VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2023-37896High· 7.5
3y ago

Nuclei Path Traversal vulnerability

Nuclei Path Traversal vulnerability

▾ Twilightprojectdiscovery · github.com/projectdiscovery/nuclei/v2EPSS 1.0%via OSV
CVE-2023-3766Medium· 5.9
3y ago

odoh-rs's Invalid Slice Split Results in Server Panic

odoh-rs's Invalid Slice Split Results in Server Panic

▾ Sunlitodoh-rs · odoh-rsEPSS 0.78%via OSV
CVE-2023-4138Medium· 4.2
3y ago

RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling

RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling

▾ Sunlitrdiffweb · rdiffwebEPSS 0.45%via OSV
CVE-2023-3978Medium· 6.1
3y ago

Improper rendering of text nodes in golang.org/x/net/html

Improper rendering of text nodes in golang.org/x/net/html

▾ Sunlitx · golang.org/x/netEPSS 0.85%via OSV
GHSA-jm77-qphf-c4w8Low
3y ago

pyca/cryptography's wheels include vulnerable OpenSSL

pyca/cryptography's wheels include vulnerable OpenSSL

▾ Sunlitcryptography · cryptographyvia OSV
CVE-2023-38200High· 7.5
3y ago

Keylime's registrar vulnerable to Denial-of-service attack via a single open connection

Keylime's registrar vulnerable to Denial-of-service attack via a single open connection

▾ Twilightkeylime · keylimeEPSS 1.4%via OSV
CVE-2023-38686Critical· 9.3
3y ago

Sydent does not verify email server certificates

Sydent does not verify email server certificates

▾ Midnightmatrix-sydent · matrix-sydentEPSS 0.27%via OSV
CVE-2023-37900Low· 3.4
3y ago

Denial of service from large image

Denial of service from large image

▾ Sunlitcrossplane · github.com/crossplane/crossplaneEPSS 0.62%via OSV
CVE-2023-38670Medium· 4.7
3y ago

Null pointer dereference in PaddlePaddle

Null pointer dereference in PaddlePaddle

▾ Sunlitpaddlepaddle · paddlepaddleEPSS 0.66%via OSV
CVE-2023-38671High· 8.3
3y ago

Heap buffer overflow in PaddlePaddle

Heap buffer overflow in PaddlePaddle

▾ Twilightpaddlepaddle · paddlepaddleEPSS 0.76%via OSV
CVE-2023-38672Medium· 4.7
3y ago

Float point exception (FPE) in paddlepaddle

Float point exception (FPE) in paddlepaddle

▾ Sunlitpaddlepaddle · paddlepaddleEPSS 0.74%via OSV
CVE-2023-38673Critical· 9.6
3y ago

Command injection in PaddlePaddle

Command injection in PaddlePaddle

▾ Midnightpaddlepaddle · paddlepaddleEPSS 2.3%via OSV
CVE-2023-38669High· 8.3
3y ago

Use after free in PaddlePaddle

Use after free in PaddlePaddle

▾ Twilightpaddlepaddle · paddlepaddleEPSS 0.77%via OSV
CVE-2023-37920High· 7.5
3y ago

Removal of e-Tugra root certificate

Removal of e-Tugra root certificate

▾ Twilightcertifi · certifiEPSS 0.57%via OSV
CVE-2023-36826High· 7.7
3y ago

Improper authorization on debug and artifact file downloads

Improper authorization on debug and artifact file downloads

▾ Twilightsentry · sentryEPSS 0.63%via OSV
CVE-2023-3637Medium· 6.5
3y ago

Denial of service in neutron

Denial of service in neutron

▾ Sunlitneutron · neutronEPSS 1.3%via OSV
CVE-2023-37916Medium· 6.5
3y ago

KubePi may leak password hash of any user

KubePi may leak password hash of any user

▾ SunlitKubeOperator · github.com/KubeOperator/kubepiEPSS 0.81%via OSV
CVE-2023-37917Critical· 9.1
3y ago

KubePi Privilege Escalation vulnerability

KubePi Privilege Escalation vulnerability

▾ MidnightKubeOperator · github.com/KubeOperator/kubepiEPSS 0.74%via OSV
CVE-2023-37918Medium· 6.8
3y ago

Dapr API token authentication bypass in HTTP endpoints

Dapr API token authentication bypass in HTTP endpoints

▾ Sunlitdapr · github.com/dapr/daprEPSS 1.4%via OSV
CVE-2023-37788High· 7.5
3y ago

goproxy Denial of Service vulnerability

goproxy Denial of Service vulnerability

▾ Twilightelazarl · github.com/elazarl/goproxyEPSS 0.98%via OSV
CVE-2023-37480Low· 2.7
3y ago

Fides Webserver Vulnerable to Zip Bomb File Uploads

Fides Webserver Vulnerable to Zip Bomb File Uploads

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.69%via OSV
CVE-2023-37481Low· 2.7
3y ago

Fides Webserver Vulnerable to SVG Bomb File Uploads

Fides Webserver Vulnerable to SVG Bomb File Uploads

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.70%via OSV
CVE-2023-34236High· 8.5
3y ago

Weave GitOps Terraform Controller Information Disclosure Vulnerability

Weave GitOps Terraform Controller Information Disclosure Vulnerability

▾ Twilightweaveworks · github.com/weaveworks/tf-controllerEPSS 0.96%via OSV
CVE-2023-37474High· 7.5PoC
3y ago

copyparty vulnerable to path traversal attack

copyparty vulnerable to path traversal attack

▾ Midnightcopyparty · copypartyEPSS 45%via OSV
CVE-2023-38325High· 7.5
3y ago

cryptography mishandles SSH certificates

cryptography mishandles SSH certificates

▾ Twilightcryptography · cryptographyEPSS 0.73%via OSV
CVE-2023-37415High· 8.8
3y ago

Apache Airflow Apache Hive Provider Improper Input Validation vulnerability

Apache Airflow Apache Hive Provider Improper Input Validation vulnerability

▾ Twilightapache-airflow-providers-apache-hive · apache-airflow-providers-apache-hiveEPSS 1.6%via OSV
GHSA-2w8w-qhg4-f78jMedium· 6.5
3y ago

A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queries

A stored XSS in jaeger UI might allow an attacker who controls a trace to perform arbitrary jaeger queries

▾ Sunlitjaegertracing · github.com/jaegertracing/jaegervia OSV
CVE-2023-37271High· 8.4
3y ago

RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape

RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape

▾ Twilightrestrictedpython · restrictedpythonEPSS 0.85%via OSV
CVE-2023-36827High· 7.5
3y ago

ethyca-fides Webserver API Path Traversal vulnerability

ethyca-fides Webserver API Path Traversal vulnerability

▾ Twilightethyca-fides · ethyca-fidesEPSS 1.5%via OSV
CVE-2023-36829Medium· 6.8
3y ago

Sentry CORS misconfiguration

Sentry CORS misconfiguration

▾ Sunlitsentry · sentryEPSS 0.67%via OSV
CVEs tagged “osv” — page 147 · VulnSea