Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2024-27304High· 8.1PoCpgx: SQL Injection via Protocol Message Size Overflow (CVE-2024-27304)
pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be…
CVE-2024-28110High· 7.5Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials
Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials
CVE-2024-27288Medium· 6.31Panel open source panel project has an unauthorized vulnerability.
1Panel open source panel project has an unauthorized vulnerability.
CVE-2024-22889Medium· 5.5PoCPhone information disclosure vulnerability
Phone information disclosure vulnerability
CVE-2024-28102Medium· 6.8JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
CVE-2024-27758High· 8.5RPyC's missing security check results in code execution when using numpy.array on the server-side.
RPyC's missing security check results in code execution when using numpy.array on the server-side.
CVE-2024-27287Medium· 6.5esphome vulnerable to stored Cross-site Scripting in edit configuration file API
esphome vulnerable to stored Cross-site Scripting in edit configuration file API
GHSA-3qwc-47jf-5rf7Mediumeth-abi is vulnerable to recursive DoS
eth-abi is vulnerable to recursive DoS
CVE-2024-27918High· 8.2Coder's OIDC authentication allows email with partially matching domain to register
Coder's OIDC authentication allows email with partially matching domain to register
CVE-2024-27081High· 7.2ESPHome vulnerable to remote code execution via arbitrary file write
ESPHome vulnerable to remote code execution via arbitrary file write
CVE-2023-50658Medium· 5.3jose2go vulnerable to denial of service via large p2c value
jose2go vulnerable to denial of service via large p2c value
CVE-2024-1949Low· 2.6Mattermost race condition
Mattermost race condition
CVE-2024-1952Low· 3.1Mattermost incorrectly allows access individual posts
Mattermost incorrectly allows access individual posts
CVE-2024-23493Medium· 4.3Mattermost leaks details of AD/LDAP groups of a teams
Mattermost leaks details of AD/LDAP groups of a teams
CVE-2024-24988Medium· 4.3Mattermost denial of service through long emoji value
Mattermost denial of service through long emoji value
CVE-2024-27290Medium· 6.1Docassemble HTML and javascript injection
Docassemble HTML and javascript injection
CVE-2024-27292High· 7.5PoCDocassemble unauthorized access through URL manipulation
Docassemble unauthorized access through URL manipulation
CVE-2024-27291Medium· 6.1Docassemble open redirect
Docassemble open redirect
CVE-2024-25128Critical· 9.1Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID
Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID
CVE-2024-24779Medium· 5.0Apache Superset: Improper data authorization when creating a new dataset
Apache Superset: Improper data authorization when creating a new dataset
CVE-2024-25169MediumPoCMezzanine allows attackers to bypass access control mechanisms
Mezzanine allows attackers to bypass access control mechanisms
CVE-2024-24772Medium· 4.3Apache Superset: Improper Neutralization of custom SQL on embedded context
Apache Superset: Improper Neutralization of custom SQL on embedded context
CVE-2024-27315Medium· 4.3Apache Superset: Improper error handling on alerts
Apache Superset: Improper error handling on alerts
CVE-2024-27083Medium· 4.3Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)
Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)
CVE-2024-24773Medium· 4.9Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
CVE-2024-26016Medium· 4.3Apache Superset: Improper authorization validation on dashboards and charts import
Apache Superset: Improper authorization validation on dashboards and charts import
CVE-2024-25170MediumPoCMezzanine allows attackers to bypass access controls via manipulating the Host header
Mezzanine allows attackers to bypass access controls via manipulating the Host header
CVE-2024-25723Medium· 6.5PoCZenML Server Remote Privilege Escalation Vulnerability
ZenML Server Remote Privilege Escalation Vulnerability
CVE-2024-27454High· 7.5orjson does not limit recursion for deeply nested JSON documents
orjson does not limit recursion for deeply nested JSON documents
CVE-2024-0243Low· 3.7langchain Server-Side Request Forgery vulnerability
langchain Server-Side Request Forgery vulnerability