Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2023-32672Medium· 4.3Apache Superset has incorrect authorization check
Apache Superset has incorrect authorization check
CVE-2023-36388Medium· 4.3Apache Superset Server Side Request Forgery vulnerability
Apache Superset Server Side Request Forgery vulnerability
CVE-2023-28434High· 8.8CISA KEVPoCPrivilege Escalation on Linux/MacOS
Privilege Escalation on Linux/MacOS
CVE-2023-41052Medium· 5.3incorrect order of evaluation of side effects for some builtins
incorrect order of evaluation of side effects for some builtins
CVE-2023-41057Low· 3.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-it
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-it
CVE-2023-40590High· 7.8GitPython untrusted search path on Windows systems leading to arbitrary code execution
GitPython untrusted search path on Windows systems leading to arbitrary code execution
CVE-2023-39968Medium· 6.1Open Redirect Vulnerability in jupyter-server
Open Redirect Vulnerability in jupyter-server
CVE-2023-40170Medium· 4.6cross-site inclusion (XSSI) of files in jupyter-server
cross-site inclusion (XSSI) of files in jupyter-server
CVE-2023-27604High· 8.8Airflow Sqoop Provider RCE Vulnerability
Airflow Sqoop Provider RCE Vulnerability
CVE-2023-32079High· 8.8Netmaker Vulnerable to Privilege Escalation From Non Admin To Admin User
Netmaker Vulnerable to Privilege Escalation From Non Admin To Admin User
CVE-2023-32078High· 7.5Netmaker IDOR Allows User to Update Other User's Password
Netmaker IDOR Allows User to Update Other User's Password
CVE-2023-40587Medium· 5.3Pyramid static view path traversal up one directory
Pyramid static view path traversal up one directory
CVE-2023-39441Medium· 5.9Apache Airflow missing Certificate Validation
Apache Airflow missing Certificate Validation
CVE-2023-38976High· 7.5Weaviate denial of service vulnerability
Weaviate denial of service vulnerability
CVE-2023-39660Highpandasai vulnerable to prompt injection
pandasai vulnerable to prompt injection
CVE-2023-40272High· 7.5Apache Airflow Spark Provider Improper Input Validation vulnerability
Apache Airflow Spark Provider Improper Input Validation vulnerability
CVE-2023-40034High· 8.1Woodpecker does not validate webhook before changing any data
Woodpecker does not validate webhook before changing any data
CVE-2023-40024Medium· 6.1Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
CVE-2023-39553High· 7.5apache-airflow-providers-apache-drill Improper Input Validation vulnerability
apache-airflow-providers-apache-drill Improper Input Validation vulnerability
CVE-2023-27506Medium· 5.5Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow
Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow
CVE-2020-35141High· 7.5FaucetSDN Ryu Denial of Service Vulnerability
FaucetSDN Ryu Denial of Service Vulnerability
CVE-2020-35139High· 7.5FaucetSDN Ryu Denial of Service Vulnerability
FaucetSDN Ryu Denial of Service Vulnerability
CVE-2023-39965Medium· 6.51Panel Arbitrary File Download vulnerability
1Panel Arbitrary File Download vulnerability
CVE-2023-39363High· 8.7Vyper has incorrectly allocated named re-entrancy locks
Vyper has incorrectly allocated named re-entrancy locks
CVE-2023-3518High· 7.4Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
CVE-2023-4241High· 7.5lol-html panics on certain HTML inputs
lol-html panics on certain HTML inputs
CVE-2023-39531Medium· 6.5Sentry vulnerable to incorrect credential validation on OAuth token requests
Sentry vulnerable to incorrect credential validation on OAuth token requests
CVE-2023-33953High· 7.5Excessive Iteration in gRPC
Excessive Iteration in gRPC
CVE-2023-39523Medium· 6.8ScanCode.io command injection in docker image fetch process
ScanCode.io command injection in docker image fetch process
CVE-2023-39349High· 8.1Privilege escalation via ApiTokensEndpoint
Privilege escalation via ApiTokensEndpoint