VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2024-36039Critical· 9.8PoC
2y ago

PyMySQL SQL Injection vulnerability

PyMySQL SQL Injection vulnerability

▾ Abyssalpymysql · pymysqlEPSS 0.69%via OSV
CVE-2024-35180Medium· 6.1
2y ago

OMERO.web must check that the JSONP callback is a valid function

OMERO.web must check that the JSONP callback is a valid function

▾ Sunlitomero-web · omero-webEPSS 0.29%via OSV
CVE-2024-35061High· 7.3
2y ago

NASA AIT-Core uses unencrypted channels to exchange data over the network

NASA AIT-Core uses unencrypted channels to exchange data over the network

▾ Twilightait-core · ait-coreEPSS 0.55%via OSV
CVE-2024-35059Critical· 9.8
2y ago

NASA AIT-Core vulnerable to remote code execution

NASA AIT-Core vulnerable to remote code execution

▾ Midnightait-core · ait-coreEPSS 0.45%via OSV
CVE-2024-35057High· 7.5
2y ago

NASA AIT-Core vulnerable to remote code execution

NASA AIT-Core vulnerable to remote code execution

▾ Twilightait-core · ait-coreEPSS 0.44%via OSV
CVE-2024-35056Critical· 9.8
2y ago

NASA AIT-Core vulnerable to SQL Injection

NASA AIT-Core vulnerable to SQL Injection

▾ Midnightait-core · ait-coreEPSS 0.61%via OSV
CVE-2024-35058High· 7.5
2y ago

NASA AIT-Core vulnerable to remote code execution

NASA AIT-Core vulnerable to remote code execution

▾ Twilightait-core · ait-coreEPSS 0.44%via OSV
CVE-2024-1727Medium· 4.3
2y ago

Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files

Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files

▾ Sunlitgradio · gradioEPSS 0.35%via OSV
CVE-2024-34083Medium· 5.4
2y ago

aiosmtpd STARTTLS unencrypted commands injection

aiosmtpd STARTTLS unencrypted commands injection

▾ Sunlitaiosmtpd · aiosmtpdEPSS 0.23%via OSV
CVE-2024-35195Medium· 5.6
2y ago

Requests `Session` object does not verify requests after making first request with verify=False

Requests `Session` object does not verify requests after making first request with verify=False

▾ Sunlitrequests · requestsEPSS 0.34%via OSV
CVE-2024-4264High· 7.2
2y ago

litellm passes untrusted data to `eval` function without sanitization

litellm passes untrusted data to `eval` function without sanitization

▾ Twilightlitellm · litellmEPSS 0.88%via OSV
CVE-2024-4078Critical· 9.8
2y ago

LoLLMS Command Injection vulnerability

LoLLMS Command Injection vulnerability

▾ Midnightlollms · lollmsEPSS 0.92%via OSV
CVE-2024-4181High· 8.8
2y ago

RunGptLLM class in LlamaIndex has a command injection

RunGptLLM class in LlamaIndex has a command injection

▾ Twilightllama-index · llama-indexEPSS 2.1%via OSV
CVE-2024-35175Medium· 5.3
2y ago

sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address

sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address

▾ Sunlittg123 · github.com/tg123/sshpiperEPSS 0.26%via OSV
CVE-2021-41244Critical· 9.1
2y ago

Grafana Fine-grained access control vulnerability

Grafana Fine-grained access control vulnerability

▾ Midnightgrafana · github.com/grafana/grafanaEPSS 2.9%via OSV
CVE-2021-43815Medium· 4.3
2y ago

Grafana directory traversal for .cvs files

Grafana directory traversal for .cvs files

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.8%via OSV
CVE-2024-3727High· 8.3
2y ago

A flaw was found in the github.com/containers/image library

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

▾ Twilightcontainers · github.com/containers/imageEPSS 1.3%via NVD
CVE-2024-34079Low· 3.7
2y ago

octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage

octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage

▾ Sunlitocto-sts · github.com/octo-sts/appEPSS 0.58%via OSV
CVE-2024-34359Critical· 9.6
2y ago

llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata

llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata

▾ Midnightllama-cpp-python · llama-cpp-pythonEPSS 26%via OSV
CVE-2024-34707High· 7.5
2y ago

Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages

Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages

▾ Twilightnautobot · nautobotEPSS 0.61%via OSV
CVE-2024-32874Critical· 9.3
2y ago

Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service

Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service

▾ Midnightfrigate · frigateEPSS 0.77%via OSV
CVE-2024-32886Medium· 4.9
2y ago

Vitess vulnerable to infinite memory consumption and vtgate crash

Vitess vulnerable to infinite memory consumption and vtgate crash

▾ Sunlitvitessio · github.com/vitessio/vitessEPSS 0.75%via OSV
CVE-2024-28148Medium· 4.3
2y ago

Apache Superset Incorrect Authorization vulnerability

Apache Superset Incorrect Authorization vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 0.70%via OSV
CVE-2024-34078High
2y ago

Arbitrary HTML present after sanitization because of unicode normalization

Arbitrary HTML present after sanitization because of unicode normalization

▾ Twilighthtml-sanitizer · html-sanitizerEPSS 0.55%via OSV
CVE-2024-34064Medium· 5.4PoC
2y ago

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

▾ Twilightjinja2 · jinja2EPSS 0.98%via OSV
CVE-2024-32982High· 8.2
2y ago

Litestar and Starlite vulnerable to Path Traversal

Litestar and Starlite vulnerable to Path Traversal

▾ Twilightlitestar · litestarEPSS 0.72%via OSV
CVE-2024-34069High· 7.5PoC
2y ago

Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain

▾ Midnightwerkzeug · werkzeugEPSS 3.4%via OSV
CVE-2024-34487Medium
2y ago

Ryu Infinite Loop vulnerability

Ryu Infinite Loop vulnerability

▾ Sunlitryu · ryuEPSS 0.68%via OSV
CVE-2024-34486High· 7.5
2y ago

Ryu Infinite Loop vulnerability

Ryu Infinite Loop vulnerability

▾ Twilightryu · ryuEPSS 0.65%via OSV
CVE-2024-34488High· 7.5
2y ago

Ryu Infinite Loop vulnerability

Ryu Infinite Loop vulnerability

▾ Twilightryu · ryuEPSS 0.68%via OSV
CVEs tagged “osv” — page 131 · VulnSea