VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

CVE-2026-8212Medium· 5.3
4mo ago

OSGeo gdal has a heap-based buffer overflow

OSGeo gdal has a heap-based buffer overflow

▾ Sunlitgdal · gdalEPSS 0.23%via OSV
MAL-2026-3411None
4mo ago

Malicious code in web3-py-checksum (PyPI)

Malicious code in web3-py-checksum (PyPI)

▾ Sunlitweb3-py-checksum · web3-py-checksumvia OSV
CVE-2026-42308Medium· 6.2
4mo ago

Pillow: Pillow: Denial of Service via integer overflow in font processing (CVE-2026-42308)

A flaw was found in Pillow, a Python imaging library. If a font advances for each glyph by an exceeding large amount, an integer overflow can occur when Pillow tracks the current position. This could lead to a denial of service (DoS) condi…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.16%via CSAF
CVE-2026-8213Medium· 5.5
4mo ago

A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4…

A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDapi.c of the component Grid File Handler. The manipulation leads to heap-based buffer ove…

▾ Sunlitgdal · gdalEPSS 0.23%via OSV
CVE-2026-44897Medium· 6.1
4mo ago

Mistune Heading ID Attribute has Injection XSS

Mistune Heading ID Attribute has Injection XSS

▾ Sunlitmistune · mistuneEPSS 0.27%via OSV
CVE-2026-42301High· 7.3
4mo ago

pyp2spec: pyp2spec: Arbitrary command execution via unescaped RPM macro directives (CVE-2026-42301)

A flaw was found in pyp2spec, a tool that generates Fedora RPM spec files for Python projects. This vulnerability allows a malicious Python Package Index (PyPI) package to execute arbitrary commands on a build machine. This occurs because …

▾ TwilightRed Hat · pyp2specEPSS 0.23%via CSAF
CVE-2026-42311High· 7.8
4mo ago

Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing (CVE-2026-42311)

A flaw was found in Pillow, a Python imaging library. An attacker could exploit this vulnerability by tricking a user into processing a specially crafted malicious PSD file. This could lead to memory corruption, potentially causing the app…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.22%via CSAF
CVE-2026-44309Medium· 5.3
4mo ago

gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits

gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits

▾ Sunlitsigstore · github.com/sigstore/gitsignEPSS 0.16%via OSV
CVE-2026-44310Medium· 5.4
4mo ago

gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers

gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers

▾ Sunlitsigstore · github.com/sigstore/gitsignEPSS 0.17%via OSV
CVE-2026-44896Medium· 6.1
4mo ago

Mistune has XSS via unescaped figclass/figwidth in Figure directive

Mistune has XSS via unescaped figclass/figwidth in Figure directive

▾ Sunlitmistune · mistuneEPSS 0.27%via OSV
CVE-2026-38360Critical· 9.8PoC
4mo ago

dash-uploader has a directory traversal vulnerability

dash-uploader has a directory traversal vulnerability

▾ Abyssaldash-uploader · dash-uploaderEPSS 6.1%via OSV
CVE-2026-4671Low
4mo ago

justhtml introduces denial-of-service hardening

justhtml introduces denial-of-service hardening

▾ Sunlitjusthtml · justhtmlEPSS 0.65%via OSV
CVE-2026-44327Critical· 10.0
4mo ago

free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler

free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler

▾ Midnightfree5gc · github.com/free5gc/nefEPSS 0.53%via OSV
CVE-2026-44564Medium· 5.4
4mo ago

Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO

Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO

▾ Sunlitopen-webui · open-webuiEPSS 0.32%via OSV
CVE-2026-44563Medium· 5.4
4mo ago

Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show

Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show

▾ Sunlitopen-webui · open-webuiEPSS 0.34%via OSV
CVE-2026-44843High· 8.2
4mo ago

LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists

LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists

▾ Twilightlangchain-core · langchain-coreEPSS 0.38%via OSV
CVE-2026-44562Medium· 6.5
4mo ago

Open WebUI's Model Import Overwrites Any Model Without Ownership Check

Open WebUI's Model Import Overwrites Any Model Without Ownership Check

▾ Sunlitopen-webui · open-webuiEPSS 0.35%via OSV
CVE-2026-40214Medium· 6.3
4mo ago

OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layer

OpenStack Cyborg's Accelerator Request (ARQ) API does not enforce project ownership at any layer

▾ Sunlitopenstack-cyborg · openstack-cyborgEPSS 0.33%via OSV
CVE-2026-40213High· 7.4
4mo ago

OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints

OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints

▾ Twilightopenstack-cyborg · openstack-cyborgEPSS 0.33%via OSV
CVE-2026-44549High· 7.3
4mo ago

Open WebUI has stored XSS in Excel file preview

Open WebUI has stored XSS in Excel file preview

▾ Twilightopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2026-44550Medium· 5.0
4mo ago

Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts

Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts

▾ Sunlitopen-webui · open-webuiEPSS 0.29%via OSV
CVE-2026-44556High· 7.1
4mo ago

Open WebUI's responses passthrough endpoint lacks access control authorization

Open WebUI's responses passthrough endpoint lacks access control authorization

▾ Twilightopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2026-44561Medium· 5.4
4mo ago

Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels

Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels

▾ Sunlitopen-webui · open-webuiEPSS 0.26%via OSV
CVE-2026-44560Medium· 6.5
4mo ago

Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search

Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search

▾ Sunlitopen-webui · open-webuiEPSS 0.38%via OSV
CVE-2026-44209High· 7.5
4mo ago

banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI

banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI

▾ Twilightbanks · banksEPSS 0.74%via OSV
CVE-2026-44721High· 7.3
4mo ago

open-webui Vulnerable to Stored XSS via Model Description

open-webui Vulnerable to Stored XSS via Model Description

▾ Twilightopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2026-44844Medium
4mo ago

eml_parser has recursion DoS via nested message/rfc822 attachments

eml_parser has recursion DoS via nested message/rfc822 attachments

▾ Sunliteml-parser · eml-parserEPSS 0.43%via OSV
CVE-2026-44568Medium· 4.8
4mo ago

Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order

Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order

▾ Sunlitopen-webui · open-webuiEPSS 0.25%via OSV
CVE-2026-44502Medium· 4.3
4mo ago

Bunsink has an SSRF bypass in `validate_webhook_url`

Bunsink has an SSRF bypass in `validate_webhook_url`

▾ Sunlitbugsink · bugsinkEPSS 0.39%via OSV
CVE-2026-44559Medium· 4.3
4mo ago

Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels

Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels

▾ Sunlitopen-webui · open-webuiEPSS 0.30%via OSV
CVEs tagged “osv” — page 66 · VulnSea