Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2023-30613High· 7.7Unrestricted file upload in kiwi TCMS
Unrestricted file upload in kiwi TCMS
CVE-2023-30544None· 0.0kiwi TCMS has possibility for user to update email address to unverified one
kiwi TCMS has possibility for user to update email address to unverified one
CVE-2023-27524High· 8.9CISA KEVPoCApache superset missing check for default SECRET_KEY
Apache superset missing check for default SECRET_KEY
CVE-2023-30622Medium· 6.7A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation
A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation
CVE-2023-27525Medium· 4.3Apache Superset vulnerable to Improper Authorization
Apache Superset vulnerable to Improper Authorization
CVE-2023-2106High· 7.3Weak Password Requirements in calibreweb
Weak Password Requirements in calibreweb
CVE-2022-2525MediumImproper Restriction of Excessive Authentication Attempts in calibreweb
Improper Restriction of Excessive Authentication Attempts in calibreweb
CVE-2023-29013High· 7.5Traefik HTTP header parsing could cause a denial of service
Traefik HTTP header parsing could cause a denial of service
CVE-2023-29194Medium· 4.1vitess allows users to create keyspaces that can deny access to already existing keyspaces
vitess allows users to create keyspaces that can deny access to already existing keyspaces
CVE-2023-25392Medium· 5.9Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation
Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation
CVE-2023-29005High· 7.5Flask-AppBuilder Has No Rate Limiting on Login AUTH DB
Flask-AppBuilder Has No Rate Limiting on Login AUTH DB
CVE-2023-28710High· 7.5Apache Airflow Spark Provider vulnerable to improper input validation
Apache Airflow Spark Provider vulnerable to improper input validation
CVE-2023-28707High· 7.5Apache Airflow Drill Provider vulnerable to improper input validation
Apache Airflow Drill Provider vulnerable to improper input validation
CVE-2023-28842Medium· 6.8moby: Encrypted overlay network with a single endpoint is unauthenticated (CVE-2023-28842)
A vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inj…
CVE-2023-28836Medium· 6.4Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views
Wagtail vulnerable to stored Cross-site Scripting attack via ModelAdmin views
CVE-2023-28837Medium· 4.4Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files
Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files
CVE-2023-26112Low· 3.7configobj ReDoS exploitable by developer using values in a server-side configuration file
configobj ReDoS exploitable by developer using values in a server-side configuration file
CVE-2023-30620High· 7.5mindsdb arbitrary file write when extracting a remotely retrieved Tarball
mindsdb arbitrary file write when extracting a remotely retrieved Tarball
CVE-2023-27489High· 7.6Kiwi TCMS Stored Cross-site Scripting via SVG file
Kiwi TCMS Stored Cross-site Scripting via SVG file
CVE-2023-25661Medium· 6.5TensorFlow Denial of Service vulnerability
TensorFlow Denial of Service vulnerability
CVE-2023-0241Medium· 6.5pgAdmin 4 vulnerable to directory traversal
pgAdmin 4 vulnerable to directory traversal
GHSA-cpmr-mw4j-99r7High· 7.5Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/
Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/
CVE-2023-25669High· 7.5TensorFlow has Floating Point Exception in AvgPoolGrad with XLA
TensorFlow has Floating Point Exception in AvgPoolGrad with XLA
CVE-2023-25660High· 7.5TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`
TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`
CVE-2023-25671High· 7.5TensorFlow has segmentation fault in tfg-translate
TensorFlow has segmentation fault in tfg-translate
CVE-2023-25674High· 7.5TensorFlow has Null Pointer Error in RandomShuffle with XLA enable
TensorFlow has Null Pointer Error in RandomShuffle with XLA enable
CVE-2023-25667Medium· 6.5TensorFlow vulnerable to segfault when opening multiframe gif
TensorFlow vulnerable to segfault when opening multiframe gif
CVE-2023-25666High· 7.5TensorFlow has Floating Point Exception in AudioSpectrogram
TensorFlow has Floating Point Exception in AudioSpectrogram
CVE-2023-25801High· 8.0TensorFlow has double free in Fractional(Max/Avg)Pool
TensorFlow has double free in Fractional(Max/Avg)Pool
CVE-2023-25672High· 7.5TensorFlow has Null Pointer Error in LookupTableImportV2
TensorFlow has Null Pointer Error in LookupTableImportV2