VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2023-26052Low· 3.7
3y ago

Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions

Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions

▾ Sunlitsaleor · saleorEPSS 0.76%via OSV
CVE-2023-22462Medium· 6.4
3y ago

Grafana vulnerable to Stored Cross-site Scripting in Text plugin

Grafana vulnerable to Stored Cross-site Scripting in Text plugin

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.6%via OSV
CVE-2023-0594High· 7.3
3y ago

grafana: cross site scripting (CVE-2023-0594)

A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known p…

▾ TwilightRed Hat · Red Hat Ceph Storage 5.3 ToolsEPSS 9.2%via CSAF
CVE-2023-30797High· 7.5
3y ago

Lemur subject to insecure random generation

Lemur subject to insecure random generation

▾ Twilightlemur · lemurEPSS 0.79%via OSV
CVE-2023-22738Medium· 6.5
3y ago

vantage6 vulnerable to Improper Preservation of Permissions

vantage6 vulnerable to Improper Preservation of Permissions

▾ Sunlitvantage6 · vantage6EPSS 0.38%via OSV
CVE-2023-23929High· 8.8
3y ago

vantage6 refresh tokens do not expire

vantage6 refresh tokens do not expire

▾ Twilightvantage6 · vantage6EPSS 0.57%via OSV
GHSA-mrrw-grhq-86gfMedium
3y ago

Ascii (crate) allows out-of-bounds array indexing in safe code

Ascii (crate) allows out-of-bounds array indexing in safe code

▾ Sunlitascii · asciivia OSV
CVE-2022-39228Medium· 6.5
3y ago

vantage6 vulnerable to Observable Response Discrepancy

vantage6 vulnerable to Observable Response Discrepancy

▾ Sunlitvantage6 · vantage6EPSS 0.60%via OSV
CVE-2023-25956High· 7.5
3y ago

Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information

Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information

▾ Twilightapache-airflow-providers-amazon · apache-airflow-providers-amazonEPSS 1.5%via OSV
CVE-2023-25692High· 7.5
3y ago

Apache Airflow Google Provider Improper Input Validation vulnerability

Apache Airflow Google Provider Improper Input Validation vulnerability

▾ Twilightapache-airflow-providers-google · apache-airflow-providers-googleEPSS 1.8%via OSV
CVE-2023-25823Medium· 5.4
3y ago

Update share links to use FRP instead of SSH tunneling

Update share links to use FRP instead of SSH tunneling

▾ Sunlitgradio · gradioEPSS 0.55%via OSV
CVE-2023-25656High· 7.5
3y ago

notation-go has excessive memory allocation on verification

notation-go has excessive memory allocation on verification

▾ Twilightnotaryproject · github.com/notaryproject/notation-goEPSS 0.44%via OSV
CVE-2023-23947Critical· 9.1
3y ago

Users with any cluster secret update access may update out-of-bounds cluster secrets

Users with any cluster secret update access may update out-of-bounds cluster secrets

▾ Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.67%via OSV
CVE-2023-0860High· 7.5PoC
3y ago

Improper Restriction of Excessive Authentication Attempts in modoboa

Improper Restriction of Excessive Authentication Attempts in modoboa

▾ Midnightmodoboa · modoboaEPSS 0.66%via OSV
CVE-2023-25153Medium· 5.5
3y ago

containerd: OCI image importer memory exhaustion (CVE-2023-25153)

A flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.

▾ SunlitRed Hat · Red Hat Ceph Storage 9.0 ToolsEPSS 0.36%via CSAF
CVE-2023-25577High· 7.5
3y ago

High resource usage when parsing multipart form data with many fields

High resource usage when parsing multipart form data with many fields

▾ Twilightwerkzeug · werkzeugEPSS 1.4%via OSV
CVE-2023-23934Low· 2.6
3y ago

Incorrect parsing of nameless cookies leads to __Host- cookies bypass

Incorrect parsing of nameless cookies leads to __Host- cookies bypass

▾ Sunlitwerkzeug · werkzeugEPSS 0.51%via OSV
CVE-2023-25171High· 7.5
3y ago

Denial of service vulnerability on Password reset page

Denial of service vulnerability on Password reset page

▾ Twilightkiwitcms · kiwitcmsEPSS 0.92%via OSV
CVE-2023-25156High· 7.5
3y ago

No protection against brute-force attacks on login page

No protection against brute-force attacks on login page

▾ Twilightkiwitcms · kiwitcmsEPSS 0.91%via OSV
CVE-2023-30798High· 7.5
3y ago

MultipartParser denial of service with too many fields or files

MultipartParser denial of service with too many fields or files

▾ Twilightstarlette · starletteEPSS 1.3%via OSV
CVE-2023-23631High· 7.5
3y ago

IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics

IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics

▾ Twilightipfs · github.com/ipfs/go-unixfsnodeEPSS 0.91%via OSV
CVE-2023-23626Medium· 5.9
3y ago

IPFS go-bitfield vulnerable to DoS via malformed size arguments

IPFS go-bitfield vulnerable to DoS via malformed size arguments

▾ Sunlitipfs · github.com/ipfs/go-bitfieldEPSS 0.91%via OSV
CVE-2023-24816Medium· 4.5
3y ago

IPython vulnerable to command injection via set_term_title

IPython vulnerable to command injection via set_term_title

▾ Sunlitipython · ipythonEPSS 1.3%via OSV
GHSA-74fp-r6jw-h4mpHigh· 7.5
3y ago

Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing

Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing

▾ Twilightapimachinery · k8s.io/apimachineryvia OSV
CVE-2023-25307High· 8.8
3y ago

mrpack-install vulnerable to path traversal with dependency

mrpack-install vulnerable to path traversal with dependency

▾ Twilightnothub · github.com/nothub/mrpack-installEPSS 0.60%via OSV
CVE-2023-23931Medium· 6.5
3y ago

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

▾ Sunlitcryptography · cryptographyEPSS 1.3%via OSV
CVE-2023-0286High· 7.4
3y ago

openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)

A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability ma…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 60%via CSAF
RUSTSEC-2023-0126None
3y ago

Aliasing violation in `OrdSet` insertion

Aliasing violation in `OrdSet` insertion

▾ Sunlitim · imvia OSV
CVE-2022-45786High· 8.1
3y ago

Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection

Apache AGE: Python and Golang drivers allow data manipulation and exposure due to SQL injection

▾ Twilightapache · github.com/apache/age/drivers/golangEPSS 0.96%via OSV
CVE-2022-39324Medium· 6.7
3y ago

grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)

A flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the "Open original dashboard" button.

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.83%via CSAF
CVEs tagged “osv” — page 152 · VulnSea