Tagged “osv”
CVEs tagged osv, newest first.
5752 CVEsRSS
CVE-2021-21423Medium· 6.8PoCRebuild-bot workflow may allow unauthorised repository modifications
Rebuild-bot workflow may allow unauthorised repository modifications
CVE-2021-21416Low· 3.7Potential sensitive information disclosed in error reports
Potential sensitive information disclosed in error reports
CVE-2021-21333Medium· 6.1HTML injection in email and account expiry notifications
HTML injection in email and account expiry notifications
CVE-2021-21332Medium· 6.9Cross-site scripting (XSS) vulnerability in the password reset endpoint
Cross-site scripting (XSS) vulnerability in the password reset endpoint
CVE-2021-21376Medium· 6.4OMERO.web exposes some unnecessary session information in the page
OMERO.web exposes some unnecessary session information in the page
CVE-2021-21377Medium· 4.8OMERO webclient does not validate URL redirects on login or switching group.
OMERO webclient does not validate URL redirects on login or switching group.
CVE-2021-28363Medium· 6.5Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
CVE-2021-21371Medium· 5.0Execution of untrusted code through config file
Execution of untrusted code through config file
CVE-2021-21360Medium· 5.3Exposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetup
Exposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetup
CVE-2021-21336Medium· 6.5Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager
Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager
CVE-2021-21337Medium· 5.7PoCURL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService
URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService
CVE-2021-21274Medium· 4.3Denial of service attack via .well-known lookups
Denial of service attack via .well-known lookups
CVE-2021-21273Low· 3.1Open redirects on some federation and push requests
Open redirects on some federation and push requests
CVE-2021-21330Low· 3.1`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)
`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)
CVE-2021-21240High· 7.5Regular Expression Denial of Service (REDoS) in httplib2
Regular Expression Denial of Service (REDoS) in httplib2
CVE-2021-23980Medium· 6.1Cross-site scripting in Bleach
Cross-site scripting in Bleach
CVE-2021-21238Medium· 6.5SAML XML Signature wrapping in PySAML2
SAML XML Signature wrapping in PySAML2
CVE-2021-21239Medium· 6.5PoCImproper Verification of Cryptographic Signature in PySAML2
Improper Verification of Cryptographic Signature in PySAML2
CVE-2021-25900Critical· 9.8Buffer overflow in SmallVec::insert_many
Buffer overflow in SmallVec::insert_many
CVE-2021-21236High· 7.5Regular Expression Denial of Service in CairoSVG
Regular Expression Denial of Service in CairoSVG
CVE-2020-26263High· 7.5RSA weakness in tslite-ng
RSA weakness in tslite-ng
CVE-2020-26275Medium· 6.1Jupyter Server open redirect vulnerability
Jupyter Server open redirect vulnerability
CVE-2020-26268Medium· 4.4Write to immutable memory region in TensorFlow
Write to immutable memory region in TensorFlow
CVE-2020-26267Medium· 4.4Lack of validation in data format attributes in TensorFlow
Lack of validation in data format attributes in TensorFlow
CVE-2020-26266Medium· 4.4Uninitialized memory access in TensorFlow
Uninitialized memory access in TensorFlow
CVE-2020-26271Medium· 4.4Heap out of bounds access in MakeEdge in TensorFlow
Heap out of bounds access in MakeEdge in TensorFlow
CVE-2020-26270Medium· 4.4CHECK-fail in LSTM with zero-length input in TensorFlow
CHECK-fail in LSTM with zero-length input in TensorFlow
CVE-2020-26257Medium· 6.5Denial of service attack via incorrect parameters in Matrix Synapse
Denial of service attack via incorrect parameters in Matrix Synapse
CVE-2020-26261High· 7.9user-readable api tokens in systemd units for JupyterHub
user-readable api tokens in systemd units for JupyterHub
CVE-2020-26249High· 7.7Remote Code Execution (RCE) Exploit on Cross Site Scripting (XSS) Vulnerability
Remote Code Execution (RCE) Exploit on Cross Site Scripting (XSS) Vulnerability