Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-8276Low· 3.7bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go
bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go
CVE-2026-45022Highgo-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
CVE-2026-42595High· 8.6Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
CVE-2026-56400High· 8.3Open WebUI has a CORS misconfiguration and session validation issue
Open WebUI has a CORS misconfiguration and session validation issue
CVE-2026-40217High· 8.8PoCLiteLLM has a sandbox escape in custom-code guardrail
LiteLLM has a sandbox escape in custom-code guardrail
CVE-2026-7817Medium· 6.5pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities
pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities
CVE-2026-31246Medium· 6.5GPT-Pilot contains a command injection vulnerability in the Executor.run() method
GPT-Pilot contains a command injection vulnerability in the Executor.run() method
CVE-2026-44972Medium· 5.0GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content
GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content
CVE-2026-44569High· 7.1Open WebUI's Insecure Message Access Breaks Authorization
Open WebUI's Insecure Message Access Breaks Authorization
CVE-2026-44571Medium· 6.5Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission
Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission
CVE-2026-7816High· 8.8pgAdmin 4: OS command injection vulnerability in Import/Export query export
pgAdmin 4: OS command injection vulnerability in Import/Export query export
CVE-2026-44565High· 8.1Open WebUI Arbitrary File Write, Delete via Path Traversal
Open WebUI Arbitrary File Write, Delete via Path Traversal
CVE-2026-7820Medium· 6.5pgAdmin 4: Improper restriction of excessive authentication attempts
pgAdmin 4: Improper restriction of excessive authentication attempts
CVE-2026-7819High· 8.1pgAdmin 4 File Manager has symbolic-link path traversal
pgAdmin 4 File Manager has symbolic-link path traversal
CVE-2026-7815High· 8.8SQL injection vulnerability in pgAdmin 4 Maintenance Tool
SQL injection vulnerability in pgAdmin 4 Maintenance Tool
CVE-2026-44570High· 8.3Open WebUI has inconsistent authorization controls within memories API
Open WebUI has inconsistent authorization controls within memories API
CVE-2026-44339High· 8.6PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVE-2026-43979Medium· 5.0local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)
local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)
CVE-2026-31247High· 7.5Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks
Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks
CVE-2026-8319Medium· 5.3aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function
aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function
CVE-2026-44340High· 7.5PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`
PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`
CVE-2026-31248High· 7.5Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks
Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks
CVE-2026-31253High· 7.3flash-attention contains an insecure deserialization vulnerability in its checkpoint loading mechanism
flash-attention contains an insecure deserialization vulnerability in its checkpoint loading mechanism
CVE-2026-44338High· 7.3PoCPraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVE-2026-7814Medium· 4.8pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modules
pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modules
CVE-2026-2393High· 7.1MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
CVE-2026-44971High· 8.2GuardDog has a blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltration
GuardDog has a blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltration
CVE-2026-7818High· 7.0pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager
pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager
CVE-2026-44337Medium· 6.3PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
CVE-2026-6815Medium· 5.9PoCCasdoor: Arbitrary file write possible through Local File System storage provider
Casdoor: Arbitrary file write possible through Local File System storage provider