VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

MAL-2026-10484None
2mo ago

Malicious code in browser-use-headless (PyPI)

Malicious code in browser-use-headless (PyPI)

▾ Sunlitbrowser-use-headless · browser-use-headlessvia OSV
MAL-2026-10441None
2mo ago

Malicious code in turbocalcng (PyPI)

Malicious code in turbocalcng (PyPI)

▾ Sunlitturbocalcng · turbocalcngvia OSV
CVE-2026-56074Medium· 5.5
2mo ago

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

▾ Sunlitpraisonaiagents · praisonaiagentsEPSS 0.17%via OSV
CVE-2026-15529Medium· 6.3
2mo ago

A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2

A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The a…

▾ Sunlitpyod · pyodEPSS 0.44%via NVD
MAL-2026-10215None
2mo ago

Malicious code in fast-dotenv (PyPI)

Malicious code in fast-dotenv (PyPI)

▾ Sunlitfast-dotenv · fast-dotenvvia OSV
MAL-2026-10213None
2mo ago

Malicious code in pipspeed (PyPI)

Malicious code in pipspeed (PyPI)

▾ Sunlitpipspeed · pipspeedvia OSV
MAL-2026-10197None
2mo ago

Malicious code in metemask-sdk (PyPI)

Malicious code in metemask-sdk (PyPI)

▾ Sunlitmetemask-sdk · metemask-sdkvia OSV
MAL-2026-10196None
2mo ago

Malicious code in jupiter-sdk (PyPI)

Malicious code in jupiter-sdk (PyPI)

▾ Sunlitjupiter-sdk · jupiter-sdkvia OSV
MAL-2026-10195None
2mo ago

Malicious code in eth-agent (PyPI)

Malicious code in eth-agent (PyPI)

▾ Sunliteth-agent · eth-agentvia OSV
MAL-2026-10194None
2mo ago

Malicious code in solidity-dev (PyPI)

Malicious code in solidity-dev (PyPI)

▾ Sunlitsolidity-dev · solidity-devvia OSV
MAL-2026-10193None
2mo ago

Malicious code in py-base58 (PyPI)

Malicious code in py-base58 (PyPI)

▾ Sunlitpy-base58 · py-base58via OSV
MAL-2026-10192None
2mo ago

Malicious code in defi-tools (PyPI)

Malicious code in defi-tools (PyPI)

▾ Sunlitdefi-tools · defi-toolsvia OSV
MAL-2026-10191None
2mo ago

Malicious code in data-harvester (PyPI)

Malicious code in data-harvester (PyPI)

▾ Sunlitdata-harvester · data-harvestervia OSV
CVE-2026-56260Critical· 9.1
2mo ago

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supp…

▾ Midnightcrawl4ai · crawl4aiEPSS 0.65%via NVD
RUSTSEC-2026-0206None
2mo ago

`rustybuzz` is unmaintained

`rustybuzz` is unmaintained

▾ Sunlitrustybuzz · rustybuzzvia OSV
CVE-2026-56666Medium· 4.8
2mo ago

ZITADEL is an open source identity management platform

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the sam…

▾ Sunlitzitadel · zitadelEPSS 0.29%via NVD
CVE-2026-59162High· 7.5
2mo ago

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks only the upper bound before indexing the shared string slice,…

▾ Twilightexcelize · excelizeEPSS 0.66%via NVD
CVE-2026-59161High· 7.5
2mo ago

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows and GetRows does not enforce the TotalRows limit on the row r attribute, allowing a smal…

▾ Twilightexcelize · excelizeEPSS 0.66%via NVD
GHSA-wm45-qh3g-v83fHigh· 7.7
2mo ago

mcp-atlassian: Arbitrary server-side file read via attachment upload

mcp-atlassian: Arbitrary server-side file read via attachment upload

▾ Twilightmcp-atlassian · mcp-atlassianvia OSV
GHSA-489g-7rxv-6c8qMedium· 6.5
2mo ago

MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)

MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)

▾ Sunlitmcp-atlassian · mcp-atlassianvia OSV
MAL-2026-10139None
2mo ago

Malicious code in turbocalc (PyPI)

Malicious code in turbocalc (PyPI)

▾ Sunlitturbocalc · turbocalcvia OSV
MAL-2026-10119None
2mo ago

Malicious code in sankislayer (PyPI)

Malicious code in sankislayer (PyPI)

▾ Sunlitsankislayer · sankislayervia OSV
MAL-2026-10100None
2mo ago

Malicious code in proxy-check-i (PyPI)

Malicious code in proxy-check-i (PyPI)

▾ Sunlitproxy-check-i · proxy-check-ivia OSV
CVE-2026-49851High· 7.5
2mo ago

Mistune: Potential DoS via quadratic-time parsing in parse_link_text

Mistune: Potential DoS via quadratic-time parsing in parse_link_text

▾ Twilightmistune · mistuneEPSS 0.63%via OSV
MAL-2026-10091None
2mo ago

Malicious code in qlinforge (PyPI)

Malicious code in qlinforge (PyPI)

▾ Sunlitqlinforge · qlinforgevia OSV
MAL-2026-10020None
2mo ago

Malicious code in playwrightr (PyPI)

Malicious code in playwrightr (PyPI)

▾ Sunlitplaywrightr · playwrightrvia OSV
CVE-2026-49476High· 7.5
2mo ago

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

▾ Twilightsoupsieve · soupsieveEPSS 0.64%via OSV
CVE-2026-14967Low· 3.1
2mo ago

BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-contai…

BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the inten…

▾ Sunlitbbot · bbotEPSS 0.26%via OSV
CVE-2026-14966Low· 3.1
2mo ago

BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect sy…

BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy vers…

▾ Sunlitbbot · bbotEPSS 0.38%via OSV
RUSTSEC-2026-0220None
2mo ago

Uint shift operations: incorrect overflow flags and truncated shift amounts

Uint shift operations: incorrect overflow flags and truncated shift amounts

▾ Sunlitruint · ruintvia OSV
CVEs tagged “osv” — page 41 · VulnSea