VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

MAL-2026-6758None
2mo ago

Malicious code in httpprobe (PyPI)

Malicious code in httpprobe (PyPI)

▾ Sunlithttpprobe · httpprobevia OSV
MAL-2026-6754None
2mo ago

Malicious code in yt-api-dlp (PyPI)

Malicious code in yt-api-dlp (PyPI)

▾ Sunlityt-api-dlp · yt-api-dlpvia OSV
MAL-2026-6753None
2mo ago

Malicious code in schemavault (PyPI)

Malicious code in schemavault (PyPI)

▾ Sunlitschemavault · schemavaultvia OSV
MAL-2026-6752None
2mo ago

Malicious code in confighub (PyPI)

Malicious code in confighub (PyPI)

▾ Sunlitconfighub · confighubvia OSV
MAL-2026-6751None
2mo ago

Malicious code in bytekit (PyPI)

Malicious code in bytekit (PyPI)

▾ Sunlitbytekit · bytekitvia OSV
MAL-2026-6750None
2mo ago

Malicious code in procwire (PyPI)

Malicious code in procwire (PyPI)

▾ Sunlitprocwire · procwirevia OSV
MAL-2026-6749None
2mo ago

Malicious code in ipa-user-collector (PyPI)

Malicious code in ipa-user-collector (PyPI)

▾ Sunlitipa-user-collector · ipa-user-collectorvia OSV
MAL-2026-6748None
2mo ago

Malicious code in haproxy-config-client (PyPI)

Malicious code in haproxy-config-client (PyPI)

▾ Sunlithaproxy-config-client · haproxy-config-clientvia OSV
CVE-2026-8147High· 8.1
2mo ago

MLflow: trace API endpoints lack proper authorization validators

MLflow: trace API endpoints lack proper authorization validators

▾ Twilightmlflow · mlflowEPSS 0.55%via OSV
MAL-2026-6736None
2mo ago

Malicious code in unreal-mladapter (PyPI)

Malicious code in unreal-mladapter (PyPI)

▾ Sunlitunreal-mladapter · unreal-mladaptervia OSV
MAL-2026-6735None
2mo ago

Malicious code in ue-python-tools (PyPI)

Malicious code in ue-python-tools (PyPI)

▾ Sunlitue-python-tools · ue-python-toolsvia OSV
MAL-2026-6734None
2mo ago

Malicious code in horde-python-client (PyPI)

Malicious code in horde-python-client (PyPI)

▾ Sunlithorde-python-client · horde-python-clientvia OSV
MAL-2026-6733None
2mo ago

Malicious code in epic-build-scripts (PyPI)

Malicious code in epic-build-scripts (PyPI)

▾ Sunlitepic-build-scripts · epic-build-scriptsvia OSV
MAL-2026-6728None
2mo ago

Malicious code in dt-validator (PyPI)

Malicious code in dt-validator (PyPI)

▾ Sunlitdt-validator · dt-validatorvia OSV
CVE-2026-49852High
2mo ago

joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)

joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)

▾ Twilightjoserfc · joserfcEPSS 0.19%via OSV
CVE-2026-63746Medium· 6.5
3mo ago

SurrealDB: Graph traversal bypasses table SELECT permissions

SurrealDB: Graph traversal bypasses table SELECT permissions

▾ Sunlitsurrealdb · surrealdbEPSS 0.40%via OSV
CVE-2026-63760High· 7.5
3mo ago

SurrealDB has Denial of Service in JSON parser due to nested objects

SurrealDB has Denial of Service in JSON parser due to nested objects

▾ Twilightsurrealdb · surrealdbEPSS 0.52%via OSV
CVE-2026-63758Medium· 5.4
3mo ago

SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries

SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries

▾ Sunlitsurrealdb · surrealdbEPSS 0.31%via OSV
CVE-2026-63761Medium· 4.3
3mo ago

SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation

SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation

▾ Sunlitsurrealdb · surrealdbEPSS 0.28%via OSV
CVE-2026-63751Medium· 4.3
3mo ago

SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`

SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`

▾ Sunlitsurrealdb · surrealdbEPSS 0.29%via OSV
CVE-2026-63755Medium· 6.5
3mo ago

SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level

SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level

▾ Sunlitsurrealdb · surrealdbEPSS 0.36%via OSV
CVE-2026-63743Medium· 6.4
3mo ago

SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect

SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect

▾ Sunlitsurrealdb · surrealdbEPSS 0.25%via OSV
CVE-2026-63748Medium· 4.3
3mo ago

SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages

SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages

▾ Sunlitsurrealdb · surrealdbEPSS 0.33%via OSV
CVE-2026-12480Medium· 5.5
3mo ago

Keras: HDF5 virtual datasets can disclose local files

Keras: HDF5 virtual datasets can disclose local files

▾ Sunlitkeras · kerasEPSS 0.18%via OSV
CVE-2026-57516High· 8.8PoC
3mo ago

Ray < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_dec…

▾ MidnightAnyscale, Inc · RayEPSS 0.86%via CVEORG
CVE-2026-49119None
3mo ago

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticat…

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory…

▾ Sunlitgradio · gradioEPSS 0.93%via OSV
MAL-2026-6724Critical⚠ Exploited
3mo ago

Malicious code in starlette-healthcheck (PyPI)

Malicious code in starlette-healthcheck (PyPI)

▾ Abyssalstarlette-healthcheck · starlette-healthcheckvia OSV
MAL-2026-6711None
3mo ago

Malicious code in twrap-tool (PyPI)

Malicious code in twrap-tool (PyPI)

▾ Sunlittwrap-tool · twrap-toolvia OSV
CVE-2026-41053High· 8.8
3mo ago

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.52%via OSV
CVE-2026-63430None
3mo ago

mXSS in ammonia via MathML `annotation-xml` encoding strip

mXSS in ammonia via MathML `annotation-xml` encoding strip

▾ Sunlitammonia · ammoniavia OSV
CVEs tagged “osv” — page 45 · VulnSea