Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
GHSA-v8gr-m533-ghj9LowVulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2023-43669High· 7.5Tungstenite allows remote attackers to cause a denial of service
Tungstenite allows remote attackers to cause a denial of service
CVE-2023-42458Low· 3.7Zope vulnerable to Stored Cross Site Scripting with SVG images
Zope vulnerable to Stored Cross Site Scripting with SVG images
CVE-2023-43621Medium· 4.7Croc may expose secret to local users
Croc may expose secret to local users
CVE-2023-43618Medium· 5.3Croc requires senders to provide local IP addresses in cleartext
Croc requires senders to provide local IP addresses in cleartext
CVE-2023-43620High· 7.8Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device
Croc sender may place ANSI or CSI escape sequences in filename to attach receiver's terminal device
CVE-2023-42439High· 7.5GeoNode vulnerable to SSRF Bypass to return internal host data
GeoNode vulnerable to SSRF Bypass to return internal host data
CVE-2023-42441Medium· 5.3Vyper has incorrect re-entrancy lock when key is empty string
Vyper has incorrect re-entrancy lock when key is empty string
CVE-2023-41626Medium· 4.8Gradio arbitrary file upload vulnerability
Gradio arbitrary file upload vulnerability
CVE-2023-4680Medium· 6.8HashiCorp Vault Improper Input Validation vulnerability
HashiCorp Vault Improper Input Validation vulnerability
RUSTSEC-2023-0085NoneHPACK decoder panics on invalid input
HPACK decoder panics on invalid input
CVE-2023-41880Low· 2.2Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
CVE-2023-41267High· 7.8Apache HDFS Provider error message suggested
Apache HDFS Provider error message suggested
CVE-2023-4785High· 7.5Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)
CVE-2023-4863High· 8.8CISA KEV0dayPoClibwebp: OOB write in BuildHuffmanTable
libwebp: OOB write in BuildHuffmanTable
GHSA-jcr6-4frq-9gjjMediumUsers vulnerable to unaligned read of `*const *const c_char` pointer
Users vulnerable to unaligned read of `*const *const c_char` pointer
CVE-2023-41318Medium· 4.1matrix-media-repo: Unsafe media served inline on download endpoints
matrix-media-repo: Unsafe media served inline on download endpoints
CVE-2023-41338Medium· 5.3Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`
Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`
CVE-2023-41329Low· 3.9Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes
Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes
GHSA-6xv5-86q9-7xr8MediumSecureJoin: on windows, paths outside of the rootfs could be inadvertently produced
SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced
CVE-2023-41319High· 8.8Remote Code Execution in Custom Integration Upload
Remote Code Execution in Custom Integration Upload
CVE-2023-41050Medium· 6.8Information disclosure in AccessControl
Information disclosure in AccessControl
GHSA-23px-mw2p-46qmMediumCosmos-SDK Cosmovisor component may be vulnerable to denial of service
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
CVE-2023-27523Medium· 5.0Apache Superset vulnerable to improper data authorization
Apache Superset vulnerable to improper data authorization
CVE-2023-39265Medium· 6.5PoCApache Superset Improper Input Validation vulnerability
Apache Superset Improper Input Validation vulnerability
CVE-2023-37941Medium· 6.6PoCApache Superset Deserialization of Untrusted Data vulnerability
Apache Superset Deserialization of Untrusted Data vulnerability
CVE-2023-38201Medium· 6.5Keylime registrar and (untrusted) Agent can be bypassed by an attacker
Keylime registrar and (untrusted) Agent can be bypassed by an attacker
CVE-2023-39264Medium· 4.3Apache Superset may expose internal traces on REST API endpoints
Apache Superset may expose internal traces on REST API endpoints
CVE-2023-27526Medium· 4.3Apache Superset users may incorrectly create resources using the import charts feature
Apache Superset users may incorrectly create resources using the import charts feature
CVE-2023-36387Medium· 5.4Apache Superset has improper default REST API permission for Gamma users
Apache Superset has improper default REST API permission for Gamma users