Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2024-1141Medium· 5.5glance-store logs s3 access keys
glance-store logs s3 access keys
CVE-2020-27534Medium· 5.3Path Traversal in Moby builder
Path Traversal in Moby builder
CVE-2024-23652Critical· 10.0PoCBuildKit vulnerable to possible host system access from mount stub cleaner
BuildKit vulnerable to possible host system access from mount stub cleaner
CVE-2019-19499Medium· 6.5Grafana Arbitrary File Read
Grafana Arbitrary File Read
CVE-2020-15114High· 7.7Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
CVE-2023-47116Medium· 5.3Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
CVE-2024-23637Medium· 4.2OctoPrint Unverified Password Change via Access Control Settings
OctoPrint Unverified Password Change via Access Control Settings
CVE-2021-21284Medium· 6.8moby Access to remapped root allows privilege escalation to real root
moby Access to remapped root allows privilege escalation to real root
CVE-2021-21334Medium· 6.3containerd environment variable leak
containerd environment variable leak
CVE-2021-21285Medium· 6.5moby docker daemon crash during image pull of malicious image
moby docker daemon crash during image pull of malicious image
CVE-2021-41091Medium· 5.9PoCMoby (Docker Engine) Insufficiently restricted permissions on data directory
Moby (Docker Engine) Insufficiently restricted permissions on data directory
CVE-2024-24567Medium· 4.8Vyper's raw_call `value=` kwargs not disabled for static and delegate calls
Vyper's raw_call `value=` kwargs not disabled for static and delegate calls
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability
vantage6 remote code execution vulnerability
CVE-2024-22193Low· 3.5vantage6 may create unencrypted tasks in encrypted collaboration
vantage6 may create unencrypted tasks in encrypted collaboration
CVE-2021-29511Medium· 6.5Memory over-allocation in evm crate
Memory over-allocation in evm crate
CVE-2024-21671Low· 3.7vantage6 vulnerable to username timing attack
vantage6 vulnerable to username timing attack
CVE-2024-21653Medium· 6.5vantage6 has insecure SSH configuration for node and server containers
vantage6 has insecure SSH configuration for node and server containers
CVE-2024-23334Medium· 5.9PoCaiohttp is vulnerable to directory traversal
aiohttp is vulnerable to directory traversal
CVE-2024-0960Medium· 5.0ai-flow Deserialization of Untrusted Data vulnerability
ai-flow Deserialization of Untrusted Data vulnerability
CVE-2024-0727Medium· 5.5Null pointer dereference in PKCS12 parsing
Null pointer dereference in PKCS12 parsing
CVE-2023-47115High· 7.1PoCCross-site Scripting Vulnerability on Avatar Upload
Cross-site Scripting Vulnerability on Avatar Upload
CVE-2024-23633Medium· 4.7Cross-site Scripting Vulnerability on Data Import
Cross-site Scripting Vulnerability on Data Import
CVE-2024-23345High· 7.1XSS potential in rendered Markdown fields (comments, description, notes, etc.)
XSS potential in rendered Markdown fields (comments, description, notes, etc.)
CVE-2024-23329Low· 3.7changedetection.io API endpoint is not secured with API token
changedetection.io API endpoint is not secured with API token
CVE-2024-23341Medium· 6.1html injection vulnerability in the `tuitse_html` function.
html injection vulnerability in the `tuitse_html` function.
CVE-2024-23342High· 7.4Minerva timing attack on P-256 in python-ecdsa
Minerva timing attack on P-256 in python-ecdsa
CVE-2024-0521Critical· 9.3Code Injection in paddlepaddle
Code Injection in paddlepaddle
CVE-2024-23332Medium· 4.0Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from co…
Go package github.com/notaryproject/notation configured with permissive trust policies potentially susceptible to rollback attack from compromised registry
CVE-2024-22416Critical· 9.6PoCCross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
CVE-2023-50447High· 8.1Arbitrary Code Execution in Pillow
Arbitrary Code Execution in Pillow