VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2024-27304High· 8.1PoC
2y ago

pgx: SQL Injection via Protocol Message Size Overflow (CVE-2024-27304)

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be…

▾ MidnightRed Hat · RHACS 4.3 for RHEL 8EPSS 1.1%via CSAF
CVE-2024-28110High· 7.5
2y ago

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

▾ Twilightcloudevents · github.com/cloudevents/sdk-go/v2EPSS 0.66%via OSV
CVE-2024-27288Medium· 6.3
2y ago

1Panel open source panel project has an unauthorized vulnerability.

1Panel open source panel project has an unauthorized vulnerability.

▾ Sunlit1Panel-dev · github.com/1Panel-dev/1PanelEPSS 0.47%via OSV
CVE-2024-22889Medium· 5.5PoC
2y ago

Phone information disclosure vulnerability

Phone information disclosure vulnerability

▾ Twilightplone · ploneEPSS 0.70%via OSV
CVE-2024-28102Medium· 6.8
2y ago

JWCrypto vulnerable to JWT bomb Attack in `deserialize` function

JWCrypto vulnerable to JWT bomb Attack in `deserialize` function

▾ Sunlitjwcrypto · jwcryptoEPSS 0.98%via OSV
CVE-2024-27758High· 8.5
2y ago

RPyC's missing security check results in code execution when using numpy.array on the server-side.

RPyC's missing security check results in code execution when using numpy.array on the server-side.

▾ Twilightrpyc · rpycEPSS 0.51%via OSV
CVE-2024-27287Medium· 6.5
2y ago

esphome vulnerable to stored Cross-site Scripting in edit configuration file API

esphome vulnerable to stored Cross-site Scripting in edit configuration file API

▾ Sunlitesphome · esphomeEPSS 0.68%via OSV
GHSA-3qwc-47jf-5rf7Medium
2y ago

eth-abi is vulnerable to recursive DoS

eth-abi is vulnerable to recursive DoS

▾ Sunliteth-abi · eth-abivia OSV
CVE-2024-27918High· 8.2
2y ago

Coder's OIDC authentication allows email with partially matching domain to register

Coder's OIDC authentication allows email with partially matching domain to register

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.97%via OSV
CVE-2024-27081High· 7.2
2y ago

ESPHome vulnerable to remote code execution via arbitrary file write

ESPHome vulnerable to remote code execution via arbitrary file write

▾ Twilightesphome · esphomeEPSS 1.5%via OSV
CVE-2023-50658Medium· 5.3
2y ago

jose2go vulnerable to denial of service via large p2c value

jose2go vulnerable to denial of service via large p2c value

▾ Sunlitdvsekhvalnov · github.com/dvsekhvalnov/jose2goEPSS 0.82%via OSV
CVE-2024-1949Low· 2.6
2y ago

Mattermost race condition

Mattermost race condition

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.27%via OSV
CVE-2024-1952Low· 3.1
2y ago

Mattermost incorrectly allows access individual posts

Mattermost incorrectly allows access individual posts

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.37%via OSV
CVE-2024-23493Medium· 4.3
2y ago

Mattermost leaks details of AD/LDAP groups of a teams

Mattermost leaks details of AD/LDAP groups of a teams

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.39%via OSV
CVE-2024-24988Medium· 4.3
2y ago

Mattermost denial of service through long emoji value

Mattermost denial of service through long emoji value

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.68%via OSV
CVE-2024-27290Medium· 6.1
2y ago

Docassemble HTML and javascript injection

Docassemble HTML and javascript injection

▾ Sunlitdocassemble-webapp · docassemble-webappEPSS 0.43%via OSV
CVE-2024-27292High· 7.5PoC
2y ago

Docassemble unauthorized access through URL manipulation

Docassemble unauthorized access through URL manipulation

▾ Midnightdocassemble-webapp · docassemble-webappEPSS 69%via OSV
CVE-2024-27291Medium· 6.1
2y ago

Docassemble open redirect

Docassemble open redirect

▾ Sunlitdocassemble-webapp · docassemble-webappEPSS 0.41%via OSV
CVE-2024-25128Critical· 9.1
2y ago

Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID

Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID

▾ Midnightflask-appbuilder · flask-appbuilderEPSS 0.86%via OSV
CVE-2024-24779Medium· 5.0
2y ago

Apache Superset: Improper data authorization when creating a new dataset

Apache Superset: Improper data authorization when creating a new dataset

▾ Sunlitapache-superset · apache-supersetEPSS 0.73%via OSV
CVE-2024-25169MediumPoC
2y ago

Mezzanine allows attackers to bypass access control mechanisms

Mezzanine allows attackers to bypass access control mechanisms

▾ Twilightmezzanine · mezzanineEPSS 1.1%via OSV
CVE-2024-24772Medium· 4.3
2y ago

Apache Superset: Improper Neutralization of custom SQL on embedded context

Apache Superset: Improper Neutralization of custom SQL on embedded context

▾ Sunlitapache-superset · apache-supersetEPSS 0.95%via OSV
CVE-2024-27315Medium· 4.3
2y ago

Apache Superset: Improper error handling on alerts

Apache Superset: Improper error handling on alerts

▾ Sunlitapache-superset · apache-supersetEPSS 0.98%via OSV
CVE-2024-27083Medium· 4.3
2y ago

Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)

Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)

▾ Sunlitflask-appbuilder · flask-appbuilderEPSS 0.57%via OSV
CVE-2024-24773Medium· 4.9
2y ago

Apache Superset: Improper validation of SQL statements allows for unauthorized access to data

Apache Superset: Improper validation of SQL statements allows for unauthorized access to data

▾ Sunlitapache-superset · apache-supersetEPSS 0.78%via OSV
CVE-2024-26016Medium· 4.3
2y ago

Apache Superset: Improper authorization validation on dashboards and charts import

Apache Superset: Improper authorization validation on dashboards and charts import

▾ Sunlitapache-superset · apache-supersetEPSS 0.87%via OSV
CVE-2024-25170MediumPoC
2y ago

Mezzanine allows attackers to bypass access controls via manipulating the Host header

Mezzanine allows attackers to bypass access controls via manipulating the Host header

▾ Twilightmezzanine · mezzanineEPSS 0.88%via OSV
CVE-2024-25723Medium· 6.5PoC
2y ago

ZenML Server Remote Privilege Escalation Vulnerability

ZenML Server Remote Privilege Escalation Vulnerability

▾ Twilightzenml · zenmlEPSS 71%via OSV
CVE-2024-27454High· 7.5
2y ago

orjson does not limit recursion for deeply nested JSON documents

orjson does not limit recursion for deeply nested JSON documents

▾ Twilightorjson · orjsonEPSS 1.2%via OSV
CVE-2024-0243Low· 3.7
2y ago

langchain Server-Side Request Forgery vulnerability

langchain Server-Side Request Forgery vulnerability

▾ Sunlitlangchain · langchainEPSS 0.52%via OSV
CVEs tagged “osv” — page 136 · VulnSea