VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2024-34484Medium
2y ago

Ryu Infinite Loop vulnerability

Ryu Infinite Loop vulnerability

▾ Sunlitryu · ryuEPSS 0.46%via OSV
CVE-2024-34483High· 7.5
2y ago

Ryu Infinite Loop vulnerability

Ryu Infinite Loop vulnerability

▾ Twilightryu · ryuEPSS 0.68%via OSV
CVE-2024-34489High· 7.5
2y ago

Ryu Infinite Loop vulnerability

Ryu Infinite Loop vulnerability

▾ Twilightryu · ryuEPSS 0.68%via OSV
CVE-2024-34511Medium· 6.5
2y ago

Gradio's Component Server does not properly consider` _is_server_fn` for functions

Gradio's Component Server does not properly consider` _is_server_fn` for functions

▾ Sunlitgradio · gradiovia OSV
CVE-2024-34072High· 7.8
2y ago

sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data

sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data

▾ Twilightsagemaker · sagemakerEPSS 0.41%via OSV
CVE-2024-34061Medium· 4.3PoC
2y ago

changedetection.io Cross-site Scripting vulnerability

changedetection.io Cross-site Scripting vulnerability

▾ Twilightchangedetection-io · changedetection-ioEPSS 1.3%via OSV
CVE-2024-34062Low· 3.9
2y ago

tqdm CLI arguments injection attack

tqdm CLI arguments injection attack

▾ Sunlittqdm · tqdmEPSS 0.44%via OSV
CVE-2024-34073High· 7.8
2y ago

sagemaker-python-sdk Command Injection vulnerability

sagemaker-python-sdk Command Injection vulnerability

▾ Twilightsagemaker · sagemakerEPSS 1.2%via OSV
CVE-2024-30251High· 7.5
2y ago

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

▾ Twilightaiohttp · aiohttpEPSS 1.1%via OSV
CVE-2024-33394Medium· 5.9
2y ago

kubevirt allows a local attacker to execute arbitrary code via a crafted command

kubevirt allows a local attacker to execute arbitrary code via a crafted command

▾ Sunlitkubevirt · kubevirt.io/kubevirtEPSS 0.33%via OSV
CVE-2024-4216High· 7.4
2y ago

pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload

pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload

▾ Twilightpgadmin4 · pgadmin4EPSS 0.46%via OSV
CVE-2024-4215High· 7.4
2y ago

pgAdmin is affected by a multi-factor authentication bypass vulnerability

pgAdmin is affected by a multi-factor authentication bypass vulnerability

▾ Twilightpgadmin4 · pgadmin4EPSS 0.63%via OSV
CVE-2024-32963Medium· 4.2
2y ago

Navidrome Parameter Tampering vulnerability

Navidrome Parameter Tampering vulnerability

▾ Sunlitnavidrome · github.com/navidrome/navidromeEPSS 0.41%via OSV
CVE-2024-32882Low· 2.7
2y ago

Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`

Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`

▾ Sunlitwagtail · wagtailEPSS 0.48%via OSV
CVE-2024-32979High· 7.5
2y ago

nautobot has reflected Cross-site Scripting potential in all object list views

nautobot has reflected Cross-site Scripting potential in all object list views

▾ Twilightnautobot · nautobotEPSS 0.49%via OSV
CVE-2024-33522Medium· 6.7
2y ago

Calico privilege escalation vulnerability

Calico privilege escalation vulnerability

▾ Sunlitprojectcalico · github.com/projectcalico/calicoEPSS 0.22%via OSV
CVE-2023-46565High· 7.5
2y ago

Buffer Overflow vulnerability in osrg gobgp

Buffer Overflow vulnerability in osrg gobgp

▾ Twilightosrg · github.com/osrg/gobgp/v3EPSS 0.74%via OSV
CVE-2023-46960High· 8.6
2y ago

PyPXE Buffer Overflow vulnerability

PyPXE Buffer Overflow vulnerability

▾ Twilightpypxe · pypxeEPSS 0.54%via OSV
CVE-2023-1000Medium· 6.3
2y ago

dcnnt-py is vulnerable to command injection via Notification Handler

dcnnt-py is vulnerable to command injection via Notification Handler

▾ Sunlitdcnnt · dcnntEPSS 1.3%via OSV
CVE-2024-33663High· 7.4
2y ago

python-jose algorithm confusion with OpenSSH ECDSA keys

python-jose algorithm confusion with OpenSSH ECDSA keys

▾ Twilightpython-jose · python-joseEPSS 0.31%via OSV
CVE-2024-3154High· 7.2
2y ago

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.

▾ Twilightcri-o · github.com/cri-o/cri-oEPSS 1.4%via NVD
CVE-2024-32476Medium· 6.5
2y ago

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences

Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 1.0%via OSV
CVE-2020-8559Medium· 6.8PoC
2y ago

Privilege Escalation in Kubernetes

Privilege Escalation in Kubernetes

▾ Twilightapimachinery · k8s.io/apimachineryEPSS 6.1%via OSV
CVE-2021-36775High· 8.0
2y ago

Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication

Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.97%via OSV
CVE-2021-31999High· 8.8
2y ago

Rancher Privilege escalation vulnerability via malicious "Connection" header

Rancher Privilege escalation vulnerability via malicious "Connection" header

▾ Twilightrancher · github.com/rancher/rancherEPSS 1.1%via OSV
CVE-2021-25318High· 8.8
2y ago

Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources

Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources

▾ Twilightrancher · github.com/rancher/rancherEPSS 1.1%via OSV
CVE-2024-32880Critical· 9.1
2y ago

pyLoad allows upload to arbitrary folder lead to RCE

pyLoad allows upload to arbitrary folder lead to RCE

▾ Midnightpyload-ng · pyload-ngEPSS 1.4%via OSV
CVE-2024-32879Medium· 4.9
2y ago

social-auth-app-django affected by Improper Handling of Case Sensitivity

social-auth-app-django affected by Improper Handling of Case Sensitivity

▾ Sunlitsocial-auth-app-django · social-auth-app-djangoEPSS 0.58%via OSV
CVE-2024-31208Medium· 6.5
2y ago

Synapse V2 state resolution weakness allows Denial of Service (DoS)

Synapse V2 state resolution weakness allows Denial of Service (DoS)

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.5%via OSV
CVE-2022-24769Medium· 5.9
2y ago

Moby (Docker Engine) started with non-empty inheritable Linux process capabilities

Moby (Docker Engine) started with non-empty inheritable Linux process capabilities

▾ Sunlitmoby · github.com/moby/mobyEPSS 0.49%via OSV
CVEs tagged “osv” — page 132 · VulnSea