VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5670 CVEsRSS

MAL-2026-15931Critical⚠ Exploited
3w ago

Malicious code in metricboxlite (PyPI)

Malicious code in metricboxlite (PyPI)

▾ Abyssalmetricboxlite · metricboxlitevia OSV
MAL-2026-15930None
3w ago

Malicious code in tpu-raiden-jax (PyPI)

Malicious code in tpu-raiden-jax (PyPI)

▾ Sunlittpu-raiden-jax · tpu-raiden-jaxvia OSV
MAL-2026-15929None
3w ago

Malicious code in pymaas (PyPI)

Malicious code in pymaas (PyPI)

▾ Sunlitpymaas · pymaasvia OSV
MAL-2026-15928None
3w ago

Malicious code in olympuslib (PyPI)

Malicious code in olympuslib (PyPI)

▾ Sunlitolympuslib · olympuslibvia OSV
MAL-2026-15927None
3w ago

Malicious code in qoeoe (PyPI)

Malicious code in qoeoe (PyPI)

▾ Sunlitqoeoe · qoeoevia OSV
MAL-2026-15926None
3w ago

Malicious code in astlsi (PyPI)

Malicious code in astlsi (PyPI)

▾ Sunlitastlsi · astlsivia OSV
MAL-2026-15910None
3w ago

Malicious code in timeweave (PyPI)

Malicious code in timeweave (PyPI)

▾ Sunlittimeweave · timeweavevia OSV
CVE-2026-68584High· 8.6
3w ago

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.53%via OSV
MAL-2026-15864Critical⚠ Exploited
3w ago

Malicious code in asti (PyPI)

Malicious code in asti (PyPI)

▾ Abyssalasti · astivia OSV
CVE-2026-72806Medium· 5.8
3w ago

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents with…

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.43%via OSV
CVE-2026-72800Medium· 5.8
3w ago

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeratio…

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via OSV
CVE-2026-68587High· 8.6
3w ago

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rende…

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.42%via OSV
CVE-2026-68586High· 8.6
3w ago

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-f…

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.41%via OSV
CVE-2026-69086High· 7.7
3w ago

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclo…

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.53%via OSV
CVE-2026-65607Medium· 6.5
3w ago

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.59%via OSV
CVE-2026-66394High· 8.7
3w ago

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.47%via OSV
MAL-2026-15863None
3w ago

Malicious code in uvhttp-custom (PyPI)

Malicious code in uvhttp-custom (PyPI)

▾ Sunlituvhttp-custom · uvhttp-customvia OSV
MAL-2026-15862None
3w ago

Malicious code in py-2equests (PyPI)

Malicious code in py-2equests (PyPI)

▾ Sunlitpy-2equests · py-2equestsvia OSV
MAL-2026-15861None
3w ago

Malicious code in py-1requests (PyPI)

Malicious code in py-1requests (PyPI)

▾ Sunlitpy-1requests · py-1requestsvia OSV
MAL-2026-15860None
3w ago

Malicious code in py-0requests (PyPI)

Malicious code in py-0requests (PyPI)

▾ Sunlitpy-0requests · py-0requestsvia OSV
MAL-2026-15859None
3w ago

Malicious code in 0requests (PyPI)

Malicious code in 0requests (PyPI)

▾ Sunlit0requests · 0requestsvia OSV
MAL-2026-15858None
3w ago

Malicious code in trongridi (PyPI)

Malicious code in trongridi (PyPI)

▾ Sunlittrongridi · trongridivia OSV
MAL-2026-15829None
3w ago

Malicious code in telemetry-helper (PyPI)

Malicious code in telemetry-helper (PyPI)

▾ Sunlittelemetry-helper · telemetry-helpervia OSV
MAL-2026-15828None
3w ago

Malicious code in env-validator-tool (PyPI)

Malicious code in env-validator-tool (PyPI)

▾ Sunlitenv-validator-tool · env-validator-toolvia OSV
MAL-2026-15827None
3w ago

Malicious code in company-sdk (PyPI)

Malicious code in company-sdk (PyPI)

▾ Sunlitcompany-sdk · company-sdkvia OSV
RUSTSEC-2026-0300None
3w ago

Use-after-free in `clear` and `retain` when an element's `Drop` panics

Use-after-free in `clear` and `retain` when an element's `Drop` panics

▾ Sunlitskiplist · skiplistvia OSV
CVE-2026-84452High
3w ago

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API…

▾ Twilightwinml-cli · winml-cliEPSS 1.6%via NVD
CVE-2026-84382High· 7.5
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bo…

▾ Twilighthttpx2 · httpx2EPSS 0.63%via NVD
CVE-2026-84380Medium· 5.6
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding h…

▾ Sunlithttpx2 · httpx2EPSS 0.36%via NVD
CVE-2026-84379Medium· 5.3
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-ele…

▾ Sunlithttpx2 · httpx2EPSS 0.45%via NVD
CVEs tagged “osv” — page 15 · VulnSea