VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5752 CVEsRSS

CVE-2021-21423Medium· 6.8PoC
5y ago

Rebuild-bot workflow may allow unauthorised repository modifications

Rebuild-bot workflow may allow unauthorised repository modifications

▾ Twilightprojen · projenEPSS 1.4%via OSV
CVE-2021-21416Low· 3.7
5y ago

Potential sensitive information disclosed in error reports

Potential sensitive information disclosed in error reports

▾ Sunlitdjango-registration · django-registrationEPSS 0.41%via OSV
CVE-2021-21333Medium· 6.1
5y ago

HTML injection in email and account expiry notifications

HTML injection in email and account expiry notifications

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.4%via OSV
CVE-2021-21332Medium· 6.9
5y ago

Cross-site scripting (XSS) vulnerability in the password reset endpoint

Cross-site scripting (XSS) vulnerability in the password reset endpoint

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.2%via OSV
CVE-2021-21376Medium· 6.4
5y ago

OMERO.web exposes some unnecessary session information in the page

OMERO.web exposes some unnecessary session information in the page

▾ Sunlitomero-web · omero-webEPSS 1.5%via OSV
CVE-2021-21377Medium· 4.8
5y ago

OMERO webclient does not validate URL redirects on login or switching group.

OMERO webclient does not validate URL redirects on login or switching group.

▾ Sunlitomero-web · omero-webEPSS 0.83%via OSV
CVE-2021-28363Medium· 6.5
5y ago

Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection

Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection

▾ Sunliturllib3 · urllib3EPSS 2.1%via OSV
CVE-2021-21371Medium· 5.0
5y ago

Execution of untrusted code through config file

Execution of untrusted code through config file

▾ Sunlittenable-jira-cloud · tenable-jira-cloudEPSS 0.45%via OSV
CVE-2021-21360Medium· 5.3
5y ago

Exposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetup

Exposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetup

▾ Sunlitproducts-genericsetup · products-genericsetupEPSS 1.5%via OSV
CVE-2021-21336Medium· 6.5
5y ago

Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager

Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager

▾ Sunlitproducts-pluggableauthservice · products-pluggableauthserviceEPSS 1.5%via OSV
CVE-2021-21337Medium· 5.7PoC
5y ago

URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService

URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService

▾ Twilightproducts-pluggableauthservice · products-pluggableauthserviceEPSS 8.4%via OSV
CVE-2021-21274Medium· 4.3
5y ago

Denial of service attack via .well-known lookups

Denial of service attack via .well-known lookups

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 2.2%via OSV
CVE-2021-21273Low· 3.1
5y ago

Open redirects on some federation and push requests

Open redirects on some federation and push requests

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.8%via OSV
CVE-2021-21330Low· 3.1
5y ago

`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)

`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)

▾ Sunlitaiohttp · aiohttpEPSS 1.9%via OSV
CVE-2021-21240High· 7.5
5y ago

Regular Expression Denial of Service (REDoS) in httplib2

Regular Expression Denial of Service (REDoS) in httplib2

▾ Twilighthttplib2 · httplib2EPSS 3.6%via OSV
CVE-2021-23980Medium· 6.1
5y ago

Cross-site scripting in Bleach

Cross-site scripting in Bleach

▾ Sunlitbleach · bleachEPSS 0.48%via OSV
CVE-2021-21238Medium· 6.5
5y ago

SAML XML Signature wrapping in PySAML2

SAML XML Signature wrapping in PySAML2

▾ Sunlitpysaml2 · pysaml2EPSS 1.1%via OSV
CVE-2021-21239Medium· 6.5PoC
5y ago

Improper Verification of Cryptographic Signature in PySAML2

Improper Verification of Cryptographic Signature in PySAML2

▾ Twilightpysaml2 · pysaml2EPSS 1.3%via OSV
CVE-2021-25900Critical· 9.8
5y ago

Buffer overflow in SmallVec::insert_many

Buffer overflow in SmallVec::insert_many

▾ Midnightsmallvec · smallvecEPSS 1.7%via OSV
CVE-2021-21236High· 7.5
5y ago

Regular Expression Denial of Service in CairoSVG

Regular Expression Denial of Service in CairoSVG

▾ Twilightcairosvg · cairosvgEPSS 1.4%via OSV
CVE-2020-26263High· 7.5
5y ago

RSA weakness in tslite-ng

RSA weakness in tslite-ng

▾ Twilighttlslite-ng · tlslite-ngEPSS 1.5%via OSV
CVE-2020-26275Medium· 6.1
5y ago

Jupyter Server open redirect vulnerability

Jupyter Server open redirect vulnerability

▾ Sunlitjupyter-server · jupyter-serverEPSS 1.4%via OSV
CVE-2020-26268Medium· 4.4
5y ago

Write to immutable memory region in TensorFlow

Write to immutable memory region in TensorFlow

▾ Sunlittensorflow · tensorflowEPSS 0.21%via OSV
CVE-2020-26267Medium· 4.4
5y ago

Lack of validation in data format attributes in TensorFlow

Lack of validation in data format attributes in TensorFlow

▾ Sunlittensorflow · tensorflowEPSS 0.24%via OSV
CVE-2020-26266Medium· 4.4
5y ago

Uninitialized memory access in TensorFlow

Uninitialized memory access in TensorFlow

▾ Sunlittensorflow · tensorflowEPSS 0.26%via OSV
CVE-2020-26271Medium· 4.4
5y ago

Heap out of bounds access in MakeEdge in TensorFlow

Heap out of bounds access in MakeEdge in TensorFlow

▾ Sunlittensorflow · tensorflowEPSS 0.22%via OSV
CVE-2020-26270Medium· 4.4
5y ago

CHECK-fail in LSTM with zero-length input in TensorFlow

CHECK-fail in LSTM with zero-length input in TensorFlow

▾ Sunlittensorflow · tensorflowEPSS 0.17%via OSV
CVE-2020-26257Medium· 6.5
5y ago

Denial of service attack via incorrect parameters in Matrix Synapse

Denial of service attack via incorrect parameters in Matrix Synapse

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 2.4%via OSV
CVE-2020-26261High· 7.9
5y ago

user-readable api tokens in systemd units for JupyterHub

user-readable api tokens in systemd units for JupyterHub

▾ Twilightjupyterhub-systemdspawner · jupyterhub-systemdspawnerEPSS 0.48%via OSV
CVE-2020-26249High· 7.7
5y ago

Remote Code Execution (RCE) Exploit on Cross Site Scripting (XSS) Vulnerability

Remote Code Execution (RCE) Exploit on Cross Site Scripting (XSS) Vulnerability

▾ Twilightred-dashboard · red-dashboardEPSS 1.3%via OSV
CVEs tagged “osv” — page 188 · VulnSea