VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-42544High· 7.5
4mo ago

Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic

Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic

▾ Twilightgranian · granianEPSS 0.46%via OSV
CVE-2026-44305Medium· 6.8
4mo ago

Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled

Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled

▾ Sunlitlemur · lemurEPSS 0.14%via OSV
CVE-2026-44405Low· 3.4
4mo ago

Paramiko rsakey.py allows the SHA-1 algorithm

Paramiko rsakey.py allows the SHA-1 algorithm

▾ Sunlitparamiko · paramikoEPSS 0.13%via OSV
CVE-2026-44335Critical· 9.8
4mo ago

PraisonAI has an SSRF bypass

PraisonAI has an SSRF bypass

▾ Midnightpraisonaiagents · praisonaiagentsEPSS 0.57%via OSV
CVE-2026-42561High· 7.5
4mo ago

python-multipart has Denial of Service via unbounded multipart part headers

python-multipart has Denial of Service via unbounded multipart part headers

▾ Twilightpython-multipart · python-multipartEPSS 0.85%via OSV
CVE-2026-42557Critical· 9.6
4mo ago

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

▾ Midnightjupyterlab · jupyterlabEPSS 0.71%via OSV
CVE-2026-44363Medium
4mo ago

misp-modules has nsafe remote resource fetching in expansion

misp-modules has nsafe remote resource fetching in expansion

▾ Sunlitmisp-modules · misp-modulesEPSS 0.13%via OSV
CVE-2026-42545Medium· 5.9
4mo ago

Granian vulnerable to DoS via WSGI response header panic

Granian vulnerable to DoS via WSGI response header panic

▾ Sunlitgranian · granianEPSS 0.37%via OSV
CVE-2026-42448Low· 3.5
4mo ago

Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed

Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed

▾ Sunlitmagic-wormhole · magic-wormholeEPSS 0.29%via OSV
CVE-2026-44226Medium· 5.3
4mo ago

PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI

PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI

▾ Sunlitpyload-ng · pyload-ngEPSS 0.41%via OSV
CVE-2026-44368Medium
4mo ago

pyquorum: Timing side‑channel in mul_mod

pyquorum: Timing side‑channel in mul_mod

▾ Sunlitpyquorum · pyquorumEPSS 0.53%via OSV
CVE-2026-44243High· 7.1
4mo ago

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

▾ Twilightgitpython · gitpythonEPSS 0.44%via OSV
CVE-2026-44439High· 7.5
4mo ago

Playwright Capture permits access to local files and internal network resources during page capture

Playwright Capture permits access to local files and internal network resources during page capture

▾ Twilightplaywrightcapture · playwrightcaptureEPSS 0.54%via OSV
CVE-2026-44304High· 8.1
4mo ago

Lemur: LDAP Filter Injection enables post-authentication privilege escalation

Lemur: LDAP Filter Injection enables post-authentication privilege escalation

▾ Twilightlemur · lemurEPSS 0.29%via OSV
CVE-2026-44307High
4mo ago

Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup

Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup

▾ Twilightmako · makoEPSS 0.89%via OSV
CVE-2025-71261High· 8.6
4mo ago

Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS

Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS

▾ Twilightharvester · github.com/harvester/harvesterEPSS 0.21%via OSV
CVE-2026-33079High· 7.5
4mo ago

In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service

In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular ex…

▾ Twilightmistune · mistuneEPSS 0.70%via NVD
CVE-2026-5766Medium· 5.3
4mo ago

Django has an Improper Handling of Length Parameter Inconsistency

Django has an Improper Handling of Length Parameter Inconsistency

▾ Sunlitdjango · djangoEPSS 0.52%via OSV
CVE-2025-61669Medium
4mo ago

Jupyter Server has an open redirection vulnerability in `next` query parameter

Jupyter Server has an open redirection vulnerability in `next` query parameter

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.27%via OSV
CVE-2026-42304High· 7.5
4mo ago

Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains

Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains

▾ Twilighttwisted · twistedEPSS 0.95%via OSV
CVE-2026-40934Medium· 6.8
4mo ago

Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart

Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.38%via OSV
CVE-2026-6907Medium· 4.3
4mo ago

Django Uses Cache Containing Sensitive Information

Django Uses Cache Containing Sensitive Information

▾ Sunlitdjango · djangoEPSS 0.44%via OSV
CVE-2026-82254High
4mo ago

gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data

gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data

▾ Twilightgix-pack · gix-packEPSS 0.49%via OSV
CVE-2026-82252High
4mo ago

gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository

gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository

▾ Twilightgitoxide · gitoxideEPSS 0.52%via OSV
CVE-2026-82253High
4mo ago

gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure

gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure

▾ Twilightgix · gixEPSS 0.66%via OSV
CVE-2026-82251High
4mo ago

gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository

gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository

▾ Twilightgitoxide · gitoxideEPSS 0.52%via OSV
CVE-2026-40034High· 7.8
4mo ago

gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

▾ Twilightgix · gixEPSS 0.36%via OSV
CVE-2026-42186Low
4mo ago

OpenBao's Namespace Deletion May Not Delete Data Properly

OpenBao's Namespace Deletion May Not Delete Data Properly

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.43%via OSV
CVE-2026-42554Medium
4mo ago

Fiber vulnerable to XSS in AutoFormat Content Negotiation

Fiber vulnerable to XSS in AutoFormat Content Negotiation

▾ Sunlitgofiber · github.com/gofiber/fiber/v3EPSS 0.31%via OSV
CVE-2026-44166MediumPoC
4mo ago

PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade

PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade

▾ Twilightpocketbase · github.com/pocketbase/pocketbaseEPSS 0.32%via OSV
CVEs tagged “osv” — page 69 · VulnSea