VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

GHSA-pjjw-qhg8-p2p9Medium
2y ago

aiohttp has vulnerable dependency that is vulnerable to request smuggling

aiohttp has vulnerable dependency that is vulnerable to request smuggling

▾ Sunlitaiohttp · aiohttpvia OSV
CVE-2023-43701Medium· 4.3
2y ago

Apache Superset Cross-site Scripting vulnerability

Apache Superset Cross-site Scripting vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2023-42501Medium· 4.3
2y ago

Apache Superset has Incorrect Default Permissions

Apache Superset has Incorrect Default Permissions

▾ Sunlitapache-superset · apache-supersetEPSS 0.86%via OSV
CVE-2023-49092Medium· 5.9
2y ago

Marvin Attack: potential key recovery through timing sidechannels

Marvin Attack: potential key recovery through timing sidechannels

▾ Sunlitrsa · rsaEPSS 0.61%via OSV
GHSA-2c7c-3mj9-8fqhMedium
2y ago

Decryption of malicious PBES2 JWE objects can consume unbounded system resources

Decryption of malicious PBES2 JWE objects can consume unbounded system resources

▾ Sunlitgo-jose · github.com/go-jose/go-jose/v3via OSV
CVE-2023-48699High· 8.4
2y ago

Eval Injection in fastbots

Eval Injection in fastbots

▾ Twilightfastbots · fastbotsEPSS 0.74%via OSV
CVE-2023-48700Medium· 5.7
2y ago

Clear Text Credentials Exposed via Onboarding Task

Clear Text Credentials Exposed via Onboarding Task

▾ Sunlitnautobot-device-onboarding · nautobot-device-onboardingEPSS 0.41%via OSV
CVE-2023-48299Medium· 5.3
2y ago

TorchServe ZipSlip

TorchServe ZipSlip

▾ Sunlittorchserve · torchserveEPSS 0.68%via OSV
CVE-2023-47890High· 7.6
2y ago

Download to arbitrary folder can lead to RCE

Download to arbitrary folder can lead to RCE

▾ Twilightpyload-ng · pyload-ngEPSS 1.1%via OSV
CVE-2023-46402High· 7.5
2y ago

Inefficient Regular Expression Complexity in git-urls

Inefficient Regular Expression Complexity in git-urls

▾ Twilightwhilp · github.com/whilp/git-urlsEPSS 0.85%via OSV
CVE-2023-6019Critical· 9.8PoC
2y ago

Ray OS Command Injection vulnerability

Ray OS Command Injection vulnerability

▾ Abyssalray · rayEPSS 75%via OSV
CVE-2023-48052High· 7.4
2y ago

HTTPie allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack

HTTPie allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack

▾ Twilighthttpie · httpieEPSS 0.31%via OSV
CVE-2023-6020Critical· 9.3PoC
2y ago

Ray Missing Authorization vulnerability

Ray Missing Authorization vulnerability

▾ Abyssalray · rayEPSS 15%via OSV
CVE-2023-6021Critical· 9.3PoC
2y ago

Ray Path Traversal vulnerability

Ray Path Traversal vulnerability

▾ Abyssalray · rayEPSS 37%via OSV
CVE-2023-48224High· 8.2
2y ago

Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity Verification

Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity Verification

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.99%via OSV
CVE-2023-6022High· 8.8
2y ago

Cross-Site Request Forgery vulnerability in Prefect

Cross-Site Request Forgery vulnerability in Prefect

▾ Twilightprefect · prefectEPSS 0.39%via OSV
CVE-2023-5189Medium· 6.3
2y ago

Ansible galaxy-importer Path Traversal vulnerability

Ansible galaxy-importer Path Traversal vulnerability

▾ Sunlitgalaxy-importer · galaxy-importerEPSS 0.98%via OSV
CVE-2023-46121Medium· 5.0
2y ago

yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection

yt-dlp Generic Extractor MITM Vulnerability via Arbitrary Proxy Injection

▾ Sunlityt-dlp · yt-dlpEPSS 0.32%via OSV
CVE-2023-47631High· 7.2
2y ago

vantage6-server node accepts non-whitelisted algorithms from malicious server

vantage6-server node accepts non-whitelisted algorithms from malicious server

▾ Twilightvantage6-server · vantage6-serverEPSS 0.45%via OSV
CVE-2023-47627Medium· 5.3
2y ago

AIOHTTP has problems in HTTP parser (the python one, not llhttp)

AIOHTTP has problems in HTTP parser (the python one, not llhttp)

▾ Sunlitaiohttp · aiohttpEPSS 0.86%via OSV
CVE-2023-47117High· 7.5PoC
2y ago

Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task

Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task

▾ Midnightlabel-studio · label-studioEPSS 4.1%via OSV
CVE-2023-47630High· 7.1⚠ Exploited0day
2y ago

Attacker can cause Kyverno user to unintentionally consume insecure image

Attacker can cause Kyverno user to unintentionally consume insecure image

▾ Abyssalkyverno · github.com/kyverno/kyvernoEPSS 0.26%via OSV
CVE-2023-5954High· 7.5
2y ago

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.72%via OSV
CVE-2023-47248Critical· 9.8PoC
2y ago

PyArrow: Arbitrary code execution when loading a malicious data file

PyArrow: Arbitrary code execution when loading a malicious data file

▾ Abyssalpyarrow · pyarrowEPSS 15%via OSV
CVE-2023-46445Medium· 5.3
2y ago

AsyncSSH Rogue Extension Negotiation

AsyncSSH Rogue Extension Negotiation

▾ Sunlitasyncssh · asyncsshEPSS 0.59%via OSV
CVE-2023-46446High· 8.1
2y ago

AsyncSSH Rogue Session Attack

AsyncSSH Rogue Session Attack

▾ Twilightasyncssh · asyncsshEPSS 0.87%via OSV
CVE-2023-47111High· 7.3
2y ago

ZITADEL race condition in lockout policy execution

ZITADEL race condition in lockout policy execution

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.52%via OSV
CVE-2023-47114Medium· 4.3
2y ago

Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages

Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR Packages

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.61%via OSV
CVE-2023-46254Medium· 4.3
2y ago

capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name

capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name

▾ Sunlitprojectcapsule · github.com/projectcapsule/capsuleEPSS 0.41%via OSV
CVE-2023-41378High· 7.5
2y ago

Calico Typha denial of service vulnerability

Calico Typha denial of service vulnerability

▾ Twilightprojectcalico · github.com/projectcalico/calicoEPSS 0.72%via OSV
CVEs tagged “osv” — page 142 · VulnSea