VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5670 CVEsRSS

CVE-2026-88013Low· 3.7PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backen…

▾ Twilightrclone · rcloneEPSS 0.19%via NVD
CVE-2026-88045High· 7.5PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentL…

▾ Midnightrclone · rcloneEPSS 0.63%via NVD
CVE-2026-88016High· 7.1PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and l…

▾ Midnightrclone · rcloneEPSS 0.27%via NVD
CVE-2026-88009High· 8.2
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path eval…

▾ Twilighttraefik · traefikEPSS 0.44%via NVD
CVE-2026-88004High· 7.4
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing a…

▾ Twilighttraefik · traefikEPSS 0.45%via NVD
MAL-2026-16125Critical⚠ Exploited
2w ago

Malicious code in lucy-python-script-2030 (PyPI)

Malicious code in lucy-python-script-2030 (PyPI)

▾ Abyssallucy-python-script-2030 · lucy-python-script-2030via OSV
MAL-2026-16122Critical⚠ Exploited
2w ago

Malicious code in pylever (PyPI)

Malicious code in pylever (PyPI)

▾ Abyssalpylever · pylevervia OSV
CVE-2026-88014Medium· 6.3
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 until 1.75.1, the archive ZIP backend method (*Fs).readZip in backend/archive/zip/zip.go accepts archive/zip.File.N…

▾ Sunlitrclone · rcloneEPSS 0.20%via NVD
CVE-2026-88008Critical· 9.1PoC⚖ disputed
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backen…

▾ Abyssaltraefik · traefikEPSS 0.49%via NVD
CVE-2026-88011High· 8.1⚖ disputed
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy …

▾ Twilighttraefik · traefikEPSS 0.42%via NVD
CVE-2026-88007Critical· 9.1
2w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport …

▾ Midnighttraefik · traefikEPSS 0.60%via NVD
RUSTSEC-2026-0297None
2w ago

`unzip`: archive extraction is vulnerable to path traversal (zip-slip)

`unzip`: archive extraction is vulnerable to path traversal (zip-slip)

▾ Sunlitunzip · unzipvia OSV
RUSTSEC-2026-0291None
2w ago

Double free in `OwnedAlloc::drop_in_place` when the contained value's `Drop` panics

Double free in `OwnedAlloc::drop_in_place` when the contained value's `Drop` panics

▾ Sunlitowned-alloc · owned-allocvia OSV
MAL-2026-16121Critical⚠ Exploited
2w ago

Malicious code in websetup (PyPI)

Malicious code in websetup (PyPI)

▾ Abyssalwebsetup · websetupvia OSV
CVE-2026-59177High· 8.8PoC
2w ago

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

▾ Midnightesphome-device-builder · esphome-device-buildervia OSV
CVE-2026-87012Medium· 4.3
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the share…

▾ Sunlitopenwebui · open_webuiEPSS 0.48%via NVD
CVE-2026-87014Medium· 6.5PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's d…

▾ Twilightopenwebui · open_webuiEPSS 0.51%via NVD
CVE-2026-87818Medium· 6.5PoC
2w ago

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create…

▾ Twilightgitpython_project · gitpythonEPSS 0.41%via NVD
RUSTSEC-2026-0282None
2w ago

Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics

Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics

▾ Sunlitaligned_box · aligned_boxvia OSV
GO-2026-6302None
2w ago

Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2

Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2

▾ Sunlitcrossplane · github.com/crossplane/crossplane-runtime/v2via OSV
MAL-2026-16099Critical⚠ Exploited
2w ago

Malicious code in bq-sdist-probe-vrp (PyPI)

Malicious code in bq-sdist-probe-vrp (PyPI)

▾ Abyssalbq-sdist-probe-vrp · bq-sdist-probe-vrpvia OSV
MAL-2026-16098Critical⚠ Exploited
2w ago

Malicious code in bq-build-probe-vrp-2026 (PyPI)

Malicious code in bq-build-probe-vrp-2026 (PyPI)

▾ Abyssalbq-build-probe-vrp-2026 · bq-build-probe-vrp-2026via OSV
MAL-2026-16080Critical⚠ Exploited
2w ago

Malicious code in databricks-webapp-navigation-homepage (PyPI)

Malicious code in databricks-webapp-navigation-homepage (PyPI)

▾ Abyssaldatabricks-webapp-navigation-homepage · databricks-webapp-navigation-homepagevia OSV
GHSA-hxjg-93wc-h8p8High· 8.8
2w ago

Komari: Management Interface CSRF

Komari: Management Interface CSRF

▾ Twilightkomari-monitor · github.com/komari-monitor/komarivia OSV
CVE-2026-59185High· 8.5
2w ago

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

▾ Twilightidentrail · github.com/identrail/identrailvia OSV
CVE-2026-59172High· 7.8
2w ago

Joker linter executed project-local .jokerd/linter.* files during linting

Joker linter executed project-local .jokerd/linter.* files during linting

▾ Twilightcandid82 · github.com/candid82/jokervia OSV
CVE-2026-87996High· 7.7
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then l…

▾ Twilightopenwebui · open_webuiEPSS 0.35%via NVD
CVE-2025-24979Medium· 5.5
2w ago

LF Edge eKuiper: SSRF in External Service

LF Edge eKuiper: SSRF in External Service

▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2025-24978Low· 3.7
2w ago

LF Edge eKuiper: Self-XSS in External Service Creation

LF Edge eKuiper: Self-XSS in External Service Creation

▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2025-58363Medium· 5.5
2w ago

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVEs tagged “osv” — page 13 · VulnSea