Tagged “osv”
CVEs tagged osv, newest first.
5752 CVEsRSS
CVE-2021-41124High· 7.4Splash authentication credentials potentially leaked to target websites
Splash authentication credentials potentially leaked to target websites
CVE-2021-40325High· 7.5Cobbler before 3.3.0 allows authorization bypass for modification of settings.
Cobbler before 3.3.0 allows authorization bypass for modification of settings.
CVE-2021-40323Critical· 9.8PoCCobbler before 3.3.0 allows log poisoning
Cobbler before 3.3.0 allows log poisoning
CVE-2021-40324High· 7.5Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
CVE-2021-39226High· 7.3CISA KEVPoCAuthentication bypass for viewing and deletions of snapshots
Authentication bypass for viewing and deletions of snapshots
CVE-2021-41103Medium· 5.9Insufficiently restricted permissions on plugin directories
Insufficiently restricted permissions on plugin directories
CVE-2021-32619Critical· 9.8Deno's static imports inside dynamically imported modules do not adhere to permission checks
Deno's static imports inside dynamically imported modules do not adhere to permission checks
CVE-2021-41088High· 8.0Elvish vulnerable to remote code execution via the web UI backend
Elvish vulnerable to remote code execution via the web UI backend
CVE-2021-41087Medium· 5.6Improperly Implemented path matching for in-toto-golang
Improperly Implemented path matching for in-toto-golang
CVE-2020-8561Medium· 4.1Confused Deputy in Kubernetes
Confused Deputy in Kubernetes
CVE-2021-39228Medium· 6.5Memory Safety Issue when using patch or merge on state and assign the result back to state
Memory Safety Issue when using patch or merge on state and assign the result back to state
CVE-2021-39229High· 7.5Apprise vulnerable to regex injection with IFTTT Plugin
Apprise vulnerable to regex injection with IFTTT Plugin
CVE-2021-39216Medium· 6.3Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime
Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime
CVE-2021-39214High· 8.1Lacking Protection against HTTP Request Smuggling in mitmproxy
Lacking Protection against HTTP Request Smuggling in mitmproxy
CVE-2021-24040High· 8.4PoCDeserialization of Untrusted Data in parlai
Deserialization of Untrusted Data in parlai
CVE-2021-32839High· 7.5StripComments filter contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service)
StripComments filter contains a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service)
CVE-2021-38698Medium· 6.5HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access…
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.
CVE-2021-32805High· 7.2Flask-AppBuilder Open Redirect vulnerability
Flask-AppBuilder Open Redirect vulnerability
CVE-2021-32838High· 7.5Regular Expression Denial of Service in flask-restx
Regular Expression Denial of Service in flask-restx
CVE-2021-3761High· 7.5OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values
OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values
CVE-2021-36156Medium· 5.3Path traversal in Grafana Loki
Path traversal in Grafana Loki
CVE-2021-39193Medium· 5.3Transaction validity oversight in pallet-ethereum
Transaction validity oversight in pallet-ethereum
CVE-2021-39163Low· 3.1Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.
Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.
CVE-2021-39164Low· 3.1Improper authorisation of members discloses room membership to non-members
Improper authorisation of members discloses room membership to non-members
CVE-2021-39156High· 8.1PoCIstio Fragments in Path May Lead to Authorization Policy Bypass
Istio Fragments in Path May Lead to Authorization Policy Bypass
CVE-2021-39137Medium· 6.5Ethereum Contains Consensus Flaw During Block Processing
Ethereum Contains Consensus Flaw During Block Processing
CVE-2021-39155High· 8.3Authorization Policy Bypass Due to Case Insensitive Host Comparison
Authorization Policy Bypass Due to Case Insensitive Host Comparison
CVE-2021-32783High· 8.5ExternalName Services can be used to gain access to Envoy's admin interface
ExternalName Services can be used to gain access to Envoy's admin interface
CVE-2021-39160High· 8.8Code injection in nbgitpuller
Code injection in nbgitpuller
CVE-2021-39159Critical· 9.6remote code execution via git repo provider
remote code execution via git repo provider