Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
GHSA-pjjw-qhg8-p2p9Mediumaiohttp has vulnerable dependency that is vulnerable to request smuggling
aiohttp has vulnerable dependency that is vulnerable to request smuggling
CVE-2023-43701Medium· 4.3Apache Superset Cross-site Scripting vulnerability
Apache Superset Cross-site Scripting vulnerability
CVE-2023-42501Medium· 4.3Apache Superset has Incorrect Default Permissions
Apache Superset has Incorrect Default Permissions
CVE-2023-49092Medium· 5.9Marvin Attack: potential key recovery through timing sidechannels
Marvin Attack: potential key recovery through timing sidechannels
GHSA-2c7c-3mj9-8fqhMediumDecryption of malicious PBES2 JWE objects can consume unbounded system resources
Decryption of malicious PBES2 JWE objects can consume unbounded system resources
CVE-2023-48699High· 8.4Eval Injection in fastbots
Eval Injection in fastbots
CVE-2023-48700Medium· 5.7Clear Text Credentials Exposed via Onboarding Task
Clear Text Credentials Exposed via Onboarding Task
CVE-2023-48299Medium· 5.3TorchServe ZipSlip
TorchServe ZipSlip
CVE-2023-47890High· 7.6Download to arbitrary folder can lead to RCE
Download to arbitrary folder can lead to RCE
CVE-2023-46402High· 7.5Inefficient Regular Expression Complexity in git-urls
Inefficient Regular Expression Complexity in git-urls
CVE-2023-6019Critical· 9.8PoCRay OS Command Injection vulnerability
Ray OS Command Injection vulnerability
CVE-2023-48052High· 7.4HTTPie allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack
HTTPie allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack
CVE-2023-6020Critical· 9.3PoCRay Missing Authorization vulnerability
Ray Missing Authorization vulnerability
CVE-2023-6021Critical· 9.3PoCRay Path Traversal vulnerability
Ray Path Traversal vulnerability
CVE-2023-48224High· 8.2Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity Verification
Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity Verification
CVE-2023-6022High· 8.8Cross-Site Request Forgery vulnerability in Prefect
Cross-Site Request Forgery vulnerability in Prefect
CVE-2023-5189Medium· 6.3Ansible galaxy-importer Path Traversal vulnerability
Ansible galaxy-importer Path Traversal vulnerability
CVE-2023-46121Medium· 5.0yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection
yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection
CVE-2023-47631High· 7.2vantage6-server node accepts non-whitelisted algorithms from malicious server
vantage6-server node accepts non-whitelisted algorithms from malicious server
CVE-2023-47627Medium· 5.3AIOHTTP has problems in HTTP parser (the python one, not llhttp)
AIOHTTP has problems in HTTP parser (the python one, not llhttp)
CVE-2023-47117High· 7.5PoCLabel Studio Object Relational Mapper Leak Vulnerability in Filtering Task
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
CVE-2023-47630High· 7.1⚠ Exploited0dayAttacker can cause Kyverno user to unintentionally consume insecure image
Attacker can cause Kyverno user to unintentionally consume insecure image
CVE-2023-5954High· 7.5HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
CVE-2023-47248Critical· 9.8PoCPyArrow: Arbitrary code execution when loading a malicious data file
PyArrow: Arbitrary code execution when loading a malicious data file
CVE-2023-46445Medium· 5.3AsyncSSH Rogue Extension Negotiation
AsyncSSH Rogue Extension Negotiation
CVE-2023-46446High· 8.1AsyncSSH Rogue Session Attack
AsyncSSH Rogue Session Attack
CVE-2023-47111High· 7.3ZITADEL race condition in lockout policy execution
ZITADEL race condition in lockout policy execution
CVE-2023-47114Medium· 4.3Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages
Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages
CVE-2023-46254Medium· 4.3capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name
capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name
CVE-2023-41378High· 7.5Calico Typha denial of service vulnerability
Calico Typha denial of service vulnerability