VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2023-5764Medium· 6.6
2y ago

Ansible template injection vulnerability

Ansible template injection vulnerability

▾ Sunlitansible-core · ansible-coreEPSS 0.54%via OSV
CVE-2023-50248Medium· 4.5
2y ago

Out of memory error when submitting the dataset form with a specially-crafted field

Out of memory error when submitting the dataset form with a specially-crafted field

▾ Sunlitckan · ckanEPSS 0.58%via OSV
CVE-2023-50423Critical· 9.1
2y ago

Improper Privilege Management in sap-xssec

Improper Privilege Management in sap-xssec

▾ Midnightsap-xssec · sap-xssecEPSS 1.1%via OSV
CVE-2023-49795Medium· 6.5
2y ago

Server-Side Request Forgery in mindsdb

Server-Side Request Forgery in mindsdb

▾ Sunlitmindsdb · mindsdbEPSS 0.42%via OSV
CVE-2023-35625Medium· 4.7
2y ago

Exposure of Sensitive Information in mltable

Exposure of Sensitive Information in mltable

▾ Sunlitmltable · mltableEPSS 0.71%via OSV
CVE-2023-48311Medium· 4.3
2y ago

DockerSpawner allows any image by default

DockerSpawner allows any image by default

▾ Sunlitdockerspawner · dockerspawnerEPSS 0.64%via OSV
CVE-2023-6458High· 7.1
2y ago

Mattermost Injection vulnerability

Mattermost Injection vulnerability

▾ Twilightmattermost · github.com/mattermost/mattermost-server/v6EPSS 0.64%via OSV
CVE-2023-6459Medium· 5.3
2y ago

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost-server/v6EPSS 0.53%via OSV
CVE-2023-26154Medium· 5.9
2y ago

pubnub Insufficient Entropy vulnerability

pubnub Insufficient Entropy vulnerability

▾ Sunlitpubnub · pubnubEPSS 0.96%via OSV
CVE-2023-49290Medium· 5.3
2y ago

lestrrat-go/jwx's malicious parameters in JWE can cause a DOS

lestrrat-go/jwx's malicious parameters in JWE can cause a DOS

▾ Sunlitlestrrat-go · github.com/lestrrat-go/jwxEPSS 0.73%via OSV
CVE-2023-49297Low· 3.3
2y ago

PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution

PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution

▾ Sunlitpydrive2 · pydrive2EPSS 0.51%via OSV
CVE-2023-49080Medium· 4.3
2y ago

jupyter-server errors include tracebacks with path information

jupyter-server errors include tracebacks with path information

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.84%via OSV
CVE-2023-47106Medium· 6.5
2y ago

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.63%via OSV
CVE-2023-47124Medium· 5.9
2y ago

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.79%via OSV
CVE-2023-47633High· 7.5
2y ago

Traefik docker container using 100% CPU

Traefik docker container using 100% CPU

▾ Twilighttraefik · github.com/traefik/traefik/v2EPSS 1.3%via OSV
CVE-2023-6180Medium· 5.3
2y ago

tokio-boring vulnerable to resource exhaustion via memory leak

tokio-boring vulnerable to resource exhaustion via memory leak

▾ Sunlittokio-boring · tokio-boringEPSS 0.62%via OSV
CVE-2023-43472High· 7.5PoC
2y ago

Information exposure in MLflow

Information exposure in MLflow

▾ Midnightmlflow · mlflowEPSS 37%via OSV
CVE-2023-49277Medium· 6.1
2y ago

Reflected XSS Vulnerability in dpaste

Reflected XSS Vulnerability in dpaste

▾ Sunlitdpaste · dpasteEPSS 0.52%via OSV
CVE-2023-49081High· 7.2
2y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker co…

▾ Twilightaiohttp · aiohttpEPSS 0.88%via NVD
CVE-2023-49097High· 8.1
2y ago

ZITADEL Account Takeover via Malicious Host Header Injection

ZITADEL Account Takeover via Malicious Host Header Injection

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.77%via OSV
CVE-2023-49082Medium· 5.3
2y ago

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker…

▾ Sunlitaiohttp · aiohttpEPSS 0.95%via NVD
CVE-2023-49083Medium· 5.9
2y ago

cryptography vulnerable to NULL-dereference when loading PKCS7 certificates

cryptography vulnerable to NULL-dereference when loading PKCS7 certificates

▾ Sunlitcryptography · cryptographyEPSS 0.98%via OSV
CVE-2023-48022Critical· 9.8PoC
2y ago

Ray has arbitrary code execution via jobs submission API

Ray has arbitrary code execution via jobs submission API

▾ Abyssalray · rayEPSS 84%via OSV
CVE-2023-42502Medium· 5.4
2y ago

Apache Superset Open Redirect vulnerability

Apache Superset Open Redirect vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 0.83%via OSV
CVE-2023-42505Medium· 4.3
2y ago

Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2023-40610High· 7.3
2y ago

Apache Superset - Elevation of Privilege

Apache Superset - Elevation of Privilege

▾ Twilightapache-superset · apache-supersetEPSS 1.3%via OSV
CVE-2023-42504Medium· 6.5
2y ago

Apache Superset Allocation of Resources Without Limits or Throttling vulnerability

Apache Superset Allocation of Resources Without Limits or Throttling vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVE-2023-6202Medium· 4.3
2y ago

Mattermost Improper Access Control vulnerability

Mattermost Improper Access Control vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.44%via OSV
CVE-2023-47168Medium· 4.3
2y ago

Mattermost Open Redirect vulnerability

Mattermost Open Redirect vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.40%via OSV
CVE-2023-48369Medium· 5.3
2y ago

Mattermost Uncontrolled Resource Consumption vulnerability

Mattermost Uncontrolled Resource Consumption vulnerability

▾ Sunlitmattermost · github.com/mattermost/mattermost/server/v8EPSS 0.63%via OSV
CVEs tagged “osv” — page 141 · VulnSea