Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2024-2196High· 8.8Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations
Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations
CVE-2024-2952Critical· 9.8LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
CVE-2024-3568Low· 3.4PoCTransformers Deserialization of Untrusted Data vulnerability
Transformers Deserialization of Untrusted Data vulnerability
CVE-2024-29905High· 8.1DIRAC: Unauthorized users can read proxy contents during generation
DIRAC: Unauthorized users can read proxy contents during generation
CVE-2024-28224High· 8.8Ollama DNS rebinding vulnerability
Ollama DNS rebinding vulnerability
CVE-2024-28732High· 7.5Ryu Infinite Loop vulnerability
Ryu Infinite Loop vulnerability
CVE-2024-3250Medium· 6.5Pebble service manager's file pull API allows access by any user
Pebble service manager's file pull API allows access by any user
CVE-2023-45288Medium· 5.3PoCnet/http, x/net/http2: close connections when receiving too many headers
net/http, x/net/http2: close connections when receiving too many headers
CVE-2024-30266Medium· 5.5wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can l…
wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, w…
CVE-2024-31215Medium· 6.3Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check
Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check
CVE-2024-3116High· 7.4PoCpgAdmin Remote Code Execution (RCE) vulnerability
pgAdmin Remote Code Execution (RCE) vulnerability
CVE-2024-28219Medium· 6.7Pillow buffer overflow vulnerability
Pillow buffer overflow vulnerability
CVE-2024-30265High· 7.5Voilà Local file inclusion
Voilà Local file inclusion
CVE-2024-30248High· 7.7Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page
Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page
CVE-2024-29893Medium· 6.5ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability
CVE-2024-29640Highaliyundrive-webdav vulnerable to Command Injection
aliyundrive-webdav vulnerable to Command Injection
CVE-2024-29888Medium· 4.2Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method
Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method
CVE-2024-28233High· 8.1Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
CVE-2024-2206High· 7.3gradio Server-Side Request Forgery vulnerability
gradio Server-Side Request Forgery vulnerability
CVE-2024-1313Medium· 6.5grafana: vulnerable to authorization bypass (CVE-2024-1313)
A vulnerability was found in Grafana. Due to an error in authorization logic, it is possible for an unprivileged user in a different organization other than the snapshot owner to perform unauthorized actions such as deleting it using a vie…
CVE-2024-1455Medium· 5.9LangChain's XMLOutputParser vulnerable to XML Entity Expansion
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
CVE-2024-29199Low· 3.7Unauthenticated views may expose information to anonymous users
Unauthenticated views may expose information to anonymous users
CVE-2024-29735Medium· 5.3Apache Airflow Improper Preservation of Permissions vulnerability
Apache Airflow Improper Preservation of Permissions vulnerability
CVE-2024-29189High· 7.4ansys-geometry-core OS Command Injection vulnerability
ansys-geometry-core OS Command Injection vulnerability
CVE-2024-1603High· 7.5PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file
PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file
CVE-2024-29190High· 7.3SSRF Vulnerability on assetlinks_check(act_name, well_knowns)
SSRF Vulnerability on assetlinks_check(act_name, well_knowns)
CVE-2024-29019High· 8.1ESPHome vulnerable to Authentication bypass via Cross site request forgery
ESPHome vulnerable to Authentication bypass via Cross site request forgery
CVE-2024-1394High· 7.5Memory leaks in code encrypting and verifying RSA payloads
Memory leaks in code encrypting and verifying RSA payloads
CVE-2024-29032Medium· 5.3`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code
`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code
CVE-2024-29033High· 7.5GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace