VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

CVE-2026-47393Critical· 9.8
4mo ago

PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default

PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default

▾ Midnightpraisonai · praisonaiEPSS 0.78%via OSV
CVE-2026-47213Medium· 6.5
4mo ago

BoxLite has a Timeout Bypass Vulnerability

BoxLite has a Timeout Bypass Vulnerability

▾ Sunlitboxlite · boxliteEPSS 0.44%via OSV
CVE-2026-47409High· 8.1
4mo ago

praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role

praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.53%via OSV
CVE-2026-47184Medium· 6.5
4mo ago

zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood

zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood

▾ Sunlitzeroconf · zeroconfEPSS 0.39%via OSV
CVE-2026-47183Medium· 6.5
4mo ago

zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion

zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion

▾ Sunlitzeroconf · zeroconfEPSS 0.39%via OSV
CVE-2026-47397High
4mo ago

PraisonAI has an Arbitrary File Write in Python API

PraisonAI has an Arbitrary File Write in Python API

▾ Twilightpraisonai · praisonaiEPSS 0.46%via OSV
CVE-2026-47405High· 8.8
4mo ago

PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership

PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.51%via OSV
CVE-2026-47180Medium· 6.5
4mo ago

zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service

zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service

▾ Sunlitzeroconf · zeroconfEPSS 0.37%via OSV
CVE-2026-47394High
4mo ago

PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate

PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate

▾ Twilightpraisonai · praisonaiEPSS 0.49%via OSV
CVE-2026-47398High· 8.1
4mo ago

PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334

PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334

▾ Twilightpraisonai · praisonaiEPSS 0.57%via OSV
CVE-2026-47399High· 8.8
4mo ago

PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID

PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.51%via OSV
CVE-2026-47414High· 7.6
4mo ago

praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)

praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.38%via OSV
CVE-2026-47395Medium· 5.5
4mo ago

PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context

PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context

▾ Sunlitpraisonaiagents · praisonaiagentsEPSS 0.18%via OSV
CVE-2026-47390Medium· 5.5
4mo ago

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

▾ Sunlitpraisonaiagents · praisonaiagentsEPSS 0.18%via OSV
CVE-2026-47406High· 8.1
4mo ago

praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks

praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.41%via OSV
CVE-2026-47408Medium· 6.5
4mo ago

praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership

praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership

▾ Sunlitpraisonai-platform · praisonai-platformEPSS 0.40%via OSV
CVE-2026-49299Medium
4mo ago

OpenStack Neutron has an Incorrect Authorization issue

OpenStack Neutron has an Incorrect Authorization issue

▾ Sunlitneutron · neutronEPSS 0.43%via OSV
CVE-2026-10105High· 8.3
4mo ago

agno contains a SQL injection vulnerability

agno contains a SQL injection vulnerability

▾ Twilightagno · agnoEPSS 0.32%via OSV
CVE-2026-10108High· 7.5
4mo ago

xiaomusic contains an unauthenticated path traversal vulnerability

xiaomusic contains an unauthenticated path traversal vulnerability

▾ Twilightxiaomusic · xiaomusicEPSS 0.51%via OSV
CVE-2026-6720High
4mo ago

Calico Inserts Sensitive Information into Log File

Calico Inserts Sensitive Information into Log File

▾ Twilightprojectcalico · github.com/projectcalico/calicoctl/v3EPSS 0.30%via OSV
GHSA-qp9x-wp8f-qgjjMedium· 4.0
4mo ago

tuf has platform-dependent delegation path matching

tuf has platform-dependent delegation path matching

▾ Sunlittuf · tufvia OSV
CVE-2026-44973High· 8.1
4mo ago

github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path traversal vulnerability (CVE-2026-44973)

A flaw was found in go-billy, an interface filesystem abstraction for Go. Multiple path traversal vulnerabilities exist due to insufficient path sanitization and boundary enforcement. A remote attacker could exploit this by crafting malici…

▾ TwilightRed Hat · Multicluster Engine for KubernetesEPSS 0.47%via CSAF
CVE-2026-47179High· 7.7
4mo ago

Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives

Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives

▾ Twilightgetarcaneapp · github.com/getarcaneapp/arcane/backendEPSS 0.46%via OSV
CVE-2026-45287Low
4mo ago

opentelemetry-go's Schema ParseFile leaks file descriptors on each parse

opentelemetry-go's Schema ParseFile leaks file descriptors on each parse

▾ Sunlitotel · go.opentelemetry.io/otel/schema/v1.1EPSS 0.18%via OSV
CVE-2026-47144Medium· 5.5
4mo ago

Shamefile has an arbitrary file read via shamefile.yaml in shame next

Shamefile has an arbitrary file read via shamefile.yaml in shame next

▾ Sunlitshamefile · shamefileEPSS 0.18%via OSV
CVE-2026-46526Medium· 5.0
4mo ago

local-deep-research has an SSRF bypass in `safe_get`

local-deep-research has an SSRF bypass in `safe_get`

▾ Sunlitlocal-deep-research · local-deep-researchEPSS 0.41%via OSV
CVE-2026-9094Critical· 9.8
4mo ago

Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check

Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check

▾ Midnightcasdoor · github.com/casdoor/casdoorEPSS 0.48%via OSV
CVE-2026-9804High· 7.7
4mo ago

A flaw was found in KubeVirt's virt-exportserver component

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an ex…

▾ TwilightRed Hat · container-native-virtualization/virt-exportserver-rhel9EPSS 0.72%via NVD
CVE-2026-44394Medium· 6.0
4mo ago

OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token

OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token

▾ Sunlitkeystone · keystoneEPSS 0.32%via OSV
CVE-2026-43000Medium· 6.0
4mo ago

OpenStack Keystone has an Incorrect Authorization issue

OpenStack Keystone has an Incorrect Authorization issue

▾ Sunlitkeystone · keystoneEPSS 0.43%via OSV
CVEs tagged “osv” — page 58 · VulnSea