Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-25700High· 7.2Apache Answer: AdminToken not invalidated after admin deactivation
Apache Answer: AdminToken not invalidated after admin deactivation
CVE-2026-53474Critical· 9.6Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
CVE-2026-53475Critical· 9.3Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
CVE-2026-53476Critical· 9.6Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
CVE-2026-53470Critical· 9.6Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
CVE-2026-53469Critical· 9.1Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
CVE-2026-53471Critical· 9.6Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
CVE-2026-10143High· 7.5kafka-python: kafka-python: Denial of Service via excessive SCRAM authentication iteration count (CVE-2026-10143)
A flaw was found in kafka-python. A malicious or machine-in-the-middle broker could exploit a denial-of-service vulnerability during SCRAM authentication. By providing an excessively large iteration count, the broker can cause the client's…
CVE-2026-10142High· 7.5kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-i…
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length…
CVE-2026-42563High· 8.0dulwich: Dulwich: Arbitrary code execution via malicious Git file paths during merge (CVE-2026-42563)
A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. An attacker can exploit this vulnerability by crafting malicious file paths within an untrusted Git branch. When a victim merges this branch, the …
CVE-2026-42305High· 8.8dulwich: Dulwich: Remote Code Execution via Malicious Git Repository (CVE-2026-42305)
A flaw was found in Dulwich, a pure-Python implementation of the Git file formats and protocols. A remote attacker could exploit this vulnerability by enticing a user on a Windows system to clone or check out a specially crafted malicious …
MAL-2026-5531NoneMalicious code in telegramlite (PyPI)
Malicious code in telegramlite (PyPI)
MAL-2026-5518NoneMalicious code in hello-dynamic (PyPI)
Malicious code in hello-dynamic (PyPI)
MAL-2026-5519NoneMalicious code in requests-toolbelt-plus (PyPI)
Malicious code in requests-toolbelt-plus (PyPI)
CVE-2026-34031Medium· 6.5Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-33582Medium· 6.5Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-34905Medium· 6.5Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2026-34033Medium· 5.4Apache Answer vulnerable to Cross-site Scripting
Apache Answer vulnerable to Cross-site Scripting
CVE-2026-52902Medium· 4.7awxkit has a path traversal vulnerability
awxkit has a path traversal vulnerability
CVE-2026-49818Medium· 6.5Apache Airflow has a Path Traversal issue
Apache Airflow has a Path Traversal issue
CVE-2026-25699Medium· 6.1Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
CVE-2026-25688Medium· 6.1Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
MAL-2026-5345NoneMalicious code in dstill (PyPI)
Malicious code in dstill (PyPI)
RUSTSEC-2026-0209NoneAES-GCM did not enforce limits on AAD length
AES-GCM did not enforce limits on AAD length
CVE-2026-11481Low· 2.5grepai Uses a Broken or Risky Cryptographic Algorithm
grepai Uses a Broken or Risky Cryptographic Algorithm
CVE-2026-11500Medium· 5.0Weaviate has an Improper Authorization issue
Weaviate has an Improper Authorization issue
CVE-2026-11465Low· 3.1songquanpeng one-api has an issue that results in business logic errors
songquanpeng one-api has an issue that results in business logic errors
CVE-2026-11479Medium· 4.2grepai Uses a Broken or Risky Cryptographic Algorithm
grepai Uses a Broken or Risky Cryptographic Algorithm
CVE-2026-11466Medium· 5.4zilliztech deep-searcher has an Incorrect Privilege Assignment issue
zilliztech deep-searcher has an Incorrect Privilege Assignment issue
MAL-2026-5334NoneMalicious code in spaysrbx (PyPI)
Malicious code in spaysrbx (PyPI)