VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2022-36633High· 8.8PoC
4y ago

Improper token validation leading to code execution in Teleport

Improper token validation leading to code execution in Teleport

▾ Midnightgravitational · github.com/gravitational/teleportEPSS 50%via OSV
CVE-2022-25304High· 7.5
4y ago

Uncontrolled Resource Consumption in asyncua and opcua

Uncontrolled Resource Consumption in asyncua and opcua

▾ Twilightasyncua · asyncuaEPSS 1.3%via OSV
CVE-2022-1930Medium· 5.9
4y ago

Regular expression denial of service in eth-account

Regular expression denial of service in eth-account

▾ Sunliteth-account · eth-accountEPSS 0.89%via OSV
CVE-2022-38362High· 8.8
4y ago

Remote code execution in Apache Airflow Docker's Provider

Remote code execution in Apache Airflow Docker's Provider

▾ Twilightapache-airflow-providers-docker · apache-airflow-providers-dockerEPSS 1.9%via OSV
CVE-2022-2822Low· 3.7
4y ago

OctoPrint does not have rate limiting on the login page

OctoPrint does not have rate limiting on the login page

▾ Sunlitoctoprint · octoprintEPSS 0.85%via OSV
CVE-2022-35930High· 7.1
4y ago

PolicyController before 0.2.1 may bypass attestation verification

PolicyController before 0.2.1 may bypass attestation verification

▾ Twilightsigstore · github.com/sigstore/policy-controllerEPSS 0.66%via OSV
CVE-2021-32862Medium· 5.4
4y ago

nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths

nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths

▾ Sunlitnbconvert · nbconvertEPSS 1.4%via OSV
CVE-2022-35920High· 8.3
4y ago

sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs

sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs

▾ Twilightsanic · sanicEPSS 1.2%via OSV
CVE-2022-37394Low· 3.3
4y ago

OpenStack Nova Changing vnic_type breaks compute service restart

OpenStack Nova Changing vnic_type breaks compute service restart

▾ Sunlitnova · novaEPSS 0.31%via OSV
GO-2022-0379None
4y ago

Type confusion in github.com/docker/distribution

Type confusion in github.com/docker/distribution

▾ Sunlitdocker · github.com/docker/distributionvia OSV
CVE-2022-34558Critical· 9.8
4y ago

WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execut…

WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.

▾ Midnightglobal-workqueue · global-workqueueEPSS 1.3%via OSV
CVE-2022-2514Medium· 6.1
4y ago

Fava time and filter parameters vulnerable to reflected Cross-site Scripting

Fava time and filter parameters vulnerable to reflected Cross-site Scripting

▾ Sunlitfava · favaEPSS 0.85%via OSV
CVE-2022-24294High· 7.5
4y ago

Apache MXNet vulnerable to potential denial-of-service by excessive resource consumption

Apache MXNet vulnerable to potential denial-of-service by excessive resource consumption

▾ Twilightmxnet · mxnetEPSS 1.8%via OSV
CVE-2018-25045Medium· 6.1
4y ago

Django REST framework XSS Vulnerability

Django REST framework XSS Vulnerability

▾ Sunlitdjango-rest-framework · django-rest-frameworkEPSS 0.76%via OSV
CVE-2022-25891High· 7.5
4y ago

Shoutrrr util package DoS via sending 2000, 4000, or 6000 character messages

Shoutrrr util package DoS via sending 2000, 4000, or 6000 character messages

▾ Twilightcontainrrr · github.com/containrrr/shoutrrrEPSS 1.6%via OSV
CVE-2021-42343Critical· 9.8
4y ago

Workers for local Dask clusters mistakenly listened on public interfaces

Workers for local Dask clusters mistakenly listened on public interfaces

▾ Midnightdistributed · distributedEPSS 3.0%via OSV
CVE-2022-31153Medium· 6.5
4y ago

OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli

OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli

▾ Sunlitopenzeppelin-cairo-contracts · openzeppelin-cairo-contractsEPSS 1.4%via OSV
CVE-2022-30187Medium· 4.7
4y ago

Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library

Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library

▾ SunlitAzure · Azure.Storage.QueuesEPSS 0.53%via OSV
CVE-2021-37839Medium· 4.3
4y ago

Apache Superset allows authenticated users to access metadata they have no permission to

Apache Superset allows authenticated users to access metadata they have no permission to

▾ Sunlitapache-superset · apache-supersetEPSS 1.4%via OSV
CVE-2022-31836Critical· 9.8
4y ago

Path Traversal in Beego

Path Traversal in Beego

▾ Midnightbeego · github.com/beego/beegoEPSS 1.7%via OSV
CVE-2022-31116High· 7.5
4y ago

Incorrect handling of invalid surrogate pair characters

Incorrect handling of invalid surrogate pair characters

▾ Twilightujson · ujsonEPSS 2.5%via OSV
CVE-2022-31117Medium· 5.9
4y ago

Potential double free of buffer during string decoding

Potential double free of buffer during string decoding

▾ Sunlitujson · ujsonEPSS 1.9%via OSV
CVE-2022-33082High· 7.5PoC
4y ago

Denial of service in Open Policy Agent

Denial of service in Open Policy Agent

▾ Midnightopen-policy-agent · github.com/open-policy-agent/opaEPSS 1.7%via OSV
CVE-2022-33146Medium· 6.1
4y ago

Open redirect in web2py

Open redirect in web2py

▾ Sunlitweb2py · web2pyEPSS 1.6%via OSV
CVE-2022-31604Critical· 9.8
4y ago

Unsafe deserialisation in the PKI implementation scheme of NVFlare

Unsafe deserialisation in the PKI implementation scheme of NVFlare

▾ Midnightnvflare · nvflareEPSS 2.1%via OSV
CVE-2022-31605Critical· 9.8
4y ago

Unsafe yaml deserialization in NVFlare

Unsafe yaml deserialization in NVFlare

▾ Midnightnvflare · nvflareEPSS 2.1%via OSV
CVE-2021-46823Medium· 6.5
4y ago

Denial of Service in python-ldap

Denial of Service in python-ldap

▾ Sunlitpython-ldap · python-ldapEPSS 1.9%via OSV
CVE-2022-2112High· 8.8
4y ago

CSV Injection in inventree

CSV Injection in inventree

▾ Twilightinventree · inventreeEPSS 1.3%via OSV
CVE-2021-45707High
4y ago

Out-of-bounds write in nix::unistd::getgrouplist

Out-of-bounds write in nix::unistd::getgrouplist

▾ Twilightnix · nixEPSS 1.7%via OSV
CVE-2022-25856High· 7.5
4y ago

Insecure path traversal in Git Trigger Source can lead to arbitrary file read

Insecure path traversal in Git Trigger Source can lead to arbitrary file read

▾ Twilightargoproj · github.com/argoproj/argo-eventsEPSS 1.9%via OSV
CVEs tagged “osv” — page 159 · VulnSea