VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2023-35934Medium· 6.1
3y ago

yt-dlp File Downloader cookie leak

yt-dlp File Downloader cookie leak

▾ Sunlityt-dlp · yt-dlpEPSS 1.0%via OSV
CVE-2023-25504Medium· 6.5
3y ago

Apache Superset Server-Side Request Forgery vulnerability

Apache Superset Server-Side Request Forgery vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 0.96%via OSV
CVE-2023-30776Medium· 6.5
3y ago

Apache Superset vulnerable to Exposure of Sensitive Information

Apache Superset vulnerable to Exposure of Sensitive Information

▾ Sunlitapache-superset · apache-supersetEPSS 2.1%via OSV
CVE-2023-32732Medium· 5.3
3y ago

gRPC connection termination issue

gRPC connection termination issue

▾ Sunlitgrpc · io.grpc:grpc-protobufEPSS 0.53%via OSV
CVE-2023-1428High· 7.5
3y ago

gRPC Reachable Assertion issue

gRPC Reachable Assertion issue

▾ Twilightgrpc · io.grpc:grpc-protobufEPSS 0.41%via OSV
CVE-2023-36188Critical· 9.8
3y ago

langchain vulnerable to arbitrary code execution

langchain vulnerable to arbitrary code execution

▾ Midnightlangchain · langchainEPSS 1.9%via OSV
CVE-2023-36458Medium· 6.3
3y ago

1Panel vulnerable to command injection when entering the container terminal

1Panel vulnerable to command injection when entering the container terminal

▾ Sunlit1Panel-dev · github.com/1Panel-dev/1PanelEPSS 2.3%via OSV
CVE-2023-34457Medium· 5.9
3y ago

MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form

MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form

▾ Sunlitmechanicalsoup · mechanicalsoupEPSS 1.1%via OSV
CVE-2023-36814High· 7.5
3y ago

Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module

Products.CMFCore unauthenticated denial of service and crash via unchecked use of input with Python's marshal module

▾ Twilightproducts-cmfcore · products-cmfcoreEPSS 0.72%via OSV
CVE-2023-36809High· 8.1
3y ago

Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox

Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox

▾ Twilightkiwitcms · kiwitcmsEPSS 0.69%via OSV
CVE-2023-32731High· 7.4
3y ago

Connection confusion in gRPC

Connection confusion in gRPC

▾ Twilightgrpc · io.grpc:grpc-protobufEPSS 0.50%via OSV
CVE-2023-37365Medium· 6.5
3y ago

hnswlib Double Free vulnerability

hnswlib Double Free vulnerability

▾ Sunlithnswlib · hnswlibEPSS 0.59%via OSV
CVE-2023-36810Medium· 6.2
3y ago

PyPDF2 quadratic runtime with malformed PDF missing xref marker

PyPDF2 quadratic runtime with malformed PDF missing xref marker

▾ Sunlitpypdf2 · pypdf2EPSS 0.63%via OSV
CVE-2023-36807Medium· 6.2
3y ago

PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects

PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects

▾ Sunlitpypdf2 · pypdf2EPSS 0.57%via OSV
CVE-2023-36464Medium· 6.2
3y ago

pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character

pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character

▾ Sunlitpypdf · pypdfEPSS 0.35%via OSV
CVE-2023-22886High· 8.8
3y ago

Apache Airflow JDBC Provider Improper Input Validation vulnerability

Apache Airflow JDBC Provider Improper Input Validation vulnerability

▾ Twilightapache-airflow-providers-jdbc · apache-airflow-providers-jdbcEPSS 1.5%via OSV
CVE-2023-35798Medium· 4.3
3y ago

Apache Airflow ODBC Provider, Apache Airflow MSSQL Provider Improper Input Validation vulnerability

Apache Airflow ODBC Provider, Apache Airflow MSSQL Provider Improper Input Validation vulnerability

▾ Sunlitapache-airflow-providers-odbc · apache-airflow-providers-odbcEPSS 1.3%via OSV
CVE-2023-34395High· 7.8
3y ago

Apache Airflow ODBC Provider Argument Injection vulnerability

Apache Airflow ODBC Provider Argument Injection vulnerability

▾ Twilightapache-airflow-providers-odbc · apache-airflow-providers-odbcEPSS 0.76%via OSV
GHSA-hj8m-9fhf-v7jpCritical· 10.0
3y ago

fief-server Server-Side Template Injection vulnerability

fief-server Server-Side Template Injection vulnerability

▾ Midnightfief-server · fief-servervia OSV
CVE-2023-35932High· 7.1
3y ago

jcvi vulnerable to Configuration Injection due to unsanitized user input

jcvi vulnerable to Configuration Injection due to unsanitized user input

▾ Twilightjcvi · jcviEPSS 1.9%via OSV
CVE-2023-3128Critical· 9.4PoC
3y ago

Grafana vulnerable to Authentication Bypass by Spoofing

Grafana vulnerable to Authentication Bypass by Spoofing

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 4.0%via OSV
CVE-2023-34758High· 8.1
3y ago

Silver vulnerable to MitM attack against implants due to a cryptography vulnerability

Silver vulnerable to MitM attack against implants due to a cryptography vulnerability

▾ Twilightbishopfox · github.com/bishopfox/sliverEPSS 0.59%via OSV
CVE-2023-34620High· 7.5
3y ago

hjson stack exhaustion vulnerability

hjson stack exhaustion vulnerability

▾ Twilighthjson · org.hjson:hjsonEPSS 0.78%via OSV
CVE-2023-2183Medium· 4.1
3y ago

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.0%via OSV
CVE-2023-34239High· 7.3
3y ago

Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs

Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs

▾ Twilightgradio · gradioEPSS 0.65%via OSV
CVE-2023-33967High· 8.2
3y ago

SQL injection when using MySQL/PostgreSQL data checking

SQL injection when using MySQL/PostgreSQL data checking

▾ Twilightmegaease · github.com/megaease/easeprobeEPSS 0.66%via OSV
CVE-2023-32682Medium· 5.4
3y ago

Synapse has improper checks for deactivated users during login

Synapse has improper checks for deactivated users during login

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.75%via OSV
CVE-2023-2801High· 7.5
3y ago

Grafana Missing Synchronization vulnerability

Grafana Missing Synchronization vulnerability

▾ Twilightgrafana · github.com/grafana/grafanaEPSS 0.74%via OSV
CVE-2023-22647Critical· 9.9
3y ago

Rancher vulnerable to Privilege Escalation via manipulation of Secrets

Rancher vulnerable to Privilege Escalation via manipulation of Secrets

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.71%via OSV
CVE-2020-10676High· 8.8
3y ago

Rancher users retain access after moving namespaces into projects they don't have access to

Rancher users retain access after moving namespaces into projects they don't have access to

▾ Twilightrancher · github.com/rancher/rancherEPSS 1.0%via OSV
CVEs tagged “osv” — page 148 · VulnSea