Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2024-34484MediumRyu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34483High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34489High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-34511Medium· 6.5Gradio's Component Server does not properly consider` _is_server_fn` for functions
Gradio's Component Server does not properly consider` _is_server_fn` for functions
CVE-2024-34072High· 7.8sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data
sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data
CVE-2024-34061Medium· 4.3PoCchangedetection.io Cross-site Scripting vulnerability
changedetection.io Cross-site Scripting vulnerability
CVE-2024-34062Low· 3.9tqdm CLI arguments injection attack
tqdm CLI arguments injection attack
CVE-2024-34073High· 7.8sagemaker-python-sdk Command Injection vulnerability
sagemaker-python-sdk Command Injection vulnerability
CVE-2024-30251High· 7.5aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests
CVE-2024-33394Medium· 5.9kubevirt allows a local attacker to execute arbitrary code via a crafted command
kubevirt allows a local attacker to execute arbitrary code via a crafted command
CVE-2024-4216High· 7.4pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload
pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload
CVE-2024-4215High· 7.4pgAdmin is affected by a multi-factor authentication bypass vulnerability
pgAdmin is affected by a multi-factor authentication bypass vulnerability
CVE-2024-32963Medium· 4.2Navidrome Parameter Tampering vulnerability
Navidrome Parameter Tampering vulnerability
CVE-2024-32882Low· 2.7Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`
Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`
CVE-2024-32979High· 7.5nautobot has reflected Cross-site Scripting potential in all object list views
nautobot has reflected Cross-site Scripting potential in all object list views
CVE-2024-33522Medium· 6.7Calico privilege escalation vulnerability
Calico privilege escalation vulnerability
CVE-2023-46565High· 7.5Buffer Overflow vulnerability in osrg gobgp
Buffer Overflow vulnerability in osrg gobgp
CVE-2023-46960High· 8.6PyPXE Buffer Overflow vulnerability
PyPXE Buffer Overflow vulnerability
CVE-2023-1000Medium· 6.3dcnnt-py is vulnerable to command injection via Notification Handler
dcnnt-py is vulnerable to command injection via Notification Handler
CVE-2024-33663High· 7.4python-jose algorithm confusion with OpenSSH ECDSA keys
python-jose algorithm confusion with OpenSSH ECDSA keys
CVE-2024-3154High· 7.2A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
CVE-2024-32476Medium· 6.5Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
Argo CD vulnerable to a Denial of Service via malicious jqPathExpressions in ignoreDifferences
CVE-2020-8559Medium· 6.8PoCPrivilege Escalation in Kubernetes
Privilege Escalation in Kubernetes
CVE-2021-36775High· 8.0Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
CVE-2021-31999High· 8.8Rancher Privilege escalation vulnerability via malicious "Connection" header
Rancher Privilege escalation vulnerability via malicious "Connection" header
CVE-2021-25318High· 8.8Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources
Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources
CVE-2024-32880Critical· 9.1pyLoad allows upload to arbitrary folder lead to RCE
pyLoad allows upload to arbitrary folder lead to RCE
CVE-2024-32879Medium· 4.9social-auth-app-django affected by Improper Handling of Case Sensitivity
social-auth-app-django affected by Improper Handling of Case Sensitivity
CVE-2024-31208Medium· 6.5Synapse V2 state resolution weakness allows Denial of Service (DoS)
Synapse V2 state resolution weakness allows Denial of Service (DoS)
CVE-2022-24769Medium· 5.9Moby (Docker Engine) started with non-empty inheritable Linux process capabilities
Moby (Docker Engine) started with non-empty inheritable Linux process capabilities