VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2022-43760High· 8.4
3y ago

Rancher UI has multiple Cross-Site Scripting (XSS) issues

Rancher UI has multiple Cross-Site Scripting (XSS) issues

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.71%via OSV
CVE-2023-33977High· 8.1PoC
3y ago

kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload

kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload

▾ Midnightkiwitcms · kiwitcmsEPSS 0.87%via OSV
CVE-2023-34091Medium· 6.5
3y ago

Kyverno resource with a deletionTimestamp may allow policy circumvention

Kyverno resource with a deletionTimestamp may allow policy circumvention

▾ Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.50%via OSV
CVE-2023-33733High· 7.8PoC
3y ago

Reportlab vulnerable to remote code execution

Reportlab vulnerable to remote code execution

▾ Midnightreportlab · reportlabEPSS 2.1%via OSV
CVE-2023-33964High· 8.6
3y ago

mx-chain-go does not treat invalid transaction with wrong username correctly

mx-chain-go does not treat invalid transaction with wrong username correctly

▾ Twilightmultiversx · github.com/multiversx/mx-chain-goEPSS 0.57%via OSV
GHSA-5cpq-8wj7-hf2vLow
3y ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

▾ Sunlitcryptography · cryptographyvia OSV
CVE-2023-2970Low· 3.5
3y ago

MindSpore vulnerable to memory corruption

MindSpore vulnerable to memory corruption

▾ Sunlitmindspore · mindsporeEPSS 0.88%via OSV
GHSA-hgv6-w7r3-w4qwMedium
3y ago

Kyverno vulnerable due to usage of insecure cipher

Kyverno vulnerable due to usage of insecure cipher

▾ Sunlitkyverno · github.com/kyverno/kyvernovia OSV
CVE-2023-33191Medium· 4.6
3y ago

kyverno seccomp control can be circumvented

kyverno seccomp control can be circumvented

▾ Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.48%via OSV
CVE-2023-32321Critical· 9.8
3y ago

Ckan remote code execution and private information access via crafted resource ids

Ckan remote code execution and private information access via crafted resource ids

▾ Midnightckan · ckanEPSS 1.7%via OSV
CVE-2023-32698High· 7.1
3y ago

nfpm has incorrect default permissions

nfpm has incorrect default permissions

▾ Twilightgoreleaser · github.com/goreleaser/nfpm/v2EPSS 0.38%via OSV
CVE-2021-25748Medium· 6.5
3y ago

Ingress-nginx `path` sanitization can be bypassed with newline character

Ingress-nginx `path` sanitization can be bypassed with newline character

▾ Sunlitingress-nginx · k8s.io/ingress-nginxEPSS 0.69%via OSV
CVE-2023-30851Medium· 5.3
3y ago

Potential HTTP policy bypass when using header rules in Cilium

Potential HTTP policy bypass when using header rules in Cilium

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.66%via OSV
CVE-2023-33185Medium· 4.6
3y ago

Incorrect signature verification in django-ses

Incorrect signature verification in django-ses

▾ Sunlitdjango-ses · django-sesEPSS 0.23%via OSV
CVE-2023-32681Medium· 6.1PoC
3y ago

Unintended leak of Proxy-Authorization header in requests

Unintended leak of Proxy-Authorization header in requests

▾ Twilightrequests · requestsEPSS 3.0%via OSV
CVE-2023-32686Medium· 5.4
3y ago

kiwitcms vulnerable to stored XSS via unrestricted files upload

kiwitcms vulnerable to stored XSS via unrestricted files upload

▾ Sunlitkiwitcms · kiwitcmsEPSS 0.43%via OSV
CVE-2023-29159Low· 3.7
3y ago

Starlette has Path Traversal vulnerability in StaticFiles

Starlette has Path Traversal vulnerability in StaticFiles

▾ Sunlitstarlette · starletteEPSS 2.0%via OSV
CVE-2023-32309High· 7.5PoC
3y ago

Any file can be included with the pymdown-snippets extension

Any file can be included with the pymdown-snippets extension

▾ Midnightpymdown-extensions · pymdown-extensionsEPSS 1.7%via OSV
CVE-2023-32758High· 7.5
3y ago

git-url-parse Regular Expression Denial of Service

git-url-parse Regular Expression Denial of Service

▾ Twilightgit-url-parse · git-url-parseEPSS 1.0%via OSV
CVE-2023-32082Low· 3.1
3y ago

etcd Key name can be accessed via LeaseTimeToLive API

etcd Key name can be accessed via LeaseTimeToLive API

▾ Sunlitetcd-io · github.com/etcd-io/etcdEPSS 0.74%via OSV
CVE-2023-32059High· 7.5
3y ago

Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls

Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls

▾ Twilightvyper · vyperEPSS 0.73%via OSV
CVE-2023-32058High· 7.5
3y ago

Vyper vulnerable to integer overflow in loop

Vyper vulnerable to integer overflow in loop

▾ Twilightvyper · vyperEPSS 0.91%via OSV
CVE-2023-31146High· 7.5
3y ago

Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment

Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment

▾ Twilightvyper · vyperEPSS 1.2%via OSV
CVE-2023-1732Medium· 5.3
3y ago

Improper random reading in CIRCL

Improper random reading in CIRCL

▾ Sunlitcloudflare · github.com/cloudflare/circlEPSS 0.39%via OSV
CVE-2023-30837High· 7.5
3y ago

vyper vulnerable to storage allocator overflow

vyper vulnerable to storage allocator overflow

▾ Twilightvyper · vyperEPSS 0.70%via OSV
CVE-2023-30551High· 7.5
3y ago

Rekor's compressed archives can result in OOM conditions

Rekor's compressed archives can result in OOM conditions

▾ Twilightsigstore · github.com/sigstore/rekorEPSS 1.1%via OSV
CVE-2023-30861High· 7.5PoC
3y ago

Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header

Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header

▾ Midnightflask · flaskEPSS 1.3%via OSV
CVE-2022-37454Critical· 9.8
3y ago

Buffer overflow in sponge queue functions

Buffer overflow in sponge queue functions

▾ Midnightpysha3 · pysha3EPSS 5.8%via OSV
CVE-2023-30629High· 7.5
3y ago

Incorrect success value returned in vyper

Incorrect success value returned in vyper

▾ Twilightvyper · vyperEPSS 0.88%via OSV
CVE-2023-22651Critical· 9.9
3y ago

Rancher Webhook is misconfigured during upgrade process

Rancher Webhook is misconfigured during upgrade process

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.78%via OSV
CVEs tagged “osv” — page 149 · VulnSea