VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2024-2196High· 8.8
2y ago

Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations

Aim Cross-Site Request Forgery vulnerability allows user to delete runs and perform other operations

▾ Twilightaim · aimEPSS 0.59%via OSV
CVE-2024-2952Critical· 9.8
2y ago

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint

▾ Midnightlitellm · litellmEPSS 1.3%via OSV
CVE-2024-3568Low· 3.4PoC
2y ago

Transformers Deserialization of Untrusted Data vulnerability

Transformers Deserialization of Untrusted Data vulnerability

▾ Twilighttransformers · transformersEPSS 2.1%via OSV
CVE-2024-29905High· 8.1
2y ago

DIRAC: Unauthorized users can read proxy contents during generation

DIRAC: Unauthorized users can read proxy contents during generation

▾ Twilightdirac · diracEPSS 0.32%via OSV
CVE-2024-28224High· 8.8
2y ago

Ollama DNS rebinding vulnerability

Ollama DNS rebinding vulnerability

▾ Twilightollama · github.com/ollama/ollamaEPSS 0.35%via OSV
CVE-2024-28732High· 7.5
2y ago

Ryu Infinite Loop vulnerability

Ryu Infinite Loop vulnerability

▾ Twilightryu · ryuEPSS 0.82%via OSV
CVE-2024-3250Medium· 6.5
2y ago

Pebble service manager's file pull API allows access by any user

Pebble service manager's file pull API allows access by any user

▾ Sunlitcanonical · github.com/canonical/pebbleEPSS 0.20%via OSV
CVE-2023-45288Medium· 5.3PoC
2y ago

net/http, x/net/http2: close connections when receiving too many headers

net/http, x/net/http2: close connections when receiving too many headers

▾ Twilightnet · net/httpEPSS 92%via OSV
CVE-2024-30266Medium· 5.5
2y ago

wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can l…

wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, w…

▾ Sunlitwasmtime · wasmtimeEPSS 0.32%via OSV
CVE-2024-31215Medium· 6.3
2y ago

Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check

Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check

▾ Sunlitmobsf · mobsfEPSS 0.51%via OSV
CVE-2024-3116High· 7.4PoC
2y ago

pgAdmin Remote Code Execution (RCE) vulnerability

pgAdmin Remote Code Execution (RCE) vulnerability

▾ Midnightpgadmin4 · pgadmin4EPSS 66%via OSV
CVE-2024-28219Medium· 6.7
2y ago

Pillow buffer overflow vulnerability

Pillow buffer overflow vulnerability

▾ Sunlitpillow · pillowEPSS 1.00%via OSV
CVE-2024-30265High· 7.5
2y ago

Voilà Local file inclusion

Voilà Local file inclusion

▾ Twilightvoila · voilaEPSS 0.73%via OSV
CVE-2024-30248High· 7.7
2y ago

Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page

Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page

▾ Twilightpiccolo-admin · piccolo-adminEPSS 0.49%via OSV
CVE-2024-29893Medium· 6.5
2y ago

ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability

ArgoCD's repo server has Uncontrolled Resource Consumption vulnerability

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.97%via OSV
CVE-2024-29640High
2y ago

aliyundrive-webdav vulnerable to Command Injection

aliyundrive-webdav vulnerable to Command Injection

▾ Twilightaliyundrive-webdav · aliyundrive-webdavEPSS 1.2%via OSV
CVE-2024-29888Medium· 4.2
2y ago

Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method

Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method

▾ Sunlitsaleor · saleorEPSS 0.53%via OSV
CVE-2024-28233High· 8.1
2y ago

Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing

Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing

▾ Twilightjupyterhub · jupyterhubEPSS 0.33%via OSV
CVE-2024-2206High· 7.3
2y ago

gradio Server-Side Request Forgery vulnerability

gradio Server-Side Request Forgery vulnerability

▾ Twilightgradio · gradioEPSS 0.42%via OSV
CVE-2024-1313Medium· 6.5
2y ago

grafana: vulnerable to authorization bypass (CVE-2024-1313)

A vulnerability was found in Grafana. Due to an error in authorization logic, it is possible for an unprivileged user in a different organization other than the snapshot owner to perform unauthorized actions such as deleting it using a vie…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via CSAF
CVE-2024-1455Medium· 5.9
2y ago

LangChain's XMLOutputParser vulnerable to XML Entity Expansion

LangChain's XMLOutputParser vulnerable to XML Entity Expansion

▾ Sunlitlangchain-core · langchain-coreEPSS 0.76%via OSV
CVE-2024-29199Low· 3.7
2y ago

Unauthenticated views may expose information to anonymous users

Unauthenticated views may expose information to anonymous users

▾ Sunlitnautobot · nautobotEPSS 0.63%via OSV
CVE-2024-29735Medium· 5.3
2y ago

Apache Airflow Improper Preservation of Permissions vulnerability

Apache Airflow Improper Preservation of Permissions vulnerability

▾ Sunlitapache-airflow · apache-airflowEPSS 1.5%via OSV
CVE-2024-29189High· 7.4
2y ago

ansys-geometry-core OS Command Injection vulnerability

ansys-geometry-core OS Command Injection vulnerability

▾ Twilightansys-geometry-core · ansys-geometry-coreEPSS 0.34%via OSV
CVE-2024-1603High· 7.5
2y ago

PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file

PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file

▾ Twilightpaddlepaddle · paddlepaddleEPSS 0.56%via OSV
CVE-2024-29190High· 7.3
2y ago

SSRF Vulnerability on assetlinks_check(act_name, well_knowns)

SSRF Vulnerability on assetlinks_check(act_name, well_knowns)

▾ Twilightmobsfscan · mobsfscanEPSS 0.72%via OSV
CVE-2024-29019High· 8.1
2y ago

ESPHome vulnerable to Authentication bypass via Cross site request forgery

ESPHome vulnerable to Authentication bypass via Cross site request forgery

▾ Twilightesphome · esphomeEPSS 0.27%via OSV
CVE-2024-1394High· 7.5
2y ago

Memory leaks in code encrypting and verifying RSA payloads

Memory leaks in code encrypting and verifying RSA payloads

▾ Twilightgolang-fips · github.com/golang-fips/goEPSS 1.5%via OSV
CVE-2024-29032Medium· 5.3
2y ago

`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code

`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code

▾ Sunlitqiskit-ibm-runtime · qiskit-ibm-runtimeEPSS 0.37%via OSV
CVE-2024-29033High· 7.5
2y ago

GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace

GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace

▾ Twilightoauthenticator · oauthenticatorEPSS 0.59%via OSV
CVEs tagged “osv” — page 134 · VulnSea