VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5634 CVEsRSS

CVE-2026-76819High· 8.6
5d ago

Rejected reason: Further research determined the issue results from a dependency.

Rejected reason: Further research determined the issue results from a dependency.

▾ Twilightprojectdiscovery · github.com/projectdiscovery/nuclei/v3via NVD
CVE-2026-85709Medium· 5.3PoC
5d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and l…

▾ TwilightHKUDS · LightRAGEPSS 0.39%via NVD
CVE-2026-85725Medium· 5.9PoC
5d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can return after th…

▾ TwilightHKUDS · LightRAGEPSS 0.36%via NVD
CVE-2026-85740High· 7.1
5d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying…

▾ TwilightHKUDS · LightRAGEPSS 0.22%via NVD
CVE-2026-85734Critical· 9.1
5d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication atte…

▾ MidnightHKUDS · LightRAGEPSS 0.36%via NVD
CVE-2026-86062Medium· 6.1PoC
5d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx renders answer and thinking content with react-markdown, rehypeRaw, and skipHtml=false without an H…

▾ TwilightHKUDS · LightRAGEPSS 0.25%via NVD
CVE-2026-76805Medium· 5.3
5d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that all…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.41%via NVD
CVE-2026-76804Medium· 5.5
5d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates referenced by a workflow. …

▾ Sunlitprojectdiscovery · nucleiEPSS 0.17%via NVD
CVE-2026-76803Medium· 5.3
5d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the allowAllFiles MySQL DSN opti…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.40%via NVD
CVE-2026-76802Medium· 4.7⚖ disputed
5d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzz…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.18%via NVD
CVE-2026-79913Medium· 6.5
5d ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP without decoding NAT64, IPv4-compatible…

▾ Sunlitcloudreve · cloudreveEPSS 0.40%via NVD
CVE-2026-77633High· 7.1
5d ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and later applies an unconditiona…

▾ Twilightcloudreve · cloudreveEPSS 0.37%via NVD
CVE-2026-77637Low· 3.8
5d ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in routers/router.go inherit ScopeAdminRead but omit the RequiredScopes(types.ScopeAdminWrite) middleware applied to n…

▾ Sunlitcloudreve · cloudreveEPSS 0.33%via NVD
CVE-2026-88010Medium· 6.3
5d ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewares/auth/basic_auth.go constructs the BasicAuth singleflight key from the submitted password and stored secret. Concur…

▾ Sunlittraefik · traefikEPSS 0.69%via NVD
CVE-2026-63374Critical· 9.3
5d ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library…

▾ Midnightagronholm · anyioEPSS 0.29%via NVD
RUSTSEC-2026-0304None
6d ago

Finished streaming calls keep reading a stalled request body indefinitely

Finished streaming calls keep reading a stalled request body indefinitely

▾ Sunlitconnectrpc · connectrpcvia OSV
MAL-2026-16366Critical⚠ Exploited
6d ago

Malicious code in pullgetsage (PyPI)

Malicious code in pullgetsage (PyPI)

▾ Abyssalpullgetsage · pullgetsagevia OSV
MAL-2026-16356Critical⚠ Exploited
6d ago

Malicious code in starlette-healthchecks (PyPI)

Malicious code in starlette-healthchecks (PyPI)

▾ Abyssalstarlette-healthchecks · starlette-healthchecksvia OSV
CVE-2026-61652High· 8.7
6d ago

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed compressed responses relying on the chunk size — explicit (`iter_bytes(chunk_size=…

▾ Twilightkap-sh · zaprosEPSS 0.44%via NVD
CVE-2026-61541Medium· 6.9
6d ago

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or follows a redirect to one, because a malicious response containing an excessive nu…

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or follows a redirect to one, because a malicious response containing an excessive nu…

▾ Sunlitkap-sh · zaprosEPSS 0.43%via NVD
GHSA-jhjp-4c2q-xmx4Medium· 4.3
6d ago

k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers

k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers

▾ Sunlitfalcosecurity · github.com/falcosecurity/plugins/plugins/k8sauditvia OSV
CVE-2026-62369High· 8.1
6d ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/comm…

▾ Twilightkubeedge · kubeedgeEPSS 0.86%via NVD
CVE-2026-62182High· 8.8
6d ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/config…

▾ Twilightkubeedge · kubeedgeEPSS 0.89%via NVD
CVE-2026-77561Medium· 5.3PoC
6d ago

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a globa…

▾ Twilighttinyauthapp · tinyauthEPSS 0.60%via NVD
CVE-2026-62866Medium· 6.2PoC
6d ago

Dasel is a command-line tool and library for querying, modifying, and transforming data structures

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across trailing whitespace and then reads the s…

▾ TwilightTomWright · daselEPSS 0.19%via NVD
CVE-2026-62371High· 8.8
6d ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actio…

▾ Twilightkubeedge · kubeedgeEPSS 0.89%via NVD
CVE-2026-62370Medium· 6.5
6d ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, Reader.Read in pkg/viaduct/pkg/packer trusts the 32-bit PackageHea…

▾ Sunlitkubeedge · kubeedgeEPSS 0.92%via NVD
CVE-2026-59168Medium· 6.2
6d ago

Dasel is a command-line tool and library for querying, modifying, and transforming data structures

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.1, parsing/json/json_reader.go decodeValue, decodeObject, and decodeArray, and parsing/xml/reader.go parseElement, …

▾ SunlitTomWright · daselEPSS 0.13%via NVD
CVE-2026-62987Medium· 5.8PoC
6d ago

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-…

▾ Twilightfabiolb · fabioEPSS 0.20%via NVD
CVE-2026-77582Medium· 6.9PoC
6d ago

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_contr…

▾ Twilighttinyauthapp · tinyauthEPSS 0.48%via NVD
CVEs tagged “osv” — page 4 · VulnSea