Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2023-28635Medium· 5.4Defining resource name as integer may give unintended access in vantage6
Defining resource name as integer may give unintended access in vantage6
CVE-2023-4822Medium· 6.7grafana: incorrect assessment of permissions across organizations (CVE-2023-4822)
A flaw was found in the Grafana enterprise package. Grafana is incorrectly assessing permissions to update global roles and role assignments, therefore, users with administrator permissions in one organization can change global role permis…
CVE-2023-39325High· 7.5PoCHTTP/2 rapid reset can cause excessive work in net/http
HTTP/2 rapid reset can cause excessive work in net/http
CVE-2023-45129Medium· 4.9matrix-synapse vulnerable to denial of service due to malicious server ACL events
matrix-synapse vulnerable to denial of service due to malicious server ACL events
CVE-2023-20902Medium· 5.9Harbor timing attack risk
Harbor timing attack risk
CVE-2023-36566Medium· 6.5Microsoft Common Data Model SDK Denial of Service Vulnerability
Microsoft Common Data Model SDK Denial of Service Vulnerability
CVE-2023-32188CriticalJWT token compromise can allow malicious actions including Remote Code Execution (RCE)
JWT token compromise can allow malicious actions including Remote Code Execution (RCE)
CVE-2023-4570High· 8.8NI MeasurementLink Python Services Improper Access Restriction vulnerability
NI MeasurementLink Python Services Improper Access Restriction vulnerability
CVE-2023-44378Medium· 5.5gnark unsoundness in variable comparison / non-unique binary decomposition
gnark unsoundness in variable comparison / non-unique binary decomposition
CVE-2023-44389Low· 3.1Zope management interface vulnerable to stored cross site scripting via the title property
Zope management interface vulnerable to stored cross site scripting via the title property
CVE-2023-4237Medium· 6.5Ansible may expose private key
Ansible may expose private key
CVE-2023-43804Medium· 5.9PoC`Cookie` HTTP header isn't stripped on cross-origin redirects
`Cookie` HTTP header isn't stripped on cross-origin redirects
CVE-2023-43654Critical· 9.8PoCTorchServe Server-Side Request Forgery vulnerability
TorchServe Server-Side Request Forgery vulnerability
CVE-2023-43810High· 7.5opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics
opentelemetry-instrumentation Denial of Service vulnerability due to unbound cardinality metrics
CVE-2023-5077High· 7.6Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
CVE-2023-44464High· 7.8pretix allows Pillow to parse EPS files
pretix allows Pillow to parse EPS files
CVE-2023-43645Medium· 5.9OpenFGA Vulnerable to DoS from circular relationship definitions
OpenFGA Vulnerable to DoS from circular relationship definitions
CVE-2023-40026Medium· 5.0Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
CVE-2023-41333Medium· 6.9Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
CVE-2023-41332Low· 3.5Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
CVE-2023-42453Low· 3.1matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
CVE-2023-41335Low· 3.7matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
CVE-2023-41419Critical· 9.8Gevent allows remote attacker to escalate privileges
Gevent allows remote attacker to escalate privileges
CVE-2023-43364Critical· 9.8PoCSearchor CLI's Search vulnerable to Arbitrary Code using Eval
Searchor CLI's Search vulnerable to Arbitrary Code using Eval
CVE-2023-40581High· 8.3yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`
yt-dlp on Windows vulnerable to `--exec` command injection when using `%q`
CVE-2023-1636Medium· 6.0OpenStack Barbican information disclosure vulnerability
OpenStack Barbican information disclosure vulnerability
CVE-2023-1633Medium· 6.6OpenStack Barbican credential leak flaw
OpenStack Barbican credential leak flaw
CVE-2023-1625High· 7.4OpenStack Heat information leak vulnerability
OpenStack Heat information leak vulnerability
CVE-2022-3962Medium· 4.3Kiali content spoofing vulnerability
Kiali content spoofing vulnerability
CVE-2023-5002Medium· 6.0pgAdmin failed to properly control the server code
pgAdmin failed to properly control the server code