VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2024-27318High· 7.5
2y ago

Onnx Directory Traversal vulnerability

Onnx Directory Traversal vulnerability

▾ Twilightonnx · onnxEPSS 1.2%via OSV
CVE-2024-27319Medium· 4.4
2y ago

Onnx Out-of-bounds Read vulnerability

Onnx Out-of-bounds Read vulnerability

▾ Sunlitonnx · onnxEPSS 0.59%via OSV
CVE-2024-1729Medium· 5.9
2y ago

Gradio apps vulnerable to timing attacks to guess password

Gradio apps vulnerable to timing attacks to guess password

▾ Sunlitgradio · gradioEPSS 0.50%via OSV
CVE-2024-26151High· 8.2
2y ago

Potentially untrusted input is rendered as HTML in final output

Potentially untrusted input is rendered as HTML in final output

▾ Twilightmjml · mjmlEPSS 0.62%via OSV
CVE-2024-26130High· 7.5
2y ago

cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private …

cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override

▾ Twilightcryptography · cryptographyEPSS 0.83%via OSV
CVE-2024-25630Medium· 6.1
2y ago

Unencrypted ingress/health traffic when using Wireguard transparent encryption

Unencrypted ingress/health traffic when using Wireguard transparent encryption

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.18%via OSV
CVE-2024-3572High· 7.5
2y ago

Scrapy decompression bomb vulnerability

Scrapy decompression bomb vulnerability

▾ Twilightscrapy · scrapyEPSS 0.81%via OSV
CVE-2024-3574High· 7.5
2y ago

Scrapy authorization header leakage on cross-domain redirect

Scrapy authorization header leakage on cross-domain redirect

▾ Twilightscrapy · scrapyEPSS 0.65%via OSV
CVE-2024-1485High· 8.0
2y ago

registry-support: decompress can delete files outside scope via relative paths

registry-support: decompress can delete files outside scope via relative paths

▾ Twilightdevfile · github.com/devfile/registry-support/registry-libraryEPSS 0.94%via OSV
CVE-2023-6152Medium· 5.4
2y ago

Email Validation Bypass And Preventing Sign Up From Email's Owner

Email Validation Bypass And Preventing Sign Up From Email's Owner

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.4%via OSV
CVE-2024-24762High· 7.5
2y ago

python-multipart vulnerable to Content-Type Header ReDoS

python-multipart vulnerable to Content-Type Header ReDoS

▾ Twilightpython-multipart · python-multipartEPSS 1.5%via OSV
CVE-2024-1402Medium· 4.3
2y ago

Mattermost vulnerable to denial of service via large number of emoji reactions

Mattermost vulnerable to denial of service via large number of emoji reactions

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.52%via OSV
CVE-2024-21624Medium· 5.7
2y ago

NoneBot Potential Information Leak in User-Constructed Message Templates

NoneBot Potential Information Leak in User-Constructed Message Templates

▾ Sunlitnonebot2 · nonebot2EPSS 0.49%via OSV
CVE-2024-24825Critical· 9.1
2y ago

DIRAC's TokenManager does not check permissions on cached tokens

DIRAC's TokenManager does not check permissions on cached tokens

▾ Midnightdirac · diracEPSS 0.53%via OSV
CVE-2023-32192High· 8.3
2y ago

Rancher API Server Cross-site Scripting Vulnerability

Rancher API Server Cross-site Scripting Vulnerability

▾ Twilightrancher · github.com/rancher/apiserverEPSS 0.37%via OSV
CVE-2024-23448Medium· 5.7
2y ago

APM Server vulnerable to Insertion of Sensitive Information into Log File

APM Server vulnerable to Insertion of Sensitive Information into Log File

▾ Sunlitelastic · github.com/elastic/apm-serverEPSS 0.67%via OSV
CVE-2024-1314High· 8.6
2y ago

Kinto Attachment's attachments can be replaced on read-only records

Kinto Attachment's attachments can be replaced on read-only records

▾ Twilightkinto-attachment · kinto-attachmentvia OSV
CVE-2024-24811Critical· 9.8
2y ago

SQLAlchemyDA unauthenticated arbitrary SQL query execution

SQLAlchemyDA unauthenticated arbitrary SQL query execution

▾ Midnightproducts-sqlalchemyda · products-sqlalchemydaEPSS 0.89%via OSV
CVE-2024-24563Critical· 9.8
2y ago

Vyper negative array index bounds checks

Vyper negative array index bounds checks

▾ Midnightvyper · vyperEPSS 1.5%via OSV
CVE-2024-24591High· 8.8
2y ago

Allegro AI ClearML path traversal vulnerability

Allegro AI ClearML path traversal vulnerability

▾ Twilightclearml · clearmlEPSS 0.80%via OSV
CVE-2024-24595Medium· 6.0
2y ago

Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance

Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance

▾ Sunlitclearml · clearmlEPSS 0.26%via OSV
CVE-2024-24590High· 8.8PoC
2y ago

Allegro AI ClearML vulnerable to deserialization of untrusted data

Allegro AI ClearML vulnerable to deserialization of untrusted data

▾ Midnightclearml · clearmlEPSS 2.5%via OSV
CVE-2024-24559Low· 3.7
2y ago

Vyper sha3 codegen bug

Vyper sha3 codegen bug

▾ Sunlitvyper · vyperEPSS 0.26%via OSV
CVE-2024-24808Medium· 6.1
2y ago

pyLoad open redirect vulnerability due to improper validation of the is_safe_url function

pyLoad open redirect vulnerability due to improper validation of the is_safe_url function

▾ Sunlitpyload-ng · pyload-ngEPSS 0.55%via OSV
CVE-2023-50781High· 7.5
2y ago

A flaw was found in m2crypto

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

▾ Twilightredhat · update_infrastructureEPSS 1.1%via NVD
CVE-2023-50782High· 7.5
2y ago

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

▾ Twilightcryptography · cryptographyEPSS 1.1%via OSV
GHSA-5x4g-q5rc-36jpLow
2y ago

Etcd pkg Insecure ciphers are allowed by default

Etcd pkg Insecure ciphers are allowed by default

▾ Sunlitetcd · go.etcd.io/etcd/client/pkg/v3via OSV
CVE-2024-24560Low· 3.7
2y ago

Vyper's external calls can overflow return data to return input buffer

Vyper's external calls can overflow return data to return input buffer

▾ Sunlitvyper · vyperEPSS 0.53%via OSV
CVE-2024-21485Medium· 6.5PoC
2y ago

Dash apps vulnerable to Cross-site Scripting

Dash apps vulnerable to Cross-site Scripting

▾ Twilightdash-core-components · dash-core-componentsEPSS 1.5%via OSV
CVE-2024-24561Critical· 9.8
2y ago

Vyper's bounds check on built-in `slice()` function can be overflowed

Vyper's bounds check on built-in `slice()` function can be overflowed

▾ Midnightvyper · vyperEPSS 0.90%via OSV
CVEs tagged “osv” — page 137 · VulnSea