VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

GHSA-v8gr-m533-ghj9Low
3y ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

▾ Sunlitcryptography · cryptographyvia OSV
CVE-2023-43669High· 7.5
3y ago

Tungstenite allows remote attackers to cause a denial of service

Tungstenite allows remote attackers to cause a denial of service

▾ Twilighttungstenite · tungsteniteEPSS 2.1%via OSV
CVE-2023-42458Low· 3.7
3y ago

Zope vulnerable to Stored Cross Site Scripting with SVG images

Zope vulnerable to Stored Cross Site Scripting with SVG images

▾ Sunlitzope · zopeEPSS 0.71%via OSV
CVE-2023-43621Medium· 4.7
3y ago

Croc may expose secret to local users

Croc may expose secret to local users

▾ Sunlitschollz · github.com/schollz/croc/v9EPSS 0.31%via OSV
CVE-2023-43618Medium· 5.3
3y ago

Croc requires senders to provide local IP addresses in cleartext

Croc requires senders to provide local IP addresses in cleartext

▾ Sunlitschollz · github.com/schollz/croc/v9EPSS 0.49%via OSV
CVE-2023-43620High· 7.8
3y ago

Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device

Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device

▾ Twilightschollz · github.com/schollz/croc/v9EPSS 0.36%via OSV
CVE-2023-42439High· 7.5
3y ago

GeoNode vulnerable to SSRF Bypass to return internal host data

GeoNode vulnerable to SSRF Bypass to return internal host data

▾ Twilightgeonode · geonodeEPSS 0.96%via OSV
CVE-2023-42441Medium· 5.3
3y ago

Vyper has incorrect re-entrancy lock when key is empty string

Vyper has incorrect re-entrancy lock when key is empty string

▾ Sunlitvyper · vyperEPSS 0.51%via OSV
CVE-2023-41626Medium· 4.8
3y ago

Gradio arbitrary file upload vulnerability

Gradio arbitrary file upload vulnerability

▾ Sunlitgradio · gradioEPSS 0.41%via OSV
CVE-2023-4680Medium· 6.8
3y ago

HashiCorp Vault Improper Input Validation vulnerability

HashiCorp Vault Improper Input Validation vulnerability

▾ Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.44%via OSV
RUSTSEC-2023-0085None
3y ago

HPACK decoder panics on invalid input

HPACK decoder panics on invalid input

▾ Sunlithpack · hpackvia OSV
CVE-2023-41880Low· 2.2
3y ago

Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64

Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64

▾ Sunlitwasmtime · wasmtimeEPSS 0.67%via OSV
CVE-2023-41267High· 7.8
3y ago

Apache HDFS Provider error message suggested

Apache HDFS Provider error message suggested

▾ Twilightapache-airflow-providers-apache-hdfs · apache-airflow-providers-apache-hdfsEPSS 0.60%via OSV
CVE-2023-4785High· 7.5
3y ago

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

▾ Twilightgrpc · grpcEPSS 0.77%via OSV
CVE-2023-4863High· 8.8CISA KEV0dayPoC
3y ago

libwebp: OOB write in BuildHuffmanTable

libwebp: OOB write in BuildHuffmanTable

▾ Abyssallibwebp-sys2 · libwebp-sys2EPSS 100%via OSV
GHSA-jcr6-4frq-9gjjMedium
3y ago

Users vulnerable to unaligned read of `*const *const c_char` pointer

Users vulnerable to unaligned read of `*const *const c_char` pointer

▾ Sunlitusers · usersvia OSV
CVE-2023-41318Medium· 4.1
3y ago

matrix-media-repo: Unsafe media served inline on download endpoints

matrix-media-repo: Unsafe media served inline on download endpoints

▾ Sunlitturt2live · github.com/turt2live/matrix-media-repoEPSS 0.52%via OSV
CVE-2023-41338Medium· 5.3
3y ago

Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`

Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`

▾ Sunlitgofiber · github.com/gofiber/fiberEPSS 0.66%via OSV
CVE-2023-41329Low· 3.9
3y ago

Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes

Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes

▾ Sunlitwiremock · org.wiremock:wiremock-standaloneEPSS 0.63%via OSV
GHSA-6xv5-86q9-7xr8Medium
3y ago

SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced

SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced

▾ Sunlitcyphar · github.com/cyphar/filepath-securejoinvia OSV
CVE-2023-41319High· 8.8
3y ago

Remote Code Execution in Custom Integration Upload

Remote Code Execution in Custom Integration Upload

▾ Twilightethyca-fides · ethyca-fidesEPSS 0.94%via OSV
CVE-2023-41050Medium· 6.8
3y ago

Information disclosure in AccessControl

Information disclosure in AccessControl

▾ Sunlitaccesscontrol · accesscontrolEPSS 0.64%via OSV
GHSA-23px-mw2p-46qmMedium
3y ago

Cosmos-SDK Cosmovisor component may be vulnerable to denial of service

Cosmos-SDK Cosmovisor component may be vulnerable to denial of service

▾ Sunlitcosmos · github.com/cosmos/cosmos-sdkvia OSV
CVE-2023-27523Medium· 5.0
3y ago

Apache Superset vulnerable to improper data authorization

Apache Superset vulnerable to improper data authorization

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2023-39265Medium· 6.5PoC
3y ago

Apache Superset Improper Input Validation vulnerability

Apache Superset Improper Input Validation vulnerability

▾ Twilightapache-superset · apache-supersetEPSS 86%via OSV
CVE-2023-37941Medium· 6.6PoC
3y ago

Apache Superset Deserialization of Untrusted Data vulnerability

Apache Superset Deserialization of Untrusted Data vulnerability

▾ Twilightapache-superset · apache-supersetEPSS 35%via OSV
CVE-2023-38201Medium· 6.5
3y ago

Keylime registrar and (untrusted) Agent can be bypassed by an attacker

Keylime registrar and (untrusted) Agent can be bypassed by an attacker

▾ Sunlitkeylime · keylimeEPSS 0.49%via OSV
CVE-2023-39264Medium· 4.3
3y ago

Apache Superset may expose internal traces on REST API endpoints

Apache Superset may expose internal traces on REST API endpoints

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVE-2023-27526Medium· 4.3
3y ago

Apache Superset users may incorrectly create resources using the import charts feature

Apache Superset users may incorrectly create resources using the import charts feature

▾ Sunlitapache-superset · apache-supersetEPSS 1.2%via OSV
CVE-2023-36387Medium· 5.4
3y ago

Apache Superset has improper default REST API permission for Gamma users

Apache Superset has improper default REST API permission for Gamma users

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVEs tagged “osv” — page 145 · VulnSea