Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2023-35934Medium· 6.1yt-dlp File Downloader cookie leak
yt-dlp File Downloader cookie leak
CVE-2023-25504Medium· 6.5Apache Superset Server-Side Request Forgery vulnerability
Apache Superset Server-Side Request Forgery vulnerability
CVE-2023-30776Medium· 6.5Apache Superset vulnerable to Exposure of Sensitive Information
Apache Superset vulnerable to Exposure of Sensitive Information
CVE-2023-32732Medium· 5.3gRPC connection termination issue
gRPC connection termination issue
CVE-2023-1428High· 7.5gRPC Reachable Assertion issue
gRPC Reachable Assertion issue
CVE-2023-36188Critical· 9.8langchain vulnerable to arbitrary code execution
langchain vulnerable to arbitrary code execution
CVE-2023-36458Medium· 6.31Panel vulnerable to command injection when entering the container terminal
1Panel vulnerable to command injection when entering the container terminal
CVE-2023-34457Medium· 5.9MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
CVE-2023-36814High· 7.5Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module
Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module
CVE-2023-36809High· 8.1Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
CVE-2023-32731High· 7.4Connection confusion in gRPC
Connection confusion in gRPC
CVE-2023-37365Medium· 6.5hnswlib Double Free vulnerability
hnswlib Double Free vulnerability
CVE-2023-36810Medium· 6.2PyPDF2 quadratic runtime with malformed PDF missing xref marker
PyPDF2 quadratic runtime with malformed PDF missing xref marker
CVE-2023-36807Medium· 6.2PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects
PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects
CVE-2023-36464Medium· 6.2pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character
pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character
CVE-2023-22886High· 8.8Apache Airflow JDBC Provider Improper Input Validation vulnerability
Apache Airflow JDBC Provider Improper Input Validation vulnerability
CVE-2023-35798Medium· 4.3Apache Airflow ODBC Provider, Apache Airflow MSSQL Provider Improper Input Validation vulnerability
Apache Airflow ODBC Provider, Apache Airflow MSSQL Provider Improper Input Validation vulnerability
CVE-2023-34395High· 7.8Apache Airflow ODBC Provider Argument Injection vulnerability
Apache Airflow ODBC Provider Argument Injection vulnerability
GHSA-hj8m-9fhf-v7jpCritical· 10.0fief-server Server-Side Template Injection vulnerability
fief-server Server-Side Template Injection vulnerability
CVE-2023-35932High· 7.1jcvi vulnerable to Configuration Injection due to unsanitized user input
jcvi vulnerable to Configuration Injection due to unsanitized user input
CVE-2023-3128Critical· 9.4PoCGrafana vulnerable to Authentication Bypass by Spoofing
Grafana vulnerable to Authentication Bypass by Spoofing
CVE-2023-34758High· 8.1Silver vulnerable to MitM attack against implants due to a cryptography vulnerability
Silver vulnerable to MitM attack against implants due to a cryptography vulnerability
CVE-2023-34620High· 7.5hjson stack exhaustion vulnerability
hjson stack exhaustion vulnerability
CVE-2023-2183Medium· 4.1Grafana has Broken Access Control in Alert manager: Viewer can send test alerts
Grafana has Broken Access Control in Alert manager: Viewer can send test alerts
CVE-2023-34239High· 7.3Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
CVE-2023-33967High· 8.2SQL injection when using MySQL/PostgreSQL data checking
SQL injection when using MySQL/PostgreSQL data checking
CVE-2023-32682Medium· 5.4Synapse has improper checks for deactivated users during login
Synapse has improper checks for deactivated users during login
CVE-2023-2801High· 7.5Grafana Missing Synchronization vulnerability
Grafana Missing Synchronization vulnerability
CVE-2023-22647Critical· 9.9Rancher vulnerable to Privilege Escalation via manipulation of Secrets
Rancher vulnerable to Privilege Escalation via manipulation of Secrets
CVE-2020-10676High· 8.8Rancher users retain access after moving namespaces into projects they don't have access to
Rancher users retain access after moving namespaces into projects they don't have access to