VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

MAL-2026-13683None
1mo ago

Malicious code in kotoraka (PyPI)

Malicious code in kotoraka (PyPI)

▾ Sunlitkotoraka · kotorakavia OSV
MAL-2026-13682None
1mo ago

Malicious code in btcflx (PyPI)

Malicious code in btcflx (PyPI)

▾ Sunlitbtcflx · btcflxvia OSV
MAL-2026-13681None
1mo ago

Malicious code in btcflip (PyPI)

Malicious code in btcflip (PyPI)

▾ Sunlitbtcflip · btcflipvia OSV
CVE-2026-12570Medium· 5.5
1mo ago

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving…

▾ Sunlitkeras · kerasEPSS 0.13%via NVD
MAL-2026-13667None
1mo ago

Malicious code in kotanku (PyPI)

Malicious code in kotanku (PyPI)

▾ Sunlitkotanku · kotankuvia OSV
CVE-2026-12372Low· 3.7
1mo ago

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, f…

▾ Sunlitnltk · nltkEPSS 0.31%via NVD
RUSTSEC-2026-0242None
1mo ago

Safe ErrorRegistry APIs can cause undefined behavior

Safe ErrorRegistry APIs can cause undefined behavior

▾ Sunlitdcrypt-api · dcrypt-apivia OSV
RUSTSEC-2026-0240None
1mo ago

Ed25519 identity public keys permit universal signature forgery

Ed25519 identity public keys permit universal signature forgery

▾ Sunlitdcrypt-sign · dcrypt-signvia OSV
RUSTSEC-2026-0239None
1mo ago

Streaming AEAD does not authenticate stream structure

Streaming AEAD does not authenticate stream structure

▾ Sunlitdcrypt-symmetric · dcrypt-symmetricvia OSV
RUSTSEC-2026-0238None
1mo ago

Low-level GCM ignores the operation nonce

Low-level GCM ignores the operation nonce

▾ Sunlitdcrypt-algorithms · dcrypt-algorithmsvia OSV
MAL-2026-13666None
1mo ago

Malicious code in cubesat-upstream-driver (PyPI)

Malicious code in cubesat-upstream-driver (PyPI)

▾ Sunlitcubesat-upstream-driver · cubesat-upstream-drivervia OSV
MAL-2026-13665None
1mo ago

Malicious code in riakcs (PyPI)

Malicious code in riakcs (PyPI)

▾ Sunlitriakcs · riakcsvia OSV
CVE-2026-76217Medium· 6.5
1mo ago

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

▾ Sunlitgitpython · gitpythonEPSS 0.41%via OSV
CVE-2026-45808High
1mo ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying cred…

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.43%via NVD
CVE-2026-46358Medium
1mo ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers …

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.21%via NVD
CVE-2026-46405Medium· 5.3
1mo ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization: Negotiate` header is supplied, the response is includes a `log…

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.62%via NVD
CVE-2026-71870Medium
1mo ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a fo…

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
MAL-2026-13619None
1mo ago

Malicious code in atlas-internal (PyPI)

Malicious code in atlas-internal (PyPI)

▾ Sunlitatlas-internal · atlas-internalvia OSV
MAL-2026-13607None
1mo ago

Malicious code in speed-hashes (PyPI)

Malicious code in speed-hashes (PyPI)

▾ Sunlitspeed-hashes · speed-hashesvia OSV
MAL-2026-13606None
1mo ago

Malicious code in cdktn-provider-azurerm (PyPI)

Malicious code in cdktn-provider-azurerm (PyPI)

▾ Sunlitcdktn-provider-azurerm · cdktn-provider-azurermvia OSV
MAL-2026-13490None
1mo ago

Malicious code in fast-hashes (PyPI)

Malicious code in fast-hashes (PyPI)

▾ Sunlitfast-hashes · fast-hashesvia OSV
MAL-2026-13489None
1mo ago

Malicious code in pydanticc (PyPI)

Malicious code in pydanticc (PyPI)

▾ Sunlitpydanticc · pydanticcvia OSV
MAL-2026-13488None
1mo ago

Malicious code in idnna (PyPI)

Malicious code in idnna (PyPI)

▾ Sunlitidnna · idnnavia OSV
MAL-2026-13487None
1mo ago

Malicious code in flasq (PyPI)

Malicious code in flasq (PyPI)

▾ Sunlitflasq · flasqvia OSV
MAL-2026-13486None
1mo ago

Malicious code in fastapii (PyPI)

Malicious code in fastapii (PyPI)

▾ Sunlitfastapii · fastapiivia OSV
CVE-2026-71852Medium
1mo ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font…

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
CVE-2026-48169High· 8.8
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key…

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.44%via NVD
RUSTSEC-2026-0246None
1mo ago

`sevenz-rust` is unmaintained

`sevenz-rust` is unmaintained

▾ Sunlitsevenz-rust · sevenz-rustvia OSV
RUSTSEC-2026-0245None
1mo ago

Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.

Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.

▾ Sunlitsevenz-rust · sevenz-rustvia OSV
RUSTSEC-2026-0244None
1mo ago

`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization

`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization

▾ Sunlitgettext-rs · gettext-rsvia OSV
CVEs tagged “osv” — page 31 · VulnSea