VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

MAL-2026-14584None
1mo ago

Malicious code in flyteplugins-redis (PyPI)

Malicious code in flyteplugins-redis (PyPI)

▾ Sunlitflyteplugins-redis · flyteplugins-redisvia OSV
MAL-2026-14583None
1mo ago

Malicious code in flyteplugins-nsight (PyPI)

Malicious code in flyteplugins-nsight (PyPI)

▾ Sunlitflyteplugins-nsight · flyteplugins-nsightvia OSV
MAL-2026-14582None
1mo ago

Malicious code in flyteplugins-echo (PyPI)

Malicious code in flyteplugins-echo (PyPI)

▾ Sunlitflyteplugins-echo · flyteplugins-echovia OSV
MAL-2026-14581None
1mo ago

Malicious code in flyteplugins-agento11y (PyPI)

Malicious code in flyteplugins-agento11y (PyPI)

▾ Sunlitflyteplugins-agento11y · flyteplugins-agento11yvia OSV
MAL-2026-14556None
1mo ago

Malicious code in sap-quarterly-report (PyPI)

Malicious code in sap-quarterly-report (PyPI)

▾ Sunlitsap-quarterly-report · sap-quarterly-reportvia OSV
MAL-2026-14555None
1mo ago

Malicious code in ekx-report-utils (PyPI)

Malicious code in ekx-report-utils (PyPI)

▾ Sunlitekx-report-utils · ekx-report-utilsvia OSV
MAL-2026-14554None
1mo ago

Malicious code in decoris (PyPI)

Malicious code in decoris (PyPI)

▾ Sunlitdecoris · decorisvia OSV
MAL-2026-14552None
1mo ago

Malicious code in mathkitlite (PyPI)

Malicious code in mathkitlite (PyPI)

▾ Sunlitmathkitlite · mathkitlitevia OSV
GHSA-mf7q-r4rv-jv94High
1mo ago

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature…

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check

▾ Twilightcrossplane · github.com/crossplane/crossplane-runtime/v2via OSV
RUSTSEC-2026-0284None
1mo ago

Double free in `Map::into_iter` and an uninitialized `Arc` in `SharedIncin::clear`

Double free in `Map::into_iter` and an uninitialized `Arc` in `SharedIncin::clear`

▾ Sunlitlockfree · lockfreevia OSV
CVE-2026-57171High· 7.7
1mo ago

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author comma…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.22%via NVD
RUSTSEC-2026-0277None
1mo ago

Path traversal in apimock-server's file-serving fallback

Path traversal in apimock-server's file-serving fallback

▾ Sunlitapimock-server · apimock-servervia OSV
RUSTSEC-2026-0276None
1mo ago

Path traversal in apimock's file-serving fallback

Path traversal in apimock's file-serving fallback

▾ Sunlitapimock · apimockvia OSV
CVE-2026-80205High· 7.5
1mo ago

nltk: NLTK: Denial of Service via unvalidated regular expressions (CVE-2026-80205)

A flaw was found in NLTK. A remote attacker can exploit a regular expression denial of service (ReDoS) vulnerability in the `Text.findall()` and `TokenSearcher.findall()` methods. These methods accept user-supplied regular expressions with…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.65%via CSAF
CVE-2026-79921High· 7.5
1mo ago

amqp091-go is a Go AMQP 0.9.1 client

amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead …

▾ Twilightrabbitmq · github.com/rabbitmq/amqp091-goEPSS 0.55%via NVD
CVE-2026-57170High· 7.8
1mo ago

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-par…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.24%via NVD
MAL-2026-14545Critical⚠ Exploited
1mo ago

Malicious code in pybitjs (PyPI)

Malicious code in pybitjs (PyPI)

▾ Abyssalpybitjs · pybitjsvia OSV
MAL-2026-14542None
1mo ago

Malicious code in trongridet (PyPI)

Malicious code in trongridet (PyPI)

▾ Sunlittrongridet · trongridetvia OSV
MAL-2026-14525None
1mo ago

Malicious code in 0xfighter3 (PyPI)

Malicious code in 0xfighter3 (PyPI)

▾ Sunlit0xfighter3 · 0xfighter3via OSV
MAL-2026-14524None
1mo ago

Malicious code in bigquery-agent-analytics-tracing (PyPI)

Malicious code in bigquery-agent-analytics-tracing (PyPI)

▾ Sunlitbigquery-agent-analytics-tracing · bigquery-agent-analytics-tracingvia OSV
MAL-2026-14523None
1mo ago

Malicious code in rce-test (PyPI)

Malicious code in rce-test (PyPI)

▾ Sunlitrce-test · rce-testvia OSV
MAL-2026-14522None
1mo ago

Malicious code in syntaxerror-package-12345 (PyPI)

Malicious code in syntaxerror-package-12345 (PyPI)

▾ Sunlitsyntaxerror-package-12345 · syntaxerror-package-12345via OSV
CVE-2026-54569Critical· 9.8
1mo ago

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite.core Vulnerable to Eval Injection and Missing Authorization

▾ Midnightsenaite-core · senaite-coreEPSS 1.2%via OSV
CVE-2026-54590Medium· 5.9
1mo ago

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakl…

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

▾ Sunlitasyncssh · asyncsshEPSS 0.39%via OSV
CVE-2026-54591High· 8.1
1mo ago

asyncssh has SCP Path Traversal to Arbitrary File Write

asyncssh has SCP Path Traversal to Arbitrary File Write

▾ Twilightasyncssh · asyncsshEPSS 0.49%via OSV
CVE-2026-54553Medium· 5.4
1mo ago

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

▾ Sunlitstarlette-admin · starlette-adminEPSS 0.45%via OSV
CVE-2026-54548Low· 3.3
1mo ago

kas Persistently Disables SSH Host Key Checking

kas Persistently Disables SSH Host Key Checking

▾ Sunlitkas · kasEPSS 0.11%via OSV
CVE-2026-78679Medium· 6.5
1mo ago

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arb…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.26%via NVD
CVE-2026-78678Medium· 6.5
1mo ago

gitpython: GitPython: Arbitrary file read via Repo.blame() (CVE-2026-78678)

A flaw was found in GitPython. An incomplete denylist in the `unsafe_git_revision_options` guard omits `--contents` and `-S` options. This allows an attacker to read arbitrary files by passing these options to the `Repo.blame()` function. …

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.41%via CSAF
CVE-2026-78677High· 7.5
1mo ago

GitPython: GitPython: Arbitrary Code Execution via Path Traversal (CVE-2026-78677)

A flaw was found in GitPython. This vulnerability allows a remote attacker to create arbitrary Git directories outside the intended clone destination. By manipulating the `separate_git_dir` parameter during repository cloning, an attacker …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.65%via CSAF
CVEs tagged “osv” — page 19 · VulnSea