Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2022-43760High· 8.4Rancher UI has multiple Cross-Site Scripting (XSS) issues
Rancher UI has multiple Cross-Site Scripting (XSS) issues
CVE-2023-33977High· 8.1PoCkiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
CVE-2023-34091Medium· 6.5Kyverno resource with a deletionTimestamp may allow policy circumvention
Kyverno resource with a deletionTimestamp may allow policy circumvention
CVE-2023-33733High· 7.8PoCReportlab vulnerable to remote code execution
Reportlab vulnerable to remote code execution
CVE-2023-33964High· 8.6mx-chain-go does not treat invalid transaction with wrong username correctly
mx-chain-go does not treat invalid transaction with wrong username correctly
GHSA-5cpq-8wj7-hf2vLowVulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2023-2970Low· 3.5MindSpore vulnerable to memory corruption
MindSpore vulnerable to memory corruption
GHSA-hgv6-w7r3-w4qwMediumKyverno vulnerable due to usage of insecure cipher
Kyverno vulnerable due to usage of insecure cipher
CVE-2023-33191Medium· 4.6kyverno seccomp control can be circumvented
kyverno seccomp control can be circumvented
CVE-2023-32321Critical· 9.8Ckan remote code execution and private information access via crafted resource ids
Ckan remote code execution and private information access via crafted resource ids
CVE-2023-32698High· 7.1nfpm has incorrect default permissions
nfpm has incorrect default permissions
CVE-2021-25748Medium· 6.5Ingress-nginx `path` sanitization can be bypassed with newline character
Ingress-nginx `path` sanitization can be bypassed with newline character
CVE-2023-30851Medium· 5.3Potential HTTP policy bypass when using header rules in Cilium
Potential HTTP policy bypass when using header rules in Cilium
CVE-2023-33185Medium· 4.6Incorrect signature verification in django-ses
Incorrect signature verification in django-ses
CVE-2023-32681Medium· 6.1PoCUnintended leak of Proxy-Authorization header in requests
Unintended leak of Proxy-Authorization header in requests
CVE-2023-32686Medium· 5.4kiwitcms vulnerable to stored XSS via unrestricted files upload
kiwitcms vulnerable to stored XSS via unrestricted files upload
CVE-2023-29159Low· 3.7Starlette has Path Traversal vulnerability in StaticFiles
Starlette has Path Traversal vulnerability in StaticFiles
CVE-2023-32309High· 7.5PoCAny file can be included with the pymdown-snippets extension
Any file can be included with the pymdown-snippets extension
CVE-2023-32758High· 7.5git-url-parse Regular Expression Denial of Service
git-url-parse Regular Expression Denial of Service
CVE-2023-32082Low· 3.1etcd Key name can be accessed via LeaseTimeToLive API
etcd Key name can be accessed via LeaseTimeToLive API
CVE-2023-32059High· 7.5Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls
Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls
CVE-2023-32058High· 7.5Vyper vulnerable to integer overflow in loop
Vyper vulnerable to integer overflow in loop
CVE-2023-31146High· 7.5Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment
Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment
CVE-2023-1732Medium· 5.3Improper random reading in CIRCL
Improper random reading in CIRCL
CVE-2023-30837High· 7.5vyper vulnerable to storage allocator overflow
vyper vulnerable to storage allocator overflow
CVE-2023-30551High· 7.5Rekor's compressed archives can result in OOM conditions
Rekor's compressed archives can result in OOM conditions
CVE-2023-30861High· 7.5PoCFlask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
CVE-2022-37454Critical· 9.8Buffer overflow in sponge queue functions
Buffer overflow in sponge queue functions
CVE-2023-30629High· 7.5Incorrect success value returned in vyper
Incorrect success value returned in vyper
CVE-2023-22651Critical· 9.9Rancher Webhook is misconfigured during upgrade process
Rancher Webhook is misconfigured during upgrade process