Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2024-27318High· 7.5Onnx Directory Traversal vulnerability
Onnx Directory Traversal vulnerability
CVE-2024-27319Medium· 4.4Onnx Out-of-bounds Read vulnerability
Onnx Out-of-bounds Read vulnerability
CVE-2024-1729Medium· 5.9Gradio apps vulnerable to timing attacks to guess password
Gradio apps vulnerable to timing attacks to guess password
CVE-2024-26151High· 8.2Potentially untrusted input is rendered as HTML in final output
Potentially untrusted input is rendered as HTML in final output
CVE-2024-26130High· 7.5cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private …
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
CVE-2024-25630Medium· 6.1Unencrypted ingress/health traffic when using Wireguard transparent encryption
Unencrypted ingress/health traffic when using Wireguard transparent encryption
CVE-2024-3572High· 7.5Scrapy decompression bomb vulnerability
Scrapy decompression bomb vulnerability
CVE-2024-3574High· 7.5Scrapy authorization header leakage on cross-domain redirect
Scrapy authorization header leakage on cross-domain redirect
CVE-2024-1485High· 8.0registry-support: decompress can delete files outside scope via relative paths
registry-support: decompress can delete files outside scope via relative paths
CVE-2023-6152Medium· 5.4Email Validation Bypass And Preventing Sign Up From Email's Owner
Email Validation Bypass And Preventing Sign Up From Email's Owner
CVE-2024-24762High· 7.5python-multipart vulnerable to Content-Type Header ReDoS
python-multipart vulnerable to Content-Type Header ReDoS
CVE-2024-1402Medium· 4.3Mattermost vulnerable to denial of service via large number of emoji reactions
Mattermost vulnerable to denial of service via large number of emoji reactions
CVE-2024-21624Medium· 5.7NoneBot Potential Information Leak in User-Constructed Message Templates
NoneBot Potential Information Leak in User-Constructed Message Templates
CVE-2024-24825Critical· 9.1DIRAC's TokenManager does not check permissions on cached tokens
DIRAC's TokenManager does not check permissions on cached tokens
CVE-2023-32192High· 8.3Rancher API Server Cross-site Scripting Vulnerability
Rancher API Server Cross-site Scripting Vulnerability
CVE-2024-23448Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
APM Server vulnerable to Insertion of Sensitive Information into Log File
CVE-2024-1314High· 8.6Kinto Attachment's attachments can be replaced on read-only records
Kinto Attachment's attachments can be replaced on read-only records
CVE-2024-24811Critical· 9.8SQLAlchemyDA unauthenticated arbitrary SQL query execution
SQLAlchemyDA unauthenticated arbitrary SQL query execution
CVE-2024-24563Critical· 9.8Vyper negative array index bounds checks
Vyper negative array index bounds checks
CVE-2024-24591High· 8.8Allegro AI ClearML path traversal vulnerability
Allegro AI ClearML path traversal vulnerability
CVE-2024-24595Medium· 6.0Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance
Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance
CVE-2024-24590High· 8.8PoCAllegro AI ClearML vulnerable to deserialization of untrusted data
Allegro AI ClearML vulnerable to deserialization of untrusted data
CVE-2024-24559Low· 3.7Vyper sha3 codegen bug
Vyper sha3 codegen bug
CVE-2024-24808Medium· 6.1pyLoad open redirect vulnerability due to improper validation of the is_safe_url function
pyLoad open redirect vulnerability due to improper validation of the is_safe_url function
CVE-2023-50781High· 7.5A flaw was found in m2crypto
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
CVE-2023-50782High· 7.5Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
GHSA-5x4g-q5rc-36jpLowEtcd pkg Insecure ciphers are allowed by default
Etcd pkg Insecure ciphers are allowed by default
CVE-2024-24560Low· 3.7Vyper's external calls can overflow return data to return input buffer
Vyper's external calls can overflow return data to return input buffer
CVE-2024-21485Medium· 6.5PoCDash apps vulnerable to Cross-site Scripting
Dash apps vulnerable to Cross-site Scripting
CVE-2024-24561Critical· 9.8Vyper's bounds check on built-in `slice()` function can be overflowed
Vyper's bounds check on built-in `slice()` function can be overflowed