VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2023-0488Medium· 5.4
3y ago

Cross-site Scripting in pyload-ng

Cross-site Scripting in pyload-ng

▾ Sunlitpyload-ng · pyload-ngEPSS 0.83%via OSV
CVE-2023-0509High· 7.4
3y ago

Improper Certificate Validation in pyload-ng

Improper Certificate Validation in pyload-ng

▾ Twilightpyload-ng · pyload-ngEPSS 0.53%via OSV
CVE-2022-47951Medium· 5.7
3y ago

OpenStack Cinder, glance, and Nova vulnerable to Path Traversal

OpenStack Cinder, glance, and Nova vulnerable to Path Traversal

▾ Sunlitcinder · cinderEPSS 1.0%via OSV
CVE-2022-4510High· 7.8PoC
3y ago

Path traversal in binwalk

Path traversal in binwalk

▾ Midnightbinwalk · binwalkEPSS 22%via OSV
CVE-2023-22736High· 8.5
3y ago

Controller reconciles apps outside configured namespaces when sharding is enabled

Controller reconciles apps outside configured namespaces when sharding is enabled

▾ Twilightargoproj · github.com/argoproj/argo-cd/v2EPSS 0.78%via OSV
CVE-2023-23608Medium· 5.4
3y ago

Path traversal in spotipy

Path traversal in spotipy

▾ Sunlitspotipy · spotipyEPSS 0.66%via OSV
CVE-2023-0434Medium· 5.4
3y ago

Improper Input Validation in pyload-ng

Improper Input Validation in pyload-ng

▾ Sunlitpyload-ng · pyload-ngEPSS 0.82%via OSV
CVE-2022-47950Medium· 6.5
3y ago

OpenStack Swift XML external entities (XXE) Injection

OpenStack Swift XML external entities (XXE) Injection

▾ Sunlitswift · swiftEPSS 1.0%via OSV
CVE-2023-22298Medium· 6.1
3y ago

pgAdmin 4 Open Redirect vulnerability

pgAdmin 4 Open Redirect vulnerability

▾ Sunlitpgadmin4 · pgadmin4EPSS 0.92%via OSV
CVE-2022-43720Medium· 5.4
3y ago

Apache Superset vulnerable to Injection

Apache Superset vulnerable to Injection

▾ Sunlitapache-superset · apache-supersetEPSS 1.3%via OSV
CVE-2022-43721Medium· 5.4
3y ago

Apache Superset Open Redirect vulnerability

Apache Superset Open Redirect vulnerability

▾ Sunlitapache-superset · apache-supersetEPSS 1.0%via OSV
CVE-2022-41703Medium· 5.4
3y ago

Apache Superset's SQL Alchemy connector vulnerable to SQL Injection

Apache Superset's SQL Alchemy connector vulnerable to SQL Injection

▾ Sunlitapache-superset · apache-supersetEPSS 1.2%via OSV
CVE-2022-43717Medium· 5.4
3y ago

Apache Superset vulnerable to Cross-site Scripting

Apache Superset vulnerable to Cross-site Scripting

▾ Sunlitapache-superset · apache-supersetEPSS 1.3%via OSV
CVE-2022-45438Medium· 5.3
3y ago

Apache Superset has Improper Access Control

Apache Superset has Improper Access Control

▾ Sunlitapache-superset · apache-supersetEPSS 1.2%via OSV
CVE-2022-43718Medium· 5.4
3y ago

Apache Superset is vulnerable to Cross-Site Scripting (XSS)

Apache Superset is vulnerable to Cross-Site Scripting (XSS)

▾ Sunlitapache-superset · apache-supersetEPSS 1.1%via OSV
CVE-2022-43719High· 8.8
3y ago

Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints

Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints

▾ Twilightapache-superset · apache-supersetEPSS 0.57%via OSV
CVE-2022-41721High· 7.5
3y ago

x/net/http2/h2c: request smuggling (CVE-2022-41721)

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead read the b…

▾ TwilightRed Hat · OpenShift Service Mesh 2.1EPSS 1.8%via CSAF
CVE-2023-0227Medium· 6.5
3y ago

Pyload Insufficient Session Expiration vulnerability

Pyload Insufficient Session Expiration vulnerability

▾ Sunlitpyload-ng · pyload-ngEPSS 0.66%via OSV
CVE-2023-22492Medium· 5.9
3y ago

Zitadel RefreshToken invalidation vulnerability

Zitadel RefreshToken invalidation vulnerability

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.60%via OSV
CVE-2022-4885High· 7.5
3y ago

sviehb/jefferson vulnerable to path traversal

sviehb/jefferson vulnerable to path traversal

▾ Twilightjefferson · jeffersonEPSS 0.75%via OSV
CVE-2023-0055Medium· 5.3
3y ago

Pyload contains Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Pyload contains Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

▾ Sunlitpyload-ng · pyload-ngEPSS 0.44%via OSV
CVE-2023-0057Medium· 6.1
3y ago

pyLoad vulnerable to Improper Restriction of Rendered UI Layers or Frames

pyLoad vulnerable to Improper Restriction of Rendered UI Layers or Frames

▾ Sunlitpyload-ng · pyload-ngEPSS 0.46%via OSV
CVE-2022-2582Medium· 4.3
3y ago

AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field

AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field

▾ Sunlitaws · github.com/aws/aws-sdk-goEPSS 0.48%via OSV
CVE-2019-25091Medium· 5.3
3y ago

nsupdate.info has Sensitive Cookie Without 'HttpOnly' Flag

nsupdate.info has Sensitive Cookie Without 'HttpOnly' Flag

▾ Sunlitnsupdate · nsupdateEPSS 0.62%via OSV
CVE-2022-4729Medium· 5.4
3y ago

Graphite Web Cross-site Scripting vulnerability

Graphite Web Cross-site Scripting vulnerability

▾ Sunlitgraphite-web · graphite-webEPSS 0.74%via OSV
CVE-2022-4730Medium· 5.4
3y ago

Graphite Web Cross-site Scripting vulnerability

Graphite Web Cross-site Scripting vulnerability

▾ Sunlitgraphite-web · graphite-webEPSS 0.77%via OSV
CVE-2021-4287Medium· 6.5
3y ago

binwalk vulnerable to UNIX Symbolic Link (Symlink) Following

binwalk vulnerable to UNIX Symbolic Link (Symlink) Following

▾ Sunlitbinwalk · binwalkEPSS 1.9%via OSV
CVE-2022-4728Medium· 5.4
3y ago

Graphite Web Cross-site Scripting vulnerability

Graphite Web Cross-site Scripting vulnerability

▾ Sunlitgraphite-web · graphite-webEPSS 0.77%via OSV
CVE-2022-40897High· 7.5
3y ago

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

▾ Twilightsetuptools · setuptoolsEPSS 2.6%via OSV
CVE-2022-47633High· 8.1
3y ago

kyverno verifyImages rule bypass possible with malicious proxy/registry

kyverno verifyImages rule bypass possible with malicious proxy/registry

▾ Twilightkyverno · github.com/kyverno/kyvernoEPSS 0.96%via OSV
CVEs tagged “osv” — page 153 · VulnSea