Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2023-5764Medium· 6.6Ansible template injection vulnerability
Ansible template injection vulnerability
CVE-2023-50248Medium· 4.5Out of memory error when submitting the dataset form with a specially-crafted field
Out of memory error when submitting the dataset form with a specially-crafted field
CVE-2023-50423Critical· 9.1Improper Privilege Management in sap-xssec
Improper Privilege Management in sap-xssec
CVE-2023-49795Medium· 6.5Server-Side Request Forgery in mindsdb
Server-Side Request Forgery in mindsdb
CVE-2023-35625Medium· 4.7Exposure of Sensitive Information in mltable
Exposure of Sensitive Information in mltable
CVE-2023-48311Medium· 4.3DockerSpawner allows any image by default
DockerSpawner allows any image by default
CVE-2023-6458High· 7.1Mattermost Injection vulnerability
Mattermost Injection vulnerability
CVE-2023-6459Medium· 5.3Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-26154Medium· 5.9pubnub Insufficient Entropy vulnerability
pubnub Insufficient Entropy vulnerability
CVE-2023-49290Medium· 5.3lestrrat-go/jwx's malicious parameters in JWE can cause a DOS
lestrrat-go/jwx's malicious parameters in JWE can cause a DOS
CVE-2023-49297Low· 3.3PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution
PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution
CVE-2023-49080Medium· 4.3jupyter-server errors include tracebacks with path information
jupyter-server errors include tracebacks with path information
CVE-2023-47106Medium· 6.5Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
CVE-2023-47124Medium· 5.9Traefik vulnerable to potential DDoS via ACME HTTPChallenge
Traefik vulnerable to potential DDoS via ACME HTTPChallenge
CVE-2023-47633High· 7.5Traefik docker container using 100% CPU
Traefik docker container using 100% CPU
CVE-2023-6180Medium· 5.3tokio-boring vulnerable to resource exhaustion via memory leak
tokio-boring vulnerable to resource exhaustion via memory leak
CVE-2023-43472High· 7.5PoCInformation exposure in MLflow
Information exposure in MLflow
CVE-2023-49277Medium· 6.1Reflected XSS Vulnerability in dpaste
Reflected XSS Vulnerability in dpaste
CVE-2023-49081High· 7.2aiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker co…
CVE-2023-49097High· 8.1ZITADEL Account Takeover via Malicious Host Header Injection
ZITADEL Account Takeover via Malicious Host Header Injection
CVE-2023-49082Medium· 5.3aiohttp is an asynchronous HTTP client/server framework for asyncio and Python
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker…
CVE-2023-49083Medium· 5.9cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
CVE-2023-48022Critical· 9.8PoCRay has arbitrary code execution via jobs submission API
Ray has arbitrary code execution via jobs submission API
CVE-2023-42502Medium· 5.4Apache Superset Open Redirect vulnerability
Apache Superset Open Redirect vulnerability
CVE-2023-42505Medium· 4.3Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-40610High· 7.3Apache Superset - Elevation of Privilege
Apache Superset - Elevation of Privilege
CVE-2023-42504Medium· 6.5Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
CVE-2023-6202Medium· 4.3Mattermost Improper Access Control vulnerability
Mattermost Improper Access Control vulnerability
CVE-2023-47168Medium· 4.3Mattermost Open Redirect vulnerability
Mattermost Open Redirect vulnerability
CVE-2023-48369Medium· 5.3Mattermost Uncontrolled Resource Consumption vulnerability
Mattermost Uncontrolled Resource Consumption vulnerability