VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

MAL-2026-6246None
3mo ago

Malicious code in d0rk3r (PyPI)

Malicious code in d0rk3r (PyPI)

▾ Sunlitd0rk3r · d0rk3rvia OSV
MAL-2026-6245None
3mo ago

Malicious code in request-cache-py (PyPI)

Malicious code in request-cache-py (PyPI)

▾ Sunlitrequest-cache-py · request-cache-pyvia OSV
MAL-2026-6236None
3mo ago

Malicious code in query-profile (PyPI)

Malicious code in query-profile (PyPI)

▾ Sunlitquery-profile · query-profilevia OSV
CVE-2026-63738Medium· 4.3
3mo ago

SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals

SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals

▾ Sunlitsurrealdb · surrealdbEPSS 0.28%via OSV
CVE-2026-27878Medium· 6.5
3mo ago

Grafana Tempo vulnerable to an out-of-memory crash

Grafana Tempo vulnerable to an out-of-memory crash

▾ Sunlitgrafana · github.com/grafana/tempoEPSS 0.41%via OSV
CVE-2026-66065High
3mo ago

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

▾ Twilightouroboros-ai · ouroboros-aiEPSS 0.24%via OSV
CVE-2026-58198Medium· 5.5
3mo ago

ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer

ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer

▾ Sunlitchatterbot · chatterbotEPSS 0.12%via OSV
CVE-2026-58501Medium· 5.9
3mo ago

Zeep: Server-Side Request Forgery (SSRF)

Zeep: Server-Side Request Forgery (SSRF)

▾ Sunlitzeep · zeepEPSS 0.41%via OSV
CVE-2026-58404High
3mo ago

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

▾ Twilightgohugoio · github.com/gohugoio/hugoEPSS 0.37%via OSV
CVE-2026-58402Medium
3mo ago

Hugo: XSS via unescaped code-fence language in default code block renderer

Hugo: XSS via unescaped code-fence language in default code block renderer

▾ Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.30%via OSV
CVE-2026-58403Medium
3mo ago

Hugo: Symlink confinement bypass in os.ReadFile

Hugo: Symlink confinement bypass in os.ReadFile

▾ Sunlitgohugoio · github.com/gohugoio/hugoEPSS 0.47%via OSV
CVE-2026-59152High· 7.7
3mo ago

LangSmith SDK TracingMiddleware: Arbitrary server-side file read

LangSmith SDK TracingMiddleware: Arbitrary server-side file read

▾ Twilightlangsmith · langsmithEPSS 0.20%via OSV
CVE-2026-58266Medium· 6.5
3mo ago

Anki: User scripts in iframes have access to the internal Anki API

Anki: User scripts in iframes have access to the internal Anki API

▾ Sunlitaqt · aqtEPSS 0.22%via OSV
CVE-2026-59153High
3mo ago

Anki's local HTTP server does not sufficiently validate requests

Anki's local HTTP server does not sufficiently validate requests

▾ Twilightaqt · aqtEPSS 0.26%via OSV
CVE-2026-58203Medium· 5.3
3mo ago

pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_m…

pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size

▾ Sunlitpydantic-settings · pydantic-settingsEPSS 0.18%via OSV
CVE-2026-55865Medium
3mo ago

Python Liquid: Infinite loop when parsing malformed `{% case %}` tags

Python Liquid: Infinite loop when parsing malformed `{% case %}` tags

▾ Sunlitpython-liquid · python-liquidEPSS 0.45%via OSV
CVE-2026-54911Medium· 6.5
3mo ago

UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()

UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()

▾ Sunlitujson · ujsonEPSS 0.37%via OSV
CVE-2026-54762High· 8.6
3mo ago

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

▾ Twilighttraefik · github.com/traefik/traefik/v3EPSS 0.43%via OSV
CVE-2026-55423Medium· 6.1
3mo ago

Langflow: Logout button does not clear session

Langflow: Logout button does not clear session

▾ Sunlitlangflow · langflowEPSS 0.22%via OSV
CVE-2026-57209High
3mo ago

Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode

Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode

▾ Twilightdadrus · github.com/dadrus/heimdallvia OSV
CVE-2026-57210High
3mo ago

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

▾ Twilighthttps: · https://github.com/dadrus/heimdallvia OSV
CVE-2026-57118Critical· 9.8
3mo ago

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

▾ Midnightpraisonaiagents · praisonaiagentsvia OSV
CVE-2026-57117High· 8.8
3mo ago

PraisonAI: Compute-bridged file tools allow shell command injection

PraisonAI: Compute-bridged file tools allow shell command injection

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-56838High· 7.8
3mo ago

PraisonAI recipe.run_stream skips dangerous-tool policy enforcement

PraisonAI recipe.run_stream skips dangerous-tool policy enforcement

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57114High· 7.2
3mo ago

PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding

PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57121High· 8.1
3mo ago

PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API

PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API

▾ Twilightpraisonai-platform · praisonai-platformvia OSV
CVE-2026-56835High· 8.3
3mo ago

PraisonAI Slack app_mention bypasses configured user/channel authorization

PraisonAI Slack app_mention bypasses configured user/channel authorization

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57146High· 7.5
3mo ago

PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default

PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-56834High· 7.5
3mo ago

PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage

PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57496Critical· 9.6
3mo ago

netlicensing-mcp: REST Path Traversal Bypasses Token Redaction

netlicensing-mcp: REST Path Traversal Bypasses Token Redaction

▾ Midnightnetlicensing-mcp · netlicensing-mcpvia OSV
CVEs tagged “osv” — page 48 · VulnSea