Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2022-36633High· 8.8PoCImproper token validation leading to code execution in Teleport
Improper token validation leading to code execution in Teleport
CVE-2022-25304High· 7.5Uncontrolled Resource Consumption in asyncua and opcua
Uncontrolled Resource Consumption in asyncua and opcua
CVE-2022-1930Medium· 5.9Regular expression denial of service in eth-account
Regular expression denial of service in eth-account
CVE-2022-38362High· 8.8Remote code execution in Apache Airflow Docker's Provider
Remote code execution in Apache Airflow Docker's Provider
CVE-2022-2822Low· 3.7OctoPrint does not have rate limiting on the login page
OctoPrint does not have rate limiting on the login page
CVE-2022-35930High· 7.1PolicyController before 0.2.1 may bypass attestation verification
PolicyController before 0.2.1 may bypass attestation verification
CVE-2021-32862Medium· 5.4nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
CVE-2022-35920High· 8.3sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs
CVE-2022-37394Low· 3.3OpenStack Nova Changing vnic_type breaks compute service restart
OpenStack Nova Changing vnic_type breaks compute service restart
GO-2022-0379NoneType confusion in github.com/docker/distribution
Type confusion in github.com/docker/distribution
CVE-2022-34558Critical· 9.8WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execut…
WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.
CVE-2022-2514Medium· 6.1Fava time and filter parameters vulnerable to reflected Cross-site Scripting
Fava time and filter parameters vulnerable to reflected Cross-site Scripting
CVE-2022-24294High· 7.5Apache MXNet vulnerable to potential denial-of-service by excessive resource consumption
Apache MXNet vulnerable to potential denial-of-service by excessive resource consumption
CVE-2018-25045Medium· 6.1Django REST framework XSS Vulnerability
Django REST framework XSS Vulnerability
CVE-2022-25891High· 7.5Shoutrrr util package DoS via sending 2000, 4000, or 6000 character messages
Shoutrrr util package DoS via sending 2000, 4000, or 6000 character messages
CVE-2021-42343Critical· 9.8Workers for local Dask clusters mistakenly listened on public interfaces
Workers for local Dask clusters mistakenly listened on public interfaces
CVE-2022-31153Medium· 6.5OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli
OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli
CVE-2022-30187Medium· 4.7Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library
Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library
CVE-2021-37839Medium· 4.3Apache Superset allows authenticated users to access metadata they have no permission to
Apache Superset allows authenticated users to access metadata they have no permission to
CVE-2022-31836Critical· 9.8Path Traversal in Beego
Path Traversal in Beego
CVE-2022-31116High· 7.5Incorrect handling of invalid surrogate pair characters
Incorrect handling of invalid surrogate pair characters
CVE-2022-31117Medium· 5.9Potential double free of buffer during string decoding
Potential double free of buffer during string decoding
CVE-2022-33082High· 7.5PoCDenial of service in Open Policy Agent
Denial of service in Open Policy Agent
CVE-2022-33146Medium· 6.1Open redirect in web2py
Open redirect in web2py
CVE-2022-31604Critical· 9.8Unsafe deserialisation in the PKI implementation scheme of NVFlare
Unsafe deserialisation in the PKI implementation scheme of NVFlare
CVE-2022-31605Critical· 9.8Unsafe yaml deserialization in NVFlare
Unsafe yaml deserialization in NVFlare
CVE-2021-46823Medium· 6.5Denial of Service in python-ldap
Denial of Service in python-ldap
CVE-2022-2112High· 8.8CSV Injection in inventree
CSV Injection in inventree
CVE-2021-45707HighOut-of-bounds write in nix::unistd::getgrouplist
Out-of-bounds write in nix::unistd::getgrouplist
CVE-2022-25856High· 7.5Insecure path traversal in Git Trigger Source can lead to arbitrary file read
Insecure path traversal in Git Trigger Source can lead to arbitrary file read