3429Critical· 9.8
2y ago

LoLLMS Path Traversal vulnerability

LoLLMS Path Traversal vulnerability

▾ Midnightlollms · lollmsEPSS 28%via OSV
GO-2024-2880None
2y ago

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik

▾ Sunlittraefik · github.com/traefik/traefikvia OSV
GO-2024-2726None
2y ago

Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik

Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik

▾ Sunlittraefik · github.com/traefik/traefikvia OSV
CVE-2024-5629Medium· 4.7
2y ago

PyMongo Out-of-bounds Read in the bson module

PyMongo Out-of-bounds Read in the bson module

▾ Sunlitpymongo · pymongoEPSS 0.66%via OSV
CVE-2024-4253Critical· 9.1PoC
2y ago

A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The…

A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing…

▾ Abyssalgradio · gradioEPSS 1.7%via OSV
CVE-2024-5154High· 8.1
2y ago

malicious container creates symlink "mtab" on the host External

malicious container creates symlink "mtab" on the host External

▾ Twilightcri-o · github.com/cri-o/cri-oEPSS 1.2%via OSV
CVEs tagged “osv” — page 129 · VulnSea