Tagged “osv”
CVEs tagged osv, newest first.
5752 CVEsRSS
CVE-2020-5233Medium· 5.9The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect
The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect
CVE-2020-13845High· 7.5Execution Control List (ECL) Is Insecure in Singularity
Execution Control List (ECL) Is Insecure in Singularity
CVE-2020-13846High· 7.5"Verify All" Returns Success Despite Validation Failures in Singularity
"Verify All" Returns Success Despite Validation Failures in Singularity
CVE-2020-15091Medium· 6.5Denial of Service in TenderMint
Denial of Service in TenderMint
CVE-2021-32637Critical· 10.0Authelia vulnerable to an authentication bypassed with malformed request URI on nginx
Authelia vulnerable to an authentication bypassed with malformed request URI on nginx
CVE-2020-5415High· 7.5GitLab auth uses full name instead of username as user ID, allowing impersonation
GitLab auth uses full name instead of username as user ID, allowing impersonation
CVE-2020-4037Medium· 4.3Open Redirect in OAuth2 Proxy
Open Redirect in OAuth2 Proxy
CVE-2020-26290Critical· 9.8Authentication Bypass in dex
Authentication Bypass in dex
CVE-2021-43837High· 8.4vault-cli contains possible RCE when reading user-defined data
vault-cli contains possible RCE when reading user-defined data
CVE-2021-39183High· 8.2Unsafe inline XSS in pasting DOM element into chat
Unsafe inline XSS in pasting DOM element into chat
CVE-2021-43818High· 8.2lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
CVE-2021-37941High· 7.8APM Java Agent Local Privilege Escalation
APM Java Agent Local Privilege Escalation
CVE-2021-41265High· 8.1Improper Authentication in Flask-AppBuilder
Improper Authentication in Flask-AppBuilder
CVE-2021-43811High· 7.8PoCCode injection via unsafe YAML loading
Code injection via unsafe YAML loading
CVE-2021-41090Medium· 6.5Instance config inline secret exposure in Grafana
Instance config inline secret exposure in Grafana
CVE-2021-43784Medium· 6.0Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC
Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC
CVE-2021-43781Medium· 6.4Permissions not properly checked in Invenio-Drafts-Resources
Permissions not properly checked in Invenio-Drafts-Resources
CVE-2019-14867High· 8.8Code injection in FreeIPA
Code injection in FreeIPA
CVE-2021-43790High· 8.5Use After Free in lucet
Use After Free in lucet
CVE-2021-44227High· 8.0mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover (CVE-2021-44227)
A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right type of user when performing admin operations and a token created by a regular user can be use…
CVE-2021-43775High· 8.6Arbitrary file reading vulnerability in Aim
Arbitrary file reading vulnerability in Aim
CVE-2021-41281High· 7.5Path traversal in Matrix Synapse
Path traversal in Matrix Synapse
CVE-2021-41278Medium· 5.4PoCBroken encryption in EdgeX Foundry
Broken encryption in EdgeX Foundry
CVE-2021-41867MediumInformation disclosure vulnerability in OnionShare
Information disclosure vulnerability in OnionShare
GHSA-77vh-xpmg-72qhLow· 3.0Clarify `mediaType` handling
Clarify `mediaType` handling
GHSA-5j5w-g665-5m35Low· 3.0Ambiguous OCI manifest parsing
Ambiguous OCI manifest parsing
CVE-2021-41190Low· 3.0Clarify Content-Type handling
Clarify Content-Type handling
CVE-2021-41254High· 8.8Privilege escalation to cluster admin on multi-tenant environments
Privilege escalation to cluster admin on multi-tenant environments
CVE-2021-22565Medium· 6.5Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server
Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server
CVE-2021-3911Medium· 4.2Misconfigured IP address field in ROA leads to OctoRPKI crash
Misconfigured IP address field in ROA leads to OctoRPKI crash