VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2023-50447High· 8.1
2y ago

Arbitrary Code Execution in Pillow

Arbitrary Code Execution in Pillow

▾ Twilightpillow · pillowEPSS 1.7%via OSV
CVE-2024-22419High· 7.3
2y ago

concat built-in can corrupt memory in vyper

concat built-in can corrupt memory in vyper

▾ Twilightvyper · vyperEPSS 0.77%via OSV
CVE-2024-22424High· 8.3
2y ago

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability

▾ Twilightargoproj · github.com/argoproj/argo-cdEPSS 0.48%via OSV
CVE-2024-22420Medium· 6.5
2y ago

JupyterLab vulnerable to SXSS in Markdown Preview

JupyterLab vulnerable to SXSS in Markdown Preview

▾ Sunlitjupyterlab · jupyterlabEPSS 0.57%via OSV
CVE-2024-22421High· 7.6
2y ago

JupyterLab vulnerable to potential authentication and CSRF tokens leak

JupyterLab vulnerable to potential authentication and CSRF tokens leak

▾ Twilightjupyterlab · jupyterlabEPSS 0.67%via OSV
CVE-2024-0669High· 7.1
2y ago

Cross-Frame Scripting vulnerability has been found on Plone CMS

Cross-Frame Scripting vulnerability has been found on Plone CMS

▾ Twilightplone · ploneEPSS 0.29%via OSV
CVE-2024-22415High· 7.3
2y ago

Unsecured endpoints in the jupyter-lsp server extension

Unsecured endpoints in the jupyter-lsp server extension

▾ Twilightjupyter-lsp · jupyter-lspEPSS 0.49%via OSV
CVE-2023-6395Medium· 6.7
2y ago

Privilege escalation for users that can access mock configuration

Privilege escalation for users that can access mock configuration

▾ Sunlittemplated-dictionary · templated-dictionaryEPSS 1.6%via OSV
CVE-2023-52289High· 7.5
2y ago

Path traversal in flaskcode

Path traversal in flaskcode

▾ Twilightflaskcode · flaskcodeEPSS 0.72%via OSV
CVE-2023-52288High· 7.5
2y ago

Path traversal in flaskcode

Path traversal in flaskcode

▾ Twilightflaskcode · flaskcodeEPSS 0.80%via OSV
CVE-2024-22199Critical· 9.3
2y ago

Django Template Engine Vulnerable to XSS

Django Template Engine Vulnerable to XSS

▾ Midnightgofiber · github.com/gofiber/template/django/v3EPSS 0.48%via OSV
CVE-2024-22194Low· 2.2
2y ago

cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code

cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code

▾ Sunlitcdo-local-uuid · cdo-local-uuidEPSS 0.41%via OSV
CVE-2024-22195Medium· 5.4
2y ago

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

▾ Sunlitjinja2 · jinja2EPSS 0.89%via OSV
CVE-2024-22190High· 7.8
2y ago

Untrusted search path under some conditions on Windows allows arbitrary code execution

Untrusted search path under some conditions on Windows allows arbitrary code execution

▾ Twilightgitpython · gitpythonEPSS 0.32%via OSV
CVE-2023-49569Critical· 9.8
2y ago

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

▾ Midnightgo-git · github.com/go-git/go-git/v5EPSS 1.5%via OSV
CVE-2024-21669Critical· 9.9
2y ago

Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC

Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC

▾ Midnightaries-cloudagent · aries-cloudagentEPSS 0.63%via OSV
CVE-2023-45139High· 7.5
2y ago

fonttools XML External Entity Injection (XXE) Vulnerability

fonttools XML External Entity Injection (XXE) Vulnerability

▾ Twilightfonttools · fonttoolsEPSS 1.2%via OSV
CVE-2024-21644High· 7.5PoC
2y ago

pyload Unauthenticated Flask Configuration Leakage vulnerability

pyload Unauthenticated Flask Configuration Leakage vulnerability

▾ Midnightpyload-ng · pyload-ngEPSS 42%via OSV
CVE-2024-21645Medium· 5.3PoC
2y ago

pyload Log Injection vulnerability

pyload Log Injection vulnerability

▾ Twilightpyload-ng · pyload-ngEPSS 25%via OSV
CVE-2023-30617Medium· 6.5
2y ago

Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster

Kruise allows leveraging the kruise-daemon pod to list all secrets in the entire cluster

▾ Sunlitopenkruise · github.com/openkruise/kruiseEPSS 0.49%via OSV
CVE-2023-52323Medium· 5.3
2y ago

PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption

PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption

▾ Sunlitpycryptodomex · pycryptodomexEPSS 0.62%via OSV
CVE-2024-21642High· 7.5
2y ago

D-Tale server-side request forgery through Web uploads

D-Tale server-side request forgery through Web uploads

▾ Twilightdtale · dtaleEPSS 0.71%via OSV
CVE-2023-46739Medium· 6.5
2y ago

CubeFS timing attack can leak user passwords

CubeFS timing attack can leak user passwords

▾ Sunlitcubefs · github.com/cubefs/cubefsEPSS 0.35%via OSV
CVE-2023-46740Medium· 6.5
2y ago

Insecure random string generator used for sensitive data

Insecure random string generator used for sensitive data

▾ Sunlitcubefs · github.com/cubefs/cubefsEPSS 0.44%via OSV
CVE-2023-38674Medium· 4.7
2y ago

PaddlePaddle floating point exception in paddle.nanmedian

PaddlePaddle floating point exception in paddle.nanmedian

▾ Sunlitpaddlepaddle · paddlepaddleEPSS 0.49%via OSV
CVE-2023-38676Medium· 4.7
2y ago

PaddlePaddle segfault in paddle.dot

PaddlePaddle segfault in paddle.dot

▾ Sunlitpaddlepaddle · paddlepaddleEPSS 0.49%via OSV
CVE-2023-52308Medium· 4.7
2y ago

PaddlePaddle floating point exception in paddle.amin

PaddlePaddle floating point exception in paddle.amin

▾ Sunlitpaddlepaddle · paddlepaddleEPSS 0.49%via OSV
CVE-2023-52305Medium· 4.7
2y ago

PaddlePaddle floating point exception in paddle.topk

PaddlePaddle floating point exception in paddle.topk

▾ Sunlitpaddlepaddle · paddlepaddleEPSS 0.49%via OSV
CVE-2023-52306Medium· 4.7
2y ago

PaddlePaddle floating point exception in paddle.lerp

PaddlePaddle floating point exception in paddle.lerp

▾ Sunlitpaddlepaddle · paddlepaddleEPSS 0.49%via OSV
CVE-2023-52311Critical· 9.6
2y ago

PaddlePaddle command injection in _wget_download

PaddlePaddle command injection in _wget_download

▾ Midnightpaddlepaddle · paddlepaddleEPSS 1.2%via OSV
CVEs tagged “osv” — page 139 · VulnSea