VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5752 CVEsRSS

CVE-2021-41124High· 7.4
4y ago

Splash authentication credentials potentially leaked to target websites

Splash authentication credentials potentially leaked to target websites

▾ Twilightscrapy-splash · scrapy-splashEPSS 1.1%via OSV
CVE-2021-40325High· 7.5
4y ago

Cobbler before 3.3.0 allows authorization bypass for modification of settings.

Cobbler before 3.3.0 allows authorization bypass for modification of settings.

▾ Twilightcobbler · cobblerEPSS 1.4%via OSV
CVE-2021-40323Critical· 9.8PoC
4y ago

Cobbler before 3.3.0 allows log poisoning

Cobbler before 3.3.0 allows log poisoning

▾ Abyssalcobbler · cobblerEPSS 87%via OSV
CVE-2021-40324High· 7.5
4y ago

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

▾ Twilightcobbler · cobblerEPSS 69%via OSV
CVE-2021-39226High· 7.3CISA KEVPoC
4y ago

Authentication bypass for viewing and deletions of snapshots

Authentication bypass for viewing and deletions of snapshots

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 100%via OSV
CVE-2021-41103Medium· 5.9
4y ago

Insufficiently restricted permissions on plugin directories

Insufficiently restricted permissions on plugin directories

▾ Sunlitcontainerd · github.com/containerd/containerdEPSS 0.52%via OSV
CVE-2021-32619Critical· 9.8
5y ago

Deno's static imports inside dynamically imported modules do not adhere to permission checks

Deno's static imports inside dynamically imported modules do not adhere to permission checks

▾ Midnightdeno · denoEPSS 1.1%via OSV
CVE-2021-41088High· 8.0
5y ago

Elvish vulnerable to remote code execution via the web UI backend

Elvish vulnerable to remote code execution via the web UI backend

▾ Twilightelves · github.com/elves/elvishEPSS 0.54%via OSV
CVE-2021-41087Medium· 5.6
5y ago

Improperly Implemented path matching for in-toto-golang

Improperly Implemented path matching for in-toto-golang

▾ Sunlitin-toto · github.com/in-toto/in-toto-golangEPSS 0.43%via OSV
CVE-2020-8561Medium· 4.1
5y ago

Confused Deputy in Kubernetes

Confused Deputy in Kubernetes

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 2.1%via OSV
CVE-2021-39228Medium· 6.5
5y ago

Memory Safety Issue when using patch or merge on state and assign the result back to state

Memory Safety Issue when using patch or merge on state and assign the result back to state

▾ Sunlittremor-script · tremor-scriptEPSS 1.3%via OSV
CVE-2021-39229High· 7.5
5y ago

Apprise vulnerable to regex injection with IFTTT Plugin

Apprise vulnerable to regex injection with IFTTT Plugin

▾ Twilightapprise · appriseEPSS 1.9%via OSV
CVE-2021-39216Medium· 6.3
5y ago

Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime

Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime

▾ Sunlitwasmtime · wasmtimeEPSS 0.31%via OSV
CVE-2021-39214High· 8.1
5y ago

Lacking Protection against HTTP Request Smuggling in mitmproxy

Lacking Protection against HTTP Request Smuggling in mitmproxy

▾ Twilightmitmproxy · mitmproxyEPSS 1.1%via OSV
CVE-2021-24040High· 8.4PoC
5y ago

Deserialization of Untrusted Data in parlai

Deserialization of Untrusted Data in parlai

▾ Midnightparlai · parlaiEPSS 17%via OSV
CVE-2021-32839High· 7.5
5y ago

StripComments filter contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service)

StripComments filter contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service)

▾ Twilightsqlparse · sqlparseEPSS 2.3%via OSV
CVE-2021-38698Medium· 6.5
5y ago

HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access…

HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.

▾ Sunlithashicorp · github.com/hashicorp/consulEPSS 1.4%via OSV
CVE-2021-32805High· 7.2
5y ago

Flask-AppBuilder Open Redirect vulnerability

Flask-AppBuilder Open Redirect vulnerability

▾ Twilightflask-appbuilder · flask-appbuilderEPSS 0.70%via OSV
CVE-2021-32838High· 7.5
5y ago

Regular Expression Denial of Service in flask-restx

Regular Expression Denial of Service in flask-restx

▾ Twilightflask-restx · flask-restxEPSS 1.9%via OSV
CVE-2021-3761High· 7.5
5y ago

OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values

OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values

▾ Twilightcloudflare · github.com/cloudflare/cfrpkiEPSS 1.2%via OSV
CVE-2021-36156Medium· 5.3
5y ago

Path traversal in Grafana Loki

Path traversal in Grafana Loki

▾ Sunlitgrafana · github.com/grafana/lokiEPSS 1.5%via OSV
CVE-2021-39193Medium· 5.3
5y ago

Transaction validity oversight in pallet-ethereum

Transaction validity oversight in pallet-ethereum

▾ Sunlitpallet-ethereum · pallet-ethereumEPSS 1.2%via OSV
CVE-2021-39163Low· 3.1
5y ago

Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.

Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.90%via OSV
CVE-2021-39164Low· 3.1
5y ago

Improper authorisation of members discloses room membership to non-members

Improper authorisation of members discloses room membership to non-members

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.5%via OSV
CVE-2021-39156High· 8.1PoC
5y ago

Istio Fragments in Path May Lead to Authorization Policy Bypass

Istio Fragments in Path May Lead to Authorization Policy Bypass

▾ Midnightistio · istio.io/istioEPSS 1.2%via OSV
CVE-2021-39137Medium· 6.5
5y ago

Ethereum Contains Consensus Flaw During Block Processing

Ethereum Contains Consensus Flaw During Block Processing

▾ Sunlitethereum · github.com/ethereum/go-ethereumEPSS 1.3%via OSV
CVE-2021-39155High· 8.3
5y ago

Authorization Policy Bypass Due to Case Insensitive Host Comparison

Authorization Policy Bypass Due to Case Insensitive Host Comparison

▾ Twilightistio · istio.io/istioEPSS 1.2%via OSV
CVE-2021-32783High· 8.5
5y ago

ExternalName Services can be used to gain access to Envoy's admin interface

ExternalName Services can be used to gain access to Envoy's admin interface

▾ Twilightprojectcontour · github.com/projectcontour/contourEPSS 1.2%via OSV
CVE-2021-39160High· 8.8
5y ago

Code injection in nbgitpuller

Code injection in nbgitpuller

▾ Twilightnbgitpuller · nbgitpullerEPSS 1.7%via OSV
CVE-2021-39159Critical· 9.6
5y ago

remote code execution via git repo provider

remote code execution via git repo provider

▾ Midnightbinderhub · binderhubEPSS 1.9%via OSV
CVEs tagged “osv” — page 178 · VulnSea