VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-25700High· 7.2
3mo ago

Apache Answer: AdminToken not invalidated after admin deactivation

Apache Answer: AdminToken not invalidated after admin deactivation

▾ Twilightapache · github.com/apache/incubator-answerEPSS 0.65%via OSV
CVE-2026-53474Critical· 9.6
3mo ago

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands

▾ Midnightkubev2v · github.com/kubev2v/migration-plannerEPSS 0.51%via OSV
CVE-2026-53475Critical· 9.3
3mo ago

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication

▾ Midnightkubev2v · github.com/kubev2v/assisted-migration-agentEPSS 0.50%via OSV
CVE-2026-53476Critical· 9.6
3mo ago

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

▾ Midnightkubev2v · github.com/kubev2v/assisted-migration-agentEPSS 0.43%via OSV
CVE-2026-53470Critical· 9.6
3mo ago

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs

Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs

▾ Midnightkubev2v · github.com/kubev2v/migration-plannerEPSS 0.48%via OSV
CVE-2026-53469Critical· 9.1
3mo ago

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API

▾ Midnightkubev2v · github.com/kubev2v/migration-plannerEPSS 0.51%via OSV
CVE-2026-53471Critical· 9.6
3mo ago

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation

Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation

▾ Midnightkubev2v · github.com/kubev2v/migration-plannerEPSS 0.51%via OSV
CVE-2026-10143High· 7.5
3mo ago

kafka-python: kafka-python: Denial of Service via excessive SCRAM authentication iteration count (CVE-2026-10143)

A flaw was found in kafka-python. A malicious or machine-in-the-middle broker could exploit a denial-of-service vulnerability during SCRAM authentication. By providing an excessively large iteration count, the broker can cause the client's…

▾ TwilightRed Hat · Red Hat Quay 3.12EPSS 0.52%via CSAF
CVE-2026-10142High· 7.5
3mo ago

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-i…

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length…

▾ Twilightkafka-python · kafka-pythonEPSS 0.35%via OSV
CVE-2026-42563High· 8.0
3mo ago

dulwich: Dulwich: Arbitrary code execution via malicious Git file paths during merge (CVE-2026-42563)

A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. An attacker can exploit this vulnerability by crafting malicious file paths within an untrusted Git branch. When a victim merges this branch, the …

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.80%via CSAF
CVE-2026-42305High· 8.8
3mo ago

dulwich: Dulwich: Remote Code Execution via Malicious Git Repository (CVE-2026-42305)

A flaw was found in Dulwich, a pure-Python implementation of the Git file formats and protocols. A remote attacker could exploit this vulnerability by enticing a user on a Windows system to clone or check out a specially crafted malicious …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.85%via CSAF
MAL-2026-5531None
3mo ago

Malicious code in telegramlite (PyPI)

Malicious code in telegramlite (PyPI)

▾ Sunlittelegramlite · telegramlitevia OSV
MAL-2026-5518None
3mo ago

Malicious code in hello-dynamic (PyPI)

Malicious code in hello-dynamic (PyPI)

▾ Sunlithello-dynamic · hello-dynamicvia OSV
MAL-2026-5519None
3mo ago

Malicious code in requests-toolbelt-plus (PyPI)

Malicious code in requests-toolbelt-plus (PyPI)

▾ Sunlitrequests-toolbelt-plus · requests-toolbelt-plusvia OSV
CVE-2026-34031Medium· 6.5
3mo ago

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.64%via OSV
CVE-2026-33582Medium· 6.5
3mo ago

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.65%via OSV
CVE-2026-34905Medium· 6.5
3mo ago

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.51%via OSV
CVE-2026-34033Medium· 5.4
3mo ago

Apache Answer vulnerable to Cross-site Scripting

Apache Answer vulnerable to Cross-site Scripting

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.52%via OSV
CVE-2026-52902Medium· 4.7
3mo ago

awxkit has a path traversal vulnerability

awxkit has a path traversal vulnerability

▾ Sunlitawxkit · awxkitEPSS 0.16%via OSV
CVE-2026-49818Medium· 6.5
3mo ago

Apache Airflow has a Path Traversal issue

Apache Airflow has a Path Traversal issue

▾ Sunlitapache-airflow-providers-samba · apache-airflow-providers-sambaEPSS 0.97%via OSV
CVE-2026-25699Medium· 6.1
3mo ago

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.57%via OSV
CVE-2026-25688Medium· 6.1
3mo ago

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

▾ Sunlitapache · github.com/apache/incubator-answerEPSS 0.57%via OSV
MAL-2026-5345None
3mo ago

Malicious code in dstill (PyPI)

Malicious code in dstill (PyPI)

▾ Sunlitdstill · dstillvia OSV
RUSTSEC-2026-0209None
3mo ago

AES-GCM did not enforce limits on AAD length

AES-GCM did not enforce limits on AAD length

▾ Sunlitlibcrux-aesgcm · libcrux-aesgcmvia OSV
CVE-2026-11481Low· 2.5
3mo ago

grepai Uses a Broken or Risky Cryptographic Algorithm

grepai Uses a Broken or Risky Cryptographic Algorithm

▾ Sunlityoanbernabeu · github.com/yoanbernabeu/grepaiEPSS 0.08%via OSV
CVE-2026-11500Medium· 5.0
3mo ago

Weaviate has an Improper Authorization issue

Weaviate has an Improper Authorization issue

▾ Sunlitweaviate · github.com/weaviate/weaviateEPSS 0.34%via OSV
CVE-2026-11465Low· 3.1
3mo ago

songquanpeng one-api has an issue that results in business logic errors

songquanpeng one-api has an issue that results in business logic errors

▾ Sunlitsongquanpeng · github.com/songquanpeng/one-apiEPSS 0.22%via OSV
CVE-2026-11479Medium· 4.2
3mo ago

grepai Uses a Broken or Risky Cryptographic Algorithm

grepai Uses a Broken or Risky Cryptographic Algorithm

▾ Sunlityoanbernabeu · github.com/yoanbernabeu/grepaiEPSS 0.16%via OSV
CVE-2026-11466Medium· 5.4
3mo ago

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

▾ Sunlitdeepsearcher · deepsearcherEPSS 0.25%via OSV
MAL-2026-5334None
3mo ago

Malicious code in spaysrbx (PyPI)

Malicious code in spaysrbx (PyPI)

▾ Sunlitspaysrbx · spaysrbxvia OSV
CVEs tagged “osv” — page 52 · VulnSea