Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2024-36039Critical· 9.8PoCPyMySQL SQL Injection vulnerability
PyMySQL SQL Injection vulnerability
CVE-2024-35180Medium· 6.1OMERO.web must check that the JSONP callback is a valid function
OMERO.web must check that the JSONP callback is a valid function
CVE-2024-35061High· 7.3NASA AIT-Core uses unencrypted channels to exchange data over the network
NASA AIT-Core uses unencrypted channels to exchange data over the network
CVE-2024-35059Critical· 9.8NASA AIT-Core vulnerable to remote code execution
NASA AIT-Core vulnerable to remote code execution
CVE-2024-35057High· 7.5NASA AIT-Core vulnerable to remote code execution
NASA AIT-Core vulnerable to remote code execution
CVE-2024-35056Critical· 9.8NASA AIT-Core vulnerable to SQL Injection
NASA AIT-Core vulnerable to SQL Injection
CVE-2024-35058High· 7.5NASA AIT-Core vulnerable to remote code execution
NASA AIT-Core vulnerable to remote code execution
CVE-2024-1727Medium· 4.3Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
CVE-2024-34083Medium· 5.4aiosmtpd STARTTLS unencrypted commands injection
aiosmtpd STARTTLS unencrypted commands injection
CVE-2024-35195Medium· 5.6Requests `Session` object does not verify requests after making first request with verify=False
Requests `Session` object does not verify requests after making first request with verify=False
CVE-2024-4264High· 7.2litellm passes untrusted data to `eval` function without sanitization
litellm passes untrusted data to `eval` function without sanitization
CVE-2024-4078Critical· 9.8LoLLMS Command Injection vulnerability
LoLLMS Command Injection vulnerability
CVE-2024-4181High· 8.8RunGptLLM class in LlamaIndex has a command injection
RunGptLLM class in LlamaIndex has a command injection
CVE-2024-35175Medium· 5.3sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address
sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address
CVE-2021-41244Critical· 9.1Grafana Fine-grained access control vulnerability
Grafana Fine-grained access control vulnerability
CVE-2021-43815Medium· 4.3Grafana directory traversal for .cvs files
Grafana directory traversal for .cvs files
CVE-2024-3727High· 8.3A flaw was found in the github.com/containers/image library
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
CVE-2024-34079Low· 3.7octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage
octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage
CVE-2024-34359Critical· 9.6llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata
llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata
CVE-2024-34707High· 7.5Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
CVE-2024-32874Critical· 9.3Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service
Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service
CVE-2024-32886Medium· 4.9Vitess vulnerable to infinite memory consumption and vtgate crash
Vitess vulnerable to infinite memory consumption and vtgate crash
CVE-2024-28148Medium· 4.3Apache Superset Incorrect Authorization vulnerability
Apache Superset Incorrect Authorization vulnerability
CVE-2024-34078HighArbitrary HTML present after sanitization because of unicode normalization
Arbitrary HTML present after sanitization because of unicode normalization
CVE-2024-34064Medium· 5.4PoCJinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
CVE-2024-32982High· 8.2Litestar and Starlite vulnerable to Path Traversal
Litestar and Starlite vulnerable to Path Traversal
CVE-2024-34069High· 7.5PoCWerkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain
CVE-2024-34487MediumRyu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34486High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34488High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability