Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2023-26052Low· 3.7Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions
Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions
CVE-2023-22462Medium· 6.4Grafana vulnerable to Stored Cross-site Scripting in Text plugin
Grafana vulnerable to Stored Cross-site Scripting in Text plugin
CVE-2023-0594High· 7.3grafana: cross site scripting (CVE-2023-0594)
A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known p…
CVE-2023-30797High· 7.5Lemur subject to insecure random generation
Lemur subject to insecure random generation
CVE-2023-22738Medium· 6.5vantage6 vulnerable to Improper Preservation of Permissions
vantage6 vulnerable to Improper Preservation of Permissions
CVE-2023-23929High· 8.8vantage6 refresh tokens do not expire
vantage6 refresh tokens do not expire
GHSA-mrrw-grhq-86gfMediumAscii (crate) allows out-of-bounds array indexing in safe code
Ascii (crate) allows out-of-bounds array indexing in safe code
CVE-2022-39228Medium· 6.5vantage6 vulnerable to Observable Response Discrepancy
vantage6 vulnerable to Observable Response Discrepancy
CVE-2023-25956High· 7.5Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information
Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information
CVE-2023-25692High· 7.5Apache Airflow Google Provider Improper Input Validation vulnerability
Apache Airflow Google Provider Improper Input Validation vulnerability
CVE-2023-25823Medium· 5.4Update share links to use FRP instead of SSH tunneling
Update share links to use FRP instead of SSH tunneling
CVE-2023-25656High· 7.5notation-go has excessive memory allocation on verification
notation-go has excessive memory allocation on verification
CVE-2023-23947Critical· 9.1Users with any cluster secret update access may update out-of-bounds cluster secrets
Users with any cluster secret update access may update out-of-bounds cluster secrets
CVE-2023-0860High· 7.5PoCImproper Restriction of Excessive Authentication Attempts in modoboa
Improper Restriction of Excessive Authentication Attempts in modoboa
CVE-2023-25153Medium· 5.5containerd: OCI image importer memory exhaustion (CVE-2023-25153)
A flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.
CVE-2023-25577High· 7.5High resource usage when parsing multipart form data with many fields
High resource usage when parsing multipart form data with many fields
CVE-2023-23934Low· 2.6Incorrect parsing of nameless cookies leads to __Host- cookies bypass
Incorrect parsing of nameless cookies leads to __Host- cookies bypass
CVE-2023-25171High· 7.5Denial of service vulnerability on Password reset page
Denial of service vulnerability on Password reset page
CVE-2023-25156High· 7.5No protection against brute-force attacks on login page
No protection against brute-force attacks on login page
CVE-2023-30798High· 7.5MultipartParser denial of service with too many fields or files
MultipartParser denial of service with too many fields or files
CVE-2023-23631High· 7.5IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics
IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics
CVE-2023-23626Medium· 5.9IPFS go-bitfield vulnerable to DoS via malformed size arguments
IPFS go-bitfield vulnerable to DoS via malformed size arguments
CVE-2023-24816Medium· 4.5IPython vulnerable to command injection via set_term_title
IPython vulnerable to command injection via set_term_title
GHSA-74fp-r6jw-h4mpHigh· 7.5Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
CVE-2023-25307High· 8.8mrpack-install vulnerable to path traversal with dependency
mrpack-install vulnerable to path traversal with dependency
CVE-2023-23931Medium· 6.5Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf
Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf
CVE-2023-0286High· 7.4openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)
A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability ma…
RUSTSEC-2023-0126NoneAliasing violation in `OrdSet` insertion
Aliasing violation in `OrdSet` insertion
CVE-2022-45786High· 8.1Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection
Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection
CVE-2022-39324Medium· 6.7grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)
A flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the "Open original dashboard" button.