Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2023-0488Medium· 5.4Cross-site Scripting in pyload-ng
Cross-site Scripting in pyload-ng
CVE-2023-0509High· 7.4Improper Certificate Validation in pyload-ng
Improper Certificate Validation in pyload-ng
CVE-2022-47951Medium· 5.7OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
CVE-2022-4510High· 7.8PoCPath traversal in binwalk
Path traversal in binwalk
CVE-2023-22736High· 8.5Controller reconciles apps outside configured namespaces when sharding is enabled
Controller reconciles apps outside configured namespaces when sharding is enabled
CVE-2023-23608Medium· 5.4Path traversal in spotipy
Path traversal in spotipy
CVE-2023-0434Medium· 5.4Improper Input Validation in pyload-ng
Improper Input Validation in pyload-ng
CVE-2022-47950Medium· 6.5OpenStack Swift XML external entities (XXE) Injection
OpenStack Swift XML external entities (XXE) Injection
CVE-2023-22298Medium· 6.1pgAdmin 4 Open Redirect vulnerability
pgAdmin 4 Open Redirect vulnerability
CVE-2022-43720Medium· 5.4Apache Superset vulnerable to Injection
Apache Superset vulnerable to Injection
CVE-2022-43721Medium· 5.4Apache Superset Open Redirect vulnerability
Apache Superset Open Redirect vulnerability
CVE-2022-41703Medium· 5.4Apache Superset's SQL Alchemy connector vulnerable to SQL Injection
Apache Superset's SQL Alchemy connector vulnerable to SQL Injection
CVE-2022-43717Medium· 5.4Apache Superset vulnerable to Cross-site Scripting
Apache Superset vulnerable to Cross-site Scripting
CVE-2022-45438Medium· 5.3Apache Superset has Improper Access Control
Apache Superset has Improper Access Control
CVE-2022-43718Medium· 5.4Apache Superset is vulnerable to Cross-Site Scripting (XSS)
Apache Superset is vulnerable to Cross-Site Scripting (XSS)
CVE-2022-43719High· 8.8Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints
Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints
CVE-2022-41721High· 7.5x/net/http2/h2c: request smuggling (CVE-2022-41721)
A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead read the b…
CVE-2023-0227Medium· 6.5Pyload Insufficient Session Expiration vulnerability
Pyload Insufficient Session Expiration vulnerability
CVE-2023-22492Medium· 5.9Zitadel RefreshToken invalidation vulnerability
Zitadel RefreshToken invalidation vulnerability
CVE-2022-4885High· 7.5sviehb/jefferson vulnerable to path traversal
sviehb/jefferson vulnerable to path traversal
CVE-2023-0055Medium· 5.3Pyload contains Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Pyload contains Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2023-0057Medium· 6.1pyLoad vulnerable to Improper Restriction of Rendered UI Layers or Frames
pyLoad vulnerable to Improper Restriction of Rendered UI Layers or Frames
CVE-2022-2582Medium· 4.3AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field
AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field
CVE-2019-25091Medium· 5.3nsupdate.info has Sensitive Cookie Without 'HttpOnly' Flag
nsupdate.info has Sensitive Cookie Without 'HttpOnly' Flag
CVE-2022-4729Medium· 5.4Graphite Web Cross-site Scripting vulnerability
Graphite Web Cross-site Scripting vulnerability
CVE-2022-4730Medium· 5.4Graphite Web Cross-site Scripting vulnerability
Graphite Web Cross-site Scripting vulnerability
CVE-2021-4287Medium· 6.5binwalk vulnerable to UNIX Symbolic Link (Symlink) Following
binwalk vulnerable to UNIX Symbolic Link (Symlink) Following
CVE-2022-4728Medium· 5.4Graphite Web Cross-site Scripting vulnerability
Graphite Web Cross-site Scripting vulnerability
CVE-2022-40897High· 7.5pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)
pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2022-47633High· 8.1kyverno verifyImages rule bypass possible with malicious proxy/registry
kyverno verifyImages rule bypass possible with malicious proxy/registry