VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

CVE-2026-47412High· 8.1
4mo ago

praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}

praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.53%via OSV
CVE-2026-47417High· 8.1
4mo ago

praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR

praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.36%via OSV
CVE-2026-47418High· 8.1
4mo ago

praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR

praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.41%via OSV
CVE-2026-10219High· 7.3
4mo ago

GoClaw has a Command Injection issue

GoClaw has a Command Injection issue

▾ Twilightnextlevelbuilder · github.com/nextlevelbuilder/goclawEPSS 1.3%via OSV
CVE-2026-45426Low· 3.1
4mo ago

Apache Airflow has an Incorrect Authorization issue

Apache Airflow has an Incorrect Authorization issue

▾ Sunlitapache-airflow · apache-airflowEPSS 0.52%via OSV
CVE-2026-41014Medium· 4.3
4mo ago

Apache Airflow has a Missing Authorization issue

Apache Airflow has a Missing Authorization issue

▾ Sunlitapache-airflow · apache-airflowEPSS 0.57%via OSV
CVE-2026-42359High· 8.8
4mo ago

Apache Airflow has a Deserialization of Untrusted Data vulnerability

Apache Airflow has a Deserialization of Untrusted Data vulnerability

▾ Twilightapache-airflow · apache-airflowEPSS 0.95%via OSV
CVE-2026-46764Medium· 4.3
4mo ago

Apache Airflow has an Authorization Bypass Through User-Controlled Key

Apache Airflow has an Authorization Bypass Through User-Controlled Key

▾ Sunlitapache-airflow · apache-airflowEPSS 0.57%via OSV
CVE-2026-41084High· 7.5
4mo ago

Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key

Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key

▾ Twilightapache-airflow · apache-airflowEPSS 0.76%via OSV
CVE-2026-10222Medium· 5.6
4mo ago

hermes-agent has an Injection issue

hermes-agent has an Injection issue

▾ Sunlithermes-agent · hermes-agentEPSS 0.27%via OSV
CVE-2026-40963Low· 3.1
4mo ago

Apache Airflow has an Improper Authorization issue

Apache Airflow has an Improper Authorization issue

▾ Sunlitapache-airflow · apache-airflowEPSS 0.52%via OSV
CVE-2026-42360Medium· 6.5
4mo ago

Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

▾ Sunlitapache-airflow · apache-airflowEPSS 0.52%via OSV
CVE-2026-42252Critical· 9.1
4mo ago

Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine

Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine

▾ Midnightapache-airflow · apache-airflowEPSS 0.59%via OSV
CVE-2026-41017Medium· 5.9
4mo ago

Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

▾ Sunlitapache-airflow · apache-airflowEPSS 0.38%via OSV
CVE-2026-40861Medium· 6.5
4mo ago

Apache Airflow has a Link Following issue

Apache Airflow has a Link Following issue

▾ Sunlitapache-airflow · apache-airflowEPSS 0.76%via OSV
CVE-2026-49267Medium· 5.9
4mo ago

Apache Airflow has no certificate validation on SMTP STARTTLS connections

Apache Airflow has no certificate validation on SMTP STARTTLS connections

▾ Sunlitapache-airflow · apache-airflowEPSS 0.27%via OSV
CVE-2026-42358Medium· 6.5
4mo ago

Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

▾ Sunlitapache-airflow · apache-airflowEPSS 0.52%via OSV
CVE-2026-45360High· 7.3
4mo ago

Apache Airflow Vulnerable to Deserialization of Untrusted Data

Apache Airflow Vulnerable to Deserialization of Untrusted Data

▾ Twilightapache-airflow · apache-airflowEPSS 0.93%via OSV
CVE-2026-10517Medium· 5.8
4mo ago

Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints

Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints

▾ Sunlitquay · github.com/quay/claircorevia OSV
CVE-2026-48726Medium· 6.5
4mo ago

Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout

Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout

▾ Sunlitapache-airflow · apache-airflowEPSS 0.60%via OSV
CVE-2026-49298High· 8.8
4mo ago

Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args

Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args

▾ Twilightapache-airflow-core · apache-airflow-coreEPSS 0.81%via OSV
CVE-2026-10212Medium· 6.3
4mo ago

AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass

AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass

▾ Sunlitastrbot · astrbotEPSS 0.21%via OSV
CVE-2026-40961High· 7.2
4mo ago

Apache Airflow: Authenticated users can bypass the `is_safe_url` check

Apache Airflow: Authenticated users can bypass the `is_safe_url` check

▾ Twilightapache-airflow · apache-airflowEPSS 0.76%via OSV
CVE-2026-45192Medium· 6.5
4mo ago

Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra`  to read-permitted users

Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra`  to read-permitted users

▾ Sunlitapache-airflow · apache-airflowEPSS 0.66%via OSV
CVE-2026-8643Medium· 5.5⚖ disputed
4mo ago

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.

▾ Sunlitpypa · pipEPSS 0.47%via NVD
CVE-2026-10177Medium· 6.3
4mo ago

Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint

Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint

▾ Sunlitaider-chat · aider-chatEPSS 0.21%via OSV
CVE-2026-10175Medium· 6.3
4mo ago

Aider is vulnerable to Code Injection via editor_coder.run function

Aider is vulnerable to Code Injection via editor_coder.run function

▾ Sunlitaider-chat · aider-chatEPSS 0.24%via OSV
MAL-2026-5086None
4mo ago

Malicious code in polymarket-data (PyPI)

Malicious code in polymarket-data (PyPI)

▾ Sunlitpolymarket-data · polymarket-datavia OSV
CVE-2026-42500None
4mo ago

Panic when reading out of bound palette index in golang.org/x/image/bmp

Panic when reading out of bound palette index in golang.org/x/image/bmp

▾ Sunlitx · golang.org/x/imageEPSS 0.52%via OSV
GHSA-w5pp-99ch-qj29Medium· 6.5
4mo ago

go-git: Malformed Git object data may cause panics or resource exhaustion

go-git: Malformed Git object data may cause panics or resource exhaustion

▾ Sunlitgo-git · github.com/go-git/go-git/v5via OSV
CVEs tagged “osv” — page 57 · VulnSea