Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2023-37896High· 7.5Nuclei Path Traversal vulnerability
Nuclei Path Traversal vulnerability
CVE-2023-3766Medium· 5.9odoh-rs's Invalid Slice Split Results in Server Panic
odoh-rs's Invalid Slice Split Results in Server Panic
CVE-2023-4138Medium· 4.2RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling
RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2023-3978Medium· 6.1Improper rendering of text nodes in golang.org/x/net/html
Improper rendering of text nodes in golang.org/x/net/html
GHSA-jm77-qphf-c4w8Lowpyca/cryptography's wheels include vulnerable OpenSSL
pyca/cryptography's wheels include vulnerable OpenSSL
CVE-2023-38200High· 7.5Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
CVE-2023-38686Critical· 9.3Sydent does not verify email server certificates
Sydent does not verify email server certificates
CVE-2023-37900Low· 3.4Denial of service from large image
Denial of service from large image
CVE-2023-38670Medium· 4.7Null pointer dereference in PaddlePaddle
Null pointer dereference in PaddlePaddle
CVE-2023-38671High· 8.3Heap buffer overflow in PaddlePaddle
Heap buffer overflow in PaddlePaddle
CVE-2023-38672Medium· 4.7Float point exception (FPE) in paddlepaddle
Float point exception (FPE) in paddlepaddle
CVE-2023-38673Critical· 9.6Command injection in PaddlePaddle
Command injection in PaddlePaddle
CVE-2023-38669High· 8.3Use after free in PaddlePaddle
Use after free in PaddlePaddle
CVE-2023-37920High· 7.5Removal of e-Tugra root certificate
Removal of e-Tugra root certificate
CVE-2023-36826High· 7.7Improper authorization on debug and artifact file downloads
Improper authorization on debug and artifact file downloads
CVE-2023-3637Medium· 6.5Denial of service in neutron
Denial of service in neutron
CVE-2023-37916Medium· 6.5KubePi may leak password hash of any user
KubePi may leak password hash of any user
CVE-2023-37917Critical· 9.1KubePi Privilege Escalation vulnerability
KubePi Privilege Escalation vulnerability
CVE-2023-37918Medium· 6.8Dapr API token authentication bypass in HTTP endpoints
Dapr API token authentication bypass in HTTP endpoints
CVE-2023-37788High· 7.5goproxy Denial of Service vulnerability
goproxy Denial of Service vulnerability
CVE-2023-37480Low· 2.7Fides Webserver Vulnerable to Zip Bomb File Uploads
Fides Webserver Vulnerable to Zip Bomb File Uploads
CVE-2023-37481Low· 2.7Fides Webserver Vulnerable to SVG Bomb File Uploads
Fides Webserver Vulnerable to SVG Bomb File Uploads
CVE-2023-34236High· 8.5Weave GitOps Terraform Controller Information Disclosure Vulnerability
Weave GitOps Terraform Controller Information Disclosure Vulnerability
CVE-2023-37474High· 7.5PoCcopyparty vulnerable to path traversal attack
copyparty vulnerable to path traversal attack
CVE-2023-38325High· 7.5cryptography mishandles SSH certificates
cryptography mishandles SSH certificates
CVE-2023-37415High· 8.8Apache Airflow Apache Hive Provider Improper Input Validation vulnerability
Apache Airflow Apache Hive Provider Improper Input Validation vulnerability
GHSA-2w8w-qhg4-f78jMedium· 6.5A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queries
A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queries
CVE-2023-37271High· 8.4RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape
RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape
CVE-2023-36827High· 7.5ethyca-fides Webserver API Path Traversal vulnerability
ethyca-fides Webserver API Path Traversal vulnerability
CVE-2023-36829Medium· 6.8Sentry CORS misconfiguration
Sentry CORS misconfiguration