VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-8276Low· 3.7
4mo ago

bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go

bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go

▾ Sunlitbettercap · github.com/bettercap/bettercap/v2EPSS 0.62%via OSV
CVE-2026-45022High
4mo ago

go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

▾ Twilightgo-git · github.com/go-git/go-git/v6EPSS 0.16%via OSV
CVE-2026-42595High· 8.6
4mo ago

Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass

Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass

▾ Twilightgotenberg · github.com/gotenberg/gotenberg/v8EPSS 0.42%via OSV
CVE-2026-56400High· 8.3
4mo ago

Open WebUI has a CORS misconfiguration and session validation issue

Open WebUI has a CORS misconfiguration and session validation issue

▾ Twilightopen-webui · open-webuiEPSS 0.52%via OSV
CVE-2026-40217High· 8.8PoC
4mo ago

LiteLLM has a sandbox escape in custom-code guardrail

LiteLLM has a sandbox escape in custom-code guardrail

▾ Midnightlitellm · litellmEPSS 3.4%via OSV
CVE-2026-7817Medium· 6.5
4mo ago

pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities

pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities

▾ Sunlitpgadmin4 · pgadmin4EPSS 0.35%via OSV
CVE-2026-31246Medium· 6.5
4mo ago

GPT-Pilot contains a command injection vulnerability in the Executor.run() method

GPT-Pilot contains a command injection vulnerability in the Executor.run() method

▾ Sunlitgpt-pilot · gpt-pilotEPSS 1.1%via OSV
CVE-2026-44972Medium· 5.0
4mo ago

GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content

GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content

▾ Sunlitguarddog · guarddogEPSS 0.15%via OSV
CVE-2026-44569High· 7.1
4mo ago

Open WebUI's Insecure Message Access Breaks Authorization

Open WebUI's Insecure Message Access Breaks Authorization

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-44571Medium· 6.5
4mo ago

Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission

Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission

▾ Sunlitopen-webui · open-webuiEPSS 0.34%via OSV
CVE-2026-7816High· 8.8
4mo ago

pgAdmin 4: OS command injection vulnerability in Import/Export query export

pgAdmin 4: OS command injection vulnerability in Import/Export query export

▾ Twilightpgadmin4 · pgadmin4EPSS 2.2%via OSV
CVE-2026-44565High· 8.1
4mo ago

Open WebUI Arbitrary File Write, Delete via Path Traversal

Open WebUI Arbitrary File Write, Delete via Path Traversal

▾ Twilightopen-webui · open-webuiEPSS 0.54%via OSV
CVE-2026-7820Medium· 6.5
4mo ago

pgAdmin 4: Improper restriction of excessive authentication attempts

pgAdmin 4: Improper restriction of excessive authentication attempts

▾ Sunlitpgadmin4 · pgadmin4EPSS 0.33%via OSV
CVE-2026-7819High· 8.1
4mo ago

pgAdmin 4 File Manager has symbolic-link path traversal

pgAdmin 4 File Manager has symbolic-link path traversal

▾ Twilightpgadmin4 · pgadmin4EPSS 0.48%via OSV
CVE-2026-7815High· 8.8
4mo ago

SQL injection vulnerability in pgAdmin 4 Maintenance Tool

SQL injection vulnerability in pgAdmin 4 Maintenance Tool

▾ Twilightpgadmin4 · pgadmin4EPSS 0.64%via OSV
CVE-2026-44570High· 8.3
4mo ago

Open WebUI has inconsistent authorization controls within memories API

Open WebUI has inconsistent authorization controls within memories API

▾ Twilightopen-webui · open-webuiEPSS 0.42%via OSV
CVE-2026-44339High· 8.6
4mo ago

PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute

PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.43%via OSV
CVE-2026-43979Medium· 5.0
4mo ago

local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)

local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)

▾ Sunlitlocal-deep-research · local-deep-researchEPSS 0.36%via OSV
CVE-2026-31247High· 7.5
4mo ago

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks

▾ Twilightdocling · doclingEPSS 0.49%via OSV
CVE-2026-8319Medium· 5.3
4mo ago

aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function

aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function

▾ Sunlitai-agents · ai-agentsEPSS 0.64%via OSV
CVE-2026-44340High· 7.5
4mo ago

PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`

PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`

▾ Twilightpraisonai · praisonaiEPSS 0.46%via OSV
CVE-2026-31248High· 7.5
4mo ago

Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks

Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks

▾ Twilightdocling · doclingEPSS 0.49%via OSV
CVE-2026-31253High· 7.3
4mo ago

flash-attention contains an insecure deserialization vulnerability in its checkpoint loading mechanism

flash-attention contains an insecure deserialization vulnerability in its checkpoint loading mechanism

▾ Twilightflash-attn · flash-attnEPSS 0.37%via OSV
CVE-2026-44338High· 7.3PoC
4mo ago

PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution

PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution

▾ Midnightpraisonai · praisonaiEPSS 0.82%via OSV
CVE-2026-7814Medium· 4.8
4mo ago

pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modules

pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modules

▾ Sunlitpgadmin4 · pgadmin4EPSS 0.25%via OSV
CVE-2026-2393High· 7.1
4mo ago

MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability

MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability

▾ Twilightmlflow · mlflowEPSS 0.29%via OSV
CVE-2026-44971High· 8.2
4mo ago

GuardDog has a blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltration

GuardDog has a blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltration

▾ Twilightguarddog · guarddogEPSS 0.34%via OSV
CVE-2026-7818High· 7.0
4mo ago

pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager

pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager

▾ Twilightpgadmin4 · pgadmin4EPSS 0.35%via OSV
CVE-2026-44337Medium· 6.3
4mo ago

PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries

PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries

▾ Sunlitpraisonai · praisonaiEPSS 0.31%via OSV
CVE-2026-6815Medium· 5.9PoC
4mo ago

Casdoor: Arbitrary file write possible through Local File System storage provider

Casdoor: Arbitrary file write possible through Local File System storage provider

▾ Twilightcasdoor · github.com/casdoor/casdoorEPSS 0.59%via OSV
CVEs tagged “osv” — page 65 · VulnSea