VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5752 CVEsRSS

CVE-2020-5233Medium· 5.9
4y ago

The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect

The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect

▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxyEPSS 1.3%via OSV
CVE-2020-13845High· 7.5
4y ago

Execution Control List (ECL) Is Insecure in Singularity

Execution Control List (ECL) Is Insecure in Singularity

▾ Twilightsylabs · github.com/sylabs/singularityEPSS 0.52%via OSV
CVE-2020-13846High· 7.5
4y ago

"Verify All" Returns Success Despite Validation Failures in Singularity

"Verify All" Returns Success Despite Validation Failures in Singularity

▾ Twilightsylabs · github.com/sylabs/singularityEPSS 1.3%via OSV
CVE-2020-15091Medium· 6.5
4y ago

Denial of Service in TenderMint

Denial of Service in TenderMint

▾ Sunlittendermint · github.com/tendermint/tendermintEPSS 0.91%via OSV
CVE-2021-32637Critical· 10.0
4y ago

Authelia vulnerable to an authentication bypassed with malformed request URI on nginx

Authelia vulnerable to an authentication bypassed with malformed request URI on nginx

▾ Midnightauthelia · github.com/authelia/authelia/v4EPSS 1.9%via OSV
CVE-2020-5415High· 7.5
4y ago

GitLab auth uses full name instead of username as user ID, allowing impersonation

GitLab auth uses full name instead of username as user ID, allowing impersonation

▾ Twilightconcourse · github.com/concourse/concourseEPSS 1.2%via OSV
CVE-2020-4037Medium· 4.3
4y ago

Open Redirect in OAuth2 Proxy

Open Redirect in OAuth2 Proxy

▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxyEPSS 0.90%via OSV
CVE-2020-26290Critical· 9.8
4y ago

Authentication Bypass in dex

Authentication Bypass in dex

▾ Midnightdexidp · github.com/dexidp/dexEPSS 0.99%via OSV
CVE-2021-43837High· 8.4
4y ago

vault-cli contains possible RCE when reading user-defined data

vault-cli contains possible RCE when reading user-defined data

▾ Twilightvault-cli · vault-cliEPSS 5.0%via OSV
CVE-2021-39183High· 8.2
4y ago

Unsafe inline XSS in pasting DOM element into chat

Unsafe inline XSS in pasting DOM element into chat

▾ Twilightowncast · github.com/owncast/owncastEPSS 0.75%via OSV
CVE-2021-43818High· 8.2
4y ago

lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through

lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through

▾ Twilightlxml · lxmlEPSS 2.5%via OSV
CVE-2021-37941High· 7.8
4y ago

APM Java Agent Local Privilege Escalation

APM Java Agent Local Privilege Escalation

▾ Twilightelastic-apm · elastic-apmEPSS 0.21%via OSV
CVE-2021-41265High· 8.1
4y ago

Improper Authentication in Flask-AppBuilder

Improper Authentication in Flask-AppBuilder

▾ Twilightflask-appbuilder · flask-appbuilderEPSS 1.3%via OSV
CVE-2021-43811High· 7.8PoC
4y ago

Code injection via unsafe YAML loading

Code injection via unsafe YAML loading

▾ Midnightsockeye · sockeyeEPSS 2.4%via OSV
CVE-2021-41090Medium· 6.5
4y ago

Instance config inline secret exposure in Grafana

Instance config inline secret exposure in Grafana

▾ Sunlitgrafana · github.com/grafana/agentEPSS 0.74%via OSV
CVE-2021-43784Medium· 6.0
4y ago

Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC

Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC

▾ Sunlitopencontainers · github.com/opencontainers/runcEPSS 1.8%via OSV
CVE-2021-43781Medium· 6.4
4y ago

Permissions not properly checked in Invenio-Drafts-Resources

Permissions not properly checked in Invenio-Drafts-Resources

▾ Sunlitinvenio-drafts-resources · invenio-drafts-resourcesEPSS 0.68%via OSV
CVE-2019-14867High· 8.8
4y ago

Code injection in FreeIPA

Code injection in FreeIPA

▾ Twilightipa · ipaEPSS 7.4%via OSV
CVE-2021-43790High· 8.5
4y ago

Use After Free in lucet

Use After Free in lucet

▾ Twilightlucet-runtime · lucet-runtimeEPSS 1.6%via OSV
CVE-2021-44227High· 8.0
4y ago

mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover (CVE-2021-44227)

A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right type of user when performing admin operations and a token created by a regular user can be use…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v. 8.2)EPSS 0.76%via CSAF
CVE-2021-43775High· 8.6
4y ago

Arbitrary file reading vulnerability in Aim

Arbitrary file reading vulnerability in Aim

▾ Twilightaim · aimEPSS 1.9%via OSV
CVE-2021-41281High· 7.5
4y ago

Path traversal in Matrix Synapse

Path traversal in Matrix Synapse

▾ Twilightmatrix-synapse · matrix-synapseEPSS 1.6%via OSV
CVE-2021-41278Medium· 5.4PoC
4y ago

Broken encryption in EdgeX Foundry

Broken encryption in EdgeX Foundry

▾ Twilightedgexfoundry · github.com/edgexfoundry/app-functions-sdk-go/v2EPSS 0.32%via OSV
CVE-2021-41867Medium
4y ago

Information disclosure vulnerability in OnionShare

Information disclosure vulnerability in OnionShare

▾ Sunlitonionshare-cli · onionshare-cliEPSS 1.8%via OSV
GHSA-77vh-xpmg-72qhLow· 3.0
4y ago

Clarify `mediaType` handling

Clarify `mediaType` handling

▾ Sunlitopencontainers · github.com/opencontainers/image-specvia OSV
GHSA-5j5w-g665-5m35Low· 3.0
4y ago

Ambiguous OCI manifest parsing

Ambiguous OCI manifest parsing

▾ Sunlitcontainerd · github.com/containerd/containerdvia OSV
CVE-2021-41190Low· 3.0
4y ago

Clarify Content-Type handling

Clarify Content-Type handling

▾ Sunlitopencontainers · github.com/opencontainers/distribution-specEPSS 2.2%via OSV
CVE-2021-41254High· 8.8
4y ago

Privilege escalation to cluster admin on multi-tenant environments

Privilege escalation to cluster admin on multi-tenant environments

▾ Twilightfluxcd · github.com/fluxcd/kustomize-controllerEPSS 1.8%via OSV
CVE-2021-22565Medium· 6.5
4y ago

Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server

Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server

▾ Sunlitgoogle · github.com/google/exposure-notifications-verification-serverEPSS 0.43%via OSV
CVE-2021-3911Medium· 4.2
4y ago

Misconfigured IP address field in ROA leads to OctoRPKI crash

Misconfigured IP address field in ROA leads to OctoRPKI crash

▾ Sunlitcloudflare · github.com/cloudflare/cfrpkiEPSS 0.91%via OSV
CVEs tagged “osv” — page 174 · VulnSea