Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
MAL-2026-6758NoneMalicious code in httpprobe (PyPI)
Malicious code in httpprobe (PyPI)
MAL-2026-6754NoneMalicious code in yt-api-dlp (PyPI)
Malicious code in yt-api-dlp (PyPI)
MAL-2026-6753NoneMalicious code in schemavault (PyPI)
Malicious code in schemavault (PyPI)
MAL-2026-6752NoneMalicious code in confighub (PyPI)
Malicious code in confighub (PyPI)
MAL-2026-6751NoneMalicious code in bytekit (PyPI)
Malicious code in bytekit (PyPI)
MAL-2026-6750NoneMalicious code in procwire (PyPI)
Malicious code in procwire (PyPI)
MAL-2026-6749NoneMalicious code in ipa-user-collector (PyPI)
Malicious code in ipa-user-collector (PyPI)
MAL-2026-6748NoneMalicious code in haproxy-config-client (PyPI)
Malicious code in haproxy-config-client (PyPI)
CVE-2026-8147High· 8.1MLflow: trace API endpoints lack proper authorization validators
MLflow: trace API endpoints lack proper authorization validators
MAL-2026-6736NoneMalicious code in unreal-mladapter (PyPI)
Malicious code in unreal-mladapter (PyPI)
MAL-2026-6735NoneMalicious code in ue-python-tools (PyPI)
Malicious code in ue-python-tools (PyPI)
MAL-2026-6734NoneMalicious code in horde-python-client (PyPI)
Malicious code in horde-python-client (PyPI)
MAL-2026-6733NoneMalicious code in epic-build-scripts (PyPI)
Malicious code in epic-build-scripts (PyPI)
MAL-2026-6728NoneMalicious code in dt-validator (PyPI)
Malicious code in dt-validator (PyPI)
CVE-2026-49852Highjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
CVE-2026-63746Medium· 6.5SurrealDB: Graph traversal bypasses table SELECT permissions
SurrealDB: Graph traversal bypasses table SELECT permissions
CVE-2026-63760High· 7.5SurrealDB has Denial of Service in JSON parser due to nested objects
SurrealDB has Denial of Service in JSON parser due to nested objects
CVE-2026-63758Medium· 5.4SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
CVE-2026-63761Medium· 4.3SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
CVE-2026-63751Medium· 4.3SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
CVE-2026-63755Medium· 6.5SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
CVE-2026-63743Medium· 6.4SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
CVE-2026-63748Medium· 4.3SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
CVE-2026-12480Medium· 5.5Keras: HDF5 virtual datasets can disclose local files
Keras: HDF5 virtual datasets can disclose local files
CVE-2026-57516High· 8.8PoCRay < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader
Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_dec…
CVE-2026-49119NoneGradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticat…
Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory…
MAL-2026-6724Critical⚠ ExploitedMalicious code in starlette-healthcheck (PyPI)
Malicious code in starlette-healthcheck (PyPI)
MAL-2026-6711NoneMalicious code in twrap-tool (PyPI)
Malicious code in twrap-tool (PyPI)
CVE-2026-41053High· 8.8Rancher has over-inclusive team membership expansion in GitHub App authentication provider
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
CVE-2026-63430NonemXSS in ammonia via MathML `annotation-xml` encoding strip
mXSS in ammonia via MathML `annotation-xml` encoding strip