Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
MAL-2023-8429NoneMalicious code in littest (crates.io)
Malicious code in littest (crates.io)
CVE-2023-3676High· 8.8Kubernetes privilege escalation vulnerability
Kubernetes privilege escalation vulnerability
CVE-2023-43796Medium· 5.3Synapse vulnerable to leak of remote user device information
Synapse vulnerable to leak of remote user device information
CVE-2023-46250Medium· 5.1Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF
Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF
CVE-2023-46239High· 7.5quic-go vulnerable to pointer dereference that can lead to panic
quic-go vulnerable to pointer dereference that can lead to panic
CVE-2021-25736Medium· 5.8Kube-proxy may unintentionally forward traffic
Kube-proxy may unintentionally forward traffic
CVE-2023-46215High· 7.5Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
CVE-2023-41893Medium· 4.3Home Assistant vulnerable to account takeover via auth_callback login
Home Assistant vulnerable to account takeover via auth_callback login
CVE-2023-5752Medium· 5.5Command Injection in pip when used with Mercurial
Command Injection in pip when used with Mercurial
CVE-2023-46136Medium· 5.7PoCWerkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
CVE-2022-4886High· 8.8Ingress-nginx path sanitization can be bypassed
Ingress-nginx path sanitization can be bypassed
CVE-2023-5043High· 7.6PoCIngress nginx annotation injection causes arbitrary command execution
Ingress nginx annotation injection causes arbitrary command execution
CVE-2023-46134Medium· 6.1dtale vulnerable to Remote Code Execution through the Custom Filter Input
dtale vulnerable to Remote Code Execution through the Custom Filter Input
CVE-2023-43651Medium· 6.4Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shell
Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shell
CVE-2023-46128High· 7.7Nautobot vulnerable to exposure of hashed user passwords via REST API
Nautobot vulnerable to exposure of hashed user passwords via REST API
CVE-2023-46125Medium· 6.5Fides Information Disclosure Vulnerability in Config API Endpoint
Fides Information Disclosure Vulnerability in Config API Endpoint
CVE-2023-46124High· 8.2Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
CVE-2023-46126Low· 3.9Fides JavaScript Injection Vulnerability in Privacy Center URL
Fides JavaScript Injection Vulnerability in Privacy Center URL
CVE-2023-32786High· 7.5Langchain Server-Side Request Forgery vulnerability
Langchain Server-Side Request Forgery vulnerability
CVE-2023-44690Mediummycli has Inadequate Encryption Strength
mycli has Inadequate Encryption Strength
CVE-2023-45805High· 7.8PDM Trojan Lockfile
PDM Trojan Lockfile
CVE-2023-47090HighNATS.io: Adding accounts for just the system account adds auth bypass
NATS.io: Adding accounts for just the system account adds auth bypass
CVE-2023-45813Medium· 4.6TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link
TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link
CVE-2023-43802High· 7.3Arduino Create Agent path traversal - local privilege escalation vulnerability
Arduino Create Agent path traversal - local privilege escalation vulnerability
CVE-2023-43800High· 7.3Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability
Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability
CVE-2023-45683High· 7.1Cross-site Scripting via missing Binding syntax validation
Cross-site Scripting via missing Binding syntax validation
CVE-2023-45803Medium· 4.2urllib3's request body not stripped after redirect from 303 status changes request method to GET
urllib3's request body not stripped after redirect from 303 status changes request method to GET
CVE-2023-41881Low· 3.7vantage6 does not properly delete linked resources when deleting a collaboration
vantage6 does not properly delete linked resources when deleting a collaboration
CVE-2023-45853Critical· 9.8⚖ disputedMiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pymini…
CVE-2023-23930High· 7.2Pickle serialization vulnerable to Deserialization of Untrusted Data
Pickle serialization vulnerable to Deserialization of Untrusted Data