VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2023-28635Medium· 5.4
2y ago

Defining resource name as integer may give unintended access in vantage6

Defining resource name as integer may give unintended access in vantage6

▾ Sunlitvantage6 · vantage6EPSS 0.41%via OSV
CVE-2023-4822Medium· 6.7
2y ago

grafana: incorrect assessment of permissions across organizations (CVE-2023-4822)

A flaw was found in the Grafana enterprise package. Grafana is incorrectly assessing permissions to update global roles and role assignments, therefore, users with administrator permissions in one organization can change global role permis…

▾ SunlitRed Hat · Red Hat Ceph Storage 7.1 ToolsEPSS 1.1%via CSAF
CVE-2023-39325High· 7.5PoC
2y ago

HTTP/2 rapid reset can cause excessive work in net/http

HTTP/2 rapid reset can cause excessive work in net/http

▾ Midnightstdlib · stdlibEPSS 3.8%via OSV
CVE-2023-45129Medium· 4.9
2y ago

matrix-synapse vulnerable to denial of service due to malicious server ACL events

matrix-synapse vulnerable to denial of service due to malicious server ACL events

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.2%via OSV
CVE-2023-20902Medium· 5.9
2y ago

Harbor timing attack risk

Harbor timing attack risk

▾ Sunlitgoharbor · github.com/goharbor/harborEPSS 0.37%via OSV
CVE-2023-36566Medium· 6.5
2y ago

Microsoft Common Data Model SDK Denial of Service Vulnerability

Microsoft Common Data Model SDK Denial of Service Vulnerability

▾ SunlitMicrosoft · Microsoft.CommonDataModel.ObjectModelEPSS 2.8%via OSV
CVE-2023-32188Critical
2y ago

JWT token compromise can allow malicious actions including Remote Code Execution (RCE)

JWT token compromise can allow malicious actions including Remote Code Execution (RCE)

▾ Midnightneuvector · github.com/neuvector/neuvectorEPSS 0.48%via OSV
CVE-2023-4570High· 8.8
2y ago

NI MeasurementLink Python Services Improper Access Restriction vulnerability

NI MeasurementLink Python Services Improper Access Restriction vulnerability

▾ Twilightni-measurementlink-service · ni-measurementlink-serviceEPSS 0.28%via OSV
CVE-2023-44378Medium· 5.5
2y ago

gnark unsoundness in variable comparison / non-unique binary decomposition

gnark unsoundness in variable comparison / non-unique binary decomposition

▾ Sunlitconsensys · github.com/consensys/gnarkEPSS 0.22%via OSV
CVE-2023-44389Low· 3.1
2y ago

Zope management interface vulnerable to stored cross site scripting via the title property

Zope management interface vulnerable to stored cross site scripting via the title property

▾ Sunlitzope · zopeEPSS 0.40%via OSV
CVE-2023-4237Medium· 6.5
2y ago

Ansible may expose private key

Ansible may expose private key

▾ Sunlitansible-core · ansible-coreEPSS 0.25%via OSV
CVE-2023-43804Medium· 5.9PoC
3y ago

`Cookie` HTTP header isn't stripped on cross-origin redirects

`Cookie` HTTP header isn't stripped on cross-origin redirects

▾ Twilighturllib3 · urllib3EPSS 1.2%via OSV
CVE-2023-43654Critical· 9.8PoC
3y ago

TorchServe Server-Side Request Forgery vulnerability

TorchServe Server-Side Request Forgery vulnerability

▾ Abyssaltorchserve · torchserveEPSS 40%via OSV
CVE-2023-43810High· 7.5
3y ago

opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics

opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics

▾ Twilightopentelemetry-instrumentation · opentelemetry-instrumentationEPSS 0.69%via OSV
CVE-2023-5077High· 7.6
3y ago

Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability

Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability

▾ Twilighthashicorp · github.com/hashicorp/vaultEPSS 0.50%via OSV
CVE-2023-44464High· 7.8
3y ago

pretix allows Pillow to parse EPS files

pretix allows Pillow to parse EPS files

▾ Twilightpretix · pretixEPSS 0.30%via OSV
CVE-2023-43645Medium· 5.9
3y ago

OpenFGA Vulnerable to DoS from circular relationship definitions

OpenFGA Vulnerable to DoS from circular relationship definitions

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.94%via OSV
CVE-2023-40026Medium· 5.0
3y ago

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server

▾ Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.61%via OSV
CVE-2023-41333Medium· 6.9
3y ago

Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy

Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.48%via OSV
CVE-2023-41332Low· 3.5
3y ago

Specific Cilium configurations vulnerable to DoS via Kubernetes annotations

Specific Cilium configurations vulnerable to DoS via Kubernetes annotations

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.51%via OSV
CVE-2023-42453Low· 3.1
3y ago

matrix-synapse vulnerable to improper validation of receipts allows forged read receipts

matrix-synapse vulnerable to improper validation of receipts allows forged read receipts

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.78%via OSV
CVE-2023-41335Low· 3.7
3y ago

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.39%via OSV
CVE-2023-41419Critical· 9.8
3y ago

Gevent allows remote attacker to escalate privileges

Gevent allows remote attacker to escalate privileges

▾ Midnightgevent · geventEPSS 1.8%via OSV
CVE-2023-43364Critical· 9.8PoC
3y ago

Searchor CLI's Search vulnerable to Arbitrary Code using Eval

Searchor CLI's Search vulnerable to Arbitrary Code using Eval

▾ Abyssalsearchor · searchorEPSS 2.9%via OSV
CVE-2023-40581High· 8.3
3y ago

yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`

yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`

▾ Twilightyt-dlp · yt-dlpEPSS 1.3%via OSV
CVE-2023-1636Medium· 6.0
3y ago

OpenStack Barbican information disclosure vulnerability

OpenStack Barbican information disclosure vulnerability

▾ Sunlitbarbican · barbicanEPSS 0.48%via OSV
CVE-2023-1633Medium· 6.6
3y ago

OpenStack Barbican credential leak flaw

OpenStack Barbican credential leak flaw

▾ Sunlitbarbican · barbicanEPSS 0.19%via OSV
CVE-2023-1625High· 7.4
3y ago

OpenStack Heat information leak vulnerability

OpenStack Heat information leak vulnerability

▾ Twilightopenstack-heat · openstack-heatEPSS 0.71%via OSV
CVE-2022-3962Medium· 4.3
3y ago

Kiali content spoofing vulnerability

Kiali content spoofing vulnerability

▾ Sunlitkiali · github.com/kiali/kialiEPSS 0.74%via OSV
CVE-2023-5002Medium· 6.0
3y ago

pgAdmin failed to properly control the server code

pgAdmin failed to properly control the server code

▾ Sunlitpgadmin4 · pgadmin4EPSS 1.8%via OSV
CVEs tagged “osv” — page 144 · VulnSea