Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2024-28717High· 7.8OpenStack Storlets arbitrary code execution vulnerability
OpenStack Storlets arbitrary code execution vulnerability
CVE-2024-29733Low· 2.7Improper Certificate Validation vulnerability in Apache Airflow FTP Provider
Improper Certificate Validation vulnerability in Apache Airflow FTP Provider
CVE-2024-1681Medium· 5.3flask-cors vulnerable to log injection when the log level is set to debug
flask-cors vulnerable to log injection when the log level is set to debug
CVE-2024-30257Medium· 5.91Panel's password verification is suspected to have a timing attack vulnerability
1Panel's password verification is suspected to have a timing attack vulnerability
CVE-2024-27306Medium· 6.1aiohttp Cross-site Scripting vulnerability on index pages for static file handling
aiohttp Cross-site Scripting vulnerability on index pages for static file handling
CVE-2024-32474High· 7.3Sentry vulnerable to leaking superuser cleartext password in logs
Sentry vulnerable to leaking superuser cleartext password in logs
CVE-2024-31869Medium· 4.3Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
CVE-2024-31580High· 7.5PyTorch heap buffer overflow vulnerability
PyTorch heap buffer overflow vulnerability
CVE-2024-1135High· 8.2Request smuggling leading to endpoint restriction bypass in Gunicorn
Request smuggling leading to endpoint restriction bypass in Gunicorn
CVE-2024-3571Medium· 6.5langchain vulnerable to path traversal
langchain vulnerable to path traversal
CVE-2024-1183Medium· 6.5PoCgradio Server-Side Request Forgery vulnerability
gradio Server-Side Request Forgery vulnerability
CVE-2024-1594High· 7.5mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-1558High· 7.5mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-1561High· 7.5PoCgradio vulnerable to Path Traversal
gradio vulnerable to Path Traversal
CVE-2024-1483High· 7.5PoCmlflow Path Traversal vulnerability
mlflow Path Traversal vulnerability
CVE-2024-1593High· 7.5mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
CVE-2024-1560High· 8.1mlflow vulnerable to Path Traversal
mlflow vulnerable to Path Traversal
GHSA-7f4j-64p6-5h5vMediumTraefik affected by HTTP/2 CONTINUATION flood in net/http
Traefik affected by HTTP/2 CONTINUATION flood in net/http
CVE-2024-31990Medium· 4.8Argo CD's API server does not enforce project sourceNamespaces
Argo CD's API server does not enforce project sourceNamespaces
CVE-2024-3772Medium· 5.9Pydantic regular expression denial of service
Pydantic regular expression denial of service
CVE-2024-4340High· 7.5sqlparse parsing heavily nested list leads to Denial of Service
sqlparse parsing heavily nested list leads to Denial of Service
CVE-2024-28869High· 7.5traefik: denial of service (CVE-2024-28869)
An improper handling of exceptional conditions vulnerability was found in Traefik. In affected versions, sending a GET request to any Traefik endpoint with the "Content-length" request header results in an indefinite hang with the default …
CVE-2024-32005High· 8.2NiceGUI allows potential access to local file system
NiceGUI allows potential access to local file system
CVE-2024-28718Medium· 6.3OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack
OpenStack magnum vulnerable to time-of-check to time-of-use (TOCTOU) attack
CVE-2024-29902Medium· 4.2Cosign malicious attachments can cause system-wide denial of service
Cosign malicious attachments can cause system-wide denial of service
CVE-2024-3651Medium· 6.2PoCInternationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode
Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode
CVE-2023-29483Medium· 5.9Potential DoS via the Tudoor mechanism in eventlet and dnspython
Potential DoS via the Tudoor mechanism in eventlet and dnspython
CVE-2024-32644Critical· 9.1Evmos transaction execution not accounting for all state transition after interaction with precompiles
Evmos transaction execution not accounting for all state transition after interaction with precompiles
CVE-2024-2195Critical· 9.8Aim Web API vulnerable to Remote Code Execution
Aim Web API vulnerable to Remote Code Execution
CVE-2024-2217High· 7.5gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnera…
gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is present in both authenticated and unauthenticated versions of the application, enabling at…