VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

MAL-2023-8429None
2y ago

Malicious code in littest (crates.io)

Malicious code in littest (crates.io)

▾ Sunlitlittest · littestvia OSV
CVE-2023-3676High· 8.8
2y ago

Kubernetes privilege escalation vulnerability

Kubernetes privilege escalation vulnerability

▾ Twilightkubernetes · k8s.io/kubernetesEPSS 13%via OSV
CVE-2023-43796Medium· 5.3
2y ago

Synapse vulnerable to leak of remote user device information

Synapse vulnerable to leak of remote user device information

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.90%via OSV
CVE-2023-46250Medium· 5.1
2y ago

Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF

Possible Infinite Loop when PdfWriter(clone_from) is used with a PDF

▾ Sunlitpypdf · pypdfEPSS 0.24%via OSV
CVE-2023-46239High· 7.5
2y ago

quic-go vulnerable to pointer dereference that can lead to panic

quic-go vulnerable to pointer dereference that can lead to panic

▾ Twilightquic-go · github.com/quic-go/quic-goEPSS 0.77%via OSV
CVE-2021-25736Medium· 5.8
2y ago

Kube-proxy may unintentionally forward traffic

Kube-proxy may unintentionally forward traffic

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 0.92%via OSV
CVE-2023-46215High· 7.5
2y ago

Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability

Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability

▾ Twilightapache-airflow-providers-celery · apache-airflow-providers-celeryEPSS 1.2%via OSV
CVE-2023-41893Medium· 4.3
2y ago

Home Assistant vulnerable to account takeover via auth_callback login

Home Assistant vulnerable to account takeover via auth_callback login

▾ Sunlithomeassistant · homeassistantEPSS 0.40%via OSV
CVE-2023-5752Medium· 5.5
2y ago

Command Injection in pip when used with Mercurial

Command Injection in pip when used with Mercurial

▾ Sunlitpip · pipEPSS 0.48%via OSV
CVE-2023-46136Medium· 5.7PoC
2y ago

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning

▾ Twilightwerkzeug · werkzeugEPSS 1.1%via OSV
CVE-2022-4886High· 8.8
2y ago

Ingress-nginx path sanitization can be bypassed

Ingress-nginx path sanitization can be bypassed

▾ Twilightingress-nginx · k8s.io/ingress-nginxEPSS 1.6%via OSV
CVE-2023-5043High· 7.6PoC
2y ago

Ingress nginx annotation injection causes arbitrary command execution

Ingress nginx annotation injection causes arbitrary command execution

▾ Midnightingress-nginx · k8s.io/ingress-nginxEPSS 2.2%via OSV
CVE-2023-46134Medium· 6.1
2y ago

dtale vulnerable to Remote Code Execution through the Custom Filter Input

dtale vulnerable to Remote Code Execution through the Custom Filter Input

▾ Sunlitdtale · dtaleEPSS 0.76%via OSV
CVE-2023-43651Medium· 6.4
2y ago

Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shell

Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shell

▾ Sunlitjumpserver · github.com/jumpserver/kokoEPSS 2.1%via OSV
CVE-2023-46128High· 7.7
2y ago

Nautobot vulnerable to exposure of hashed user passwords via REST API

Nautobot vulnerable to exposure of hashed user passwords via REST API

▾ Twilightnautobot · nautobotEPSS 0.53%via OSV
CVE-2023-46125Medium· 6.5
2y ago

Fides Information Disclosure Vulnerability in Config API Endpoint

Fides Information Disclosure Vulnerability in Config API Endpoint

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.73%via OSV
CVE-2023-46124High· 8.2
2y ago

Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload

Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.68%via OSV
CVE-2023-46126Low· 3.9
2y ago

Fides JavaScript Injection Vulnerability in Privacy Center URL

Fides JavaScript Injection Vulnerability in Privacy Center URL

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.61%via OSV
CVE-2023-32786High· 7.5
2y ago

Langchain Server-Side Request Forgery vulnerability

Langchain Server-Side Request Forgery vulnerability

▾ Twilightlangchain · langchainEPSS 0.70%via OSV
CVE-2023-44690Medium
2y ago

mycli has Inadequate Encryption Strength

mycli has Inadequate Encryption Strength

▾ Sunlitmycli · mycliEPSS 0.22%via OSV
CVE-2023-45805High· 7.8
2y ago

PDM Trojan Lockfile

PDM Trojan Lockfile

▾ Twilightpdm · pdmEPSS 0.51%via OSV
CVE-2023-47090High
2y ago

NATS.io: Adding accounts for just the system account adds auth bypass

NATS.io: Adding accounts for just the system account adds auth bypass

▾ Twilightnats-io · github.com/nats-io/nats-server/v2EPSS 0.66%via OSV
CVE-2023-45813Medium· 4.6
2y ago

TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link

TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link

▾ Sunlittorbot · torbotEPSS 0.80%via OSV
CVE-2023-43802High· 7.3
2y ago

Arduino Create Agent path traversal - local privilege escalation vulnerability

Arduino Create Agent path traversal - local privilege escalation vulnerability

▾ Twilightarduino · github.com/arduino/arduino-create-agentEPSS 0.35%via OSV
CVE-2023-43800High· 7.3
2y ago

Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability

Arduino Create Agent Insufficient Verification of Data Authenticity vulnerability

▾ Twilightarduino · github.com/arduino/arduino-create-agentEPSS 0.21%via OSV
CVE-2023-45683High· 7.1
2y ago

Cross-site Scripting via missing Binding syntax validation

Cross-site Scripting via missing Binding syntax validation

▾ Twilightcrewjam · github.com/crewjam/samlEPSS 0.43%via OSV
CVE-2023-45803Medium· 4.2
2y ago

urllib3's request body not stripped after redirect from 303 status changes request method to GET

urllib3's request body not stripped after redirect from 303 status changes request method to GET

▾ Sunliturllib3 · urllib3EPSS 0.54%via OSV
CVE-2023-41881Low· 3.7
2y ago

vantage6 does not properly delete linked resources when deleting a collaboration

vantage6 does not properly delete linked resources when deleting a collaboration

▾ Sunlitvantage6 · vantage6EPSS 0.32%via OSV
CVE-2023-45853Critical· 9.8⚖ disputed
2y ago

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pymini…

▾ Midnightzlib · zlibEPSS 3.2%via NVD
CVE-2023-23930High· 7.2
2y ago

Pickle serialization vulnerable to Deserialization of Untrusted Data

Pickle serialization vulnerable to Deserialization of Untrusted Data

▾ Twilightvantage6 · vantage6EPSS 0.89%via OSV
CVEs tagged “osv” — page 143 · VulnSea