VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5670 CVEsRSS

CVE-2026-87817High· 8.8
2w ago

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a ma…

▾ Twilightgitpython_project · gitpythonEPSS 0.40%via NVD
CVE-2026-87819High· 7.5
2w ago

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containi…

▾ Twilightgitpython_project · gitpythonEPSS 0.52%via NVD
GHSA-57v5-wqx3-cgj4Medium· 5.8
2w ago

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAt…

SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelvia OSV
CVE-2026-72790Medium· 5.8
2w ago

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /ap…

SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via OSV
CVE-2026-12259Medium· 5.3
2w ago

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

▾ Sunlitnltk · nltkEPSS 0.14%via OSV
CVE-2026-78675High· 8.4⚖ disputed
2w ago

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables…

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

▾ Twilightgitpython · gitpythonEPSS 0.18%via OSV
CVE-2026-80206High
2w ago

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

▾ Twilightnltk · nltkEPSS 0.44%via OSV
CVE-2026-78681High
2w ago

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

▾ Twilightnltk · nltkEPSS 0.52%via OSV
CVE-2026-79676High
2w ago

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

▾ Twilightnltk · nltkEPSS 0.45%via OSV
CVE-2026-79657Critical
2w ago

NLTK: Allowlisted pickle loaders still permit code execution in current source

NLTK: Allowlisted pickle loaders still permit code execution in current source

▾ Midnightnltk · nltkEPSS 1.3%via OSV
CVE-2026-78683Critical
2w ago

NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

▾ Midnightnltk · nltkEPSS 0.51%via OSV
MAL-2026-16017Critical⚠ Exploited
3w ago

Malicious code in telegram-helper (PyPI)

Malicious code in telegram-helper (PyPI)

▾ Abyssaltelegram-helper · telegram-helpervia OSV
MAL-2026-16016Critical⚠ Exploited
3w ago

Malicious code in cv-train (PyPI)

Malicious code in cv-train (PyPI)

▾ Abyssalcv-train · cv-trainvia OSV
RUSTSEC-2026-0281None
3w ago

`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code

`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code

▾ Sunlitgreentic-setup · greentic-setupvia OSV
RUSTSEC-2026-0280None
3w ago

`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code

`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code

▾ Sunlitgreentic-setup-dev · greentic-setup-devvia OSV
CVE-2026-86257Medium· 5.4PoC⚖ disputed
3w ago

wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas

wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or ex…

▾ Twilightwger-project · wgerEPSS 0.28%via NVD
CVE-2026-86256Medium· 5.4PoC
3w ago

wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py)

wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the user-supplied 'next' GET param…

▾ Twilightwger-project · wgerEPSS 0.23%via NVD
CVE-2026-86255Medium· 6.5
3w ago

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endp…

▾ Sunlitwger · wgerEPSS 0.44%via NVD
MAL-2026-15938Critical⚠ Exploited
3w ago

Malicious code in dac-tools (PyPI)

Malicious code in dac-tools (PyPI)

▾ Abyssaldac-tools · dac-toolsvia OSV
MAL-2026-15937None
3w ago

Malicious code in minecraftmodes (PyPI)

Malicious code in minecraftmodes (PyPI)

▾ Sunlitminecraftmodes · minecraftmodesvia OSV
MAL-2026-15936None
3w ago

Malicious code in trongridew (PyPI)

Malicious code in trongridew (PyPI)

▾ Sunlittrongridew · trongridewvia OSV
MAL-2026-15935Critical⚠ Exploited
3w ago

Malicious code in proxycer (PyPI)

Malicious code in proxycer (PyPI)

▾ Abyssalproxycer · proxycervia OSV
MAL-2026-15934None
3w ago

Malicious code in dbt-sa-cli (PyPI)

Malicious code in dbt-sa-cli (PyPI)

▾ Sunlitdbt-sa-cli · dbt-sa-clivia OSV
RUSTSEC-2026-0292None
3w ago

Double free / use-after-free in `Chunk` and `InlineArray` removal methods when an element's `Drop` panics

Double free / use-after-free in `Chunk` and `InlineArray` removal methods when an element's `Drop` panics

▾ Sunlitimbl-sized-chunks · imbl-sized-chunksvia OSV
MAL-2026-16044Critical⚠ Exploited
3w ago

Malicious code in tsshare (PyPI)

Malicious code in tsshare (PyPI)

▾ Abyssaltsshare · tssharevia OSV
CVE-2026-63464High· 7.7PoC
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/w…

▾ Midnightforgekeep · nebula-meshEPSS 0.46%via NVD
MAL-2026-15933None
3w ago

Malicious code in houdus (PyPI)

Malicious code in houdus (PyPI)

▾ Sunlithoudus · houdusvia OSV
MAL-2026-15932None
3w ago

Malicious code in chartkit-core (PyPI)

Malicious code in chartkit-core (PyPI)

▾ Sunlitchartkit-core · chartkit-corevia OSV
CVE-2026-72799Medium· 5.8
3w ago

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via OSV
CVE-2026-72794High· 8.6
3w ago

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.42%via OSV
CVEs tagged “osv” — page 14 · VulnSea