Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2023-50447High· 8.1Arbitrary Code Execution in Pillow
Arbitrary Code Execution in Pillow
CVE-2024-22419High· 7.3concat built-in can corrupt memory in vyper
concat built-in can corrupt memory in vyper
CVE-2024-22424High· 8.3github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability
CVE-2024-22420Medium· 6.5JupyterLab vulnerable to SXSS in Markdown Preview
JupyterLab vulnerable to SXSS in Markdown Preview
CVE-2024-22421High· 7.6JupyterLab vulnerable to potential authentication and CSRF tokens leak
JupyterLab vulnerable to potential authentication and CSRF tokens leak
CVE-2024-0669High· 7.1Cross-Frame Scripting vulnerability has been found on Plone CMS
Cross-Frame Scripting vulnerability has been found on Plone CMS
CVE-2024-22415High· 7.3Unsecured endpoints in the jupyter-lsp server extension
Unsecured endpoints in the jupyter-lsp server extension
CVE-2023-6395Medium· 6.7Privilege escalation for users that can access mock configuration
Privilege escalation for users that can access mock configuration
CVE-2023-52289High· 7.5Path traversal in flaskcode
Path traversal in flaskcode
CVE-2023-52288High· 7.5Path traversal in flaskcode
Path traversal in flaskcode
CVE-2024-22199Critical· 9.3Django Template Engine Vulnerable to XSS
Django Template Engine Vulnerable to XSS
CVE-2024-22194Low· 2.2cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code
cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code
CVE-2024-22195Medium· 5.4Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
CVE-2024-22190High· 7.8Untrusted search path under some conditions on Windows allows arbitrary code execution
Untrusted search path under some conditions on Windows allows arbitrary code execution
CVE-2023-49569Critical· 9.8Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
CVE-2024-21669Critical· 9.9Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
CVE-2023-45139High· 7.5fonttools XML External Entity Injection (XXE) Vulnerability
fonttools XML External Entity Injection (XXE) Vulnerability
CVE-2024-21644High· 7.5PoCpyload Unauthenticated Flask Configuration Leakage vulnerability
pyload Unauthenticated Flask Configuration Leakage vulnerability
CVE-2024-21645Medium· 5.3PoCpyload Log Injection vulnerability
pyload Log Injection vulnerability
CVE-2023-30617Medium· 6.5Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster
Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster
CVE-2023-52323Medium· 5.3PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
CVE-2024-21642High· 7.5D-Tale server-side request forgery through Web uploads
D-Tale server-side request forgery through Web uploads
CVE-2023-46739Medium· 6.5CubeFS timing attack can leak user passwords
CubeFS timing attack can leak user passwords
CVE-2023-46740Medium· 6.5Insecure random string generator used for sensitive data
Insecure random string generator used for sensitive data
CVE-2023-38674Medium· 4.7PaddlePaddle floating point exception in paddle.nanmedian
PaddlePaddle floating point exception in paddle.nanmedian
CVE-2023-38676Medium· 4.7PaddlePaddle segfault in paddle.dot
PaddlePaddle segfault in paddle.dot
CVE-2023-52308Medium· 4.7PaddlePaddle floating point exception in paddle.amin
PaddlePaddle floating point exception in paddle.amin
CVE-2023-52305Medium· 4.7PaddlePaddle floating point exception in paddle.topk
PaddlePaddle floating point exception in paddle.topk
CVE-2023-52306Medium· 4.7PaddlePaddle floating point exception in paddle.lerp
PaddlePaddle floating point exception in paddle.lerp
CVE-2023-52311Critical· 9.6PaddlePaddle command injection in _wget_download
PaddlePaddle command injection in _wget_download