VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

CVE-2026-35397High· 8.8PoC
4mo ago

Jupyter Server is the backend for Jupyter web applications

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whos…

▾ Midnightjupyter · jupyter_serverEPSS 0.67%via NVD
GHSA-h5fq-653g-gxrmMedium· 5.3
4mo ago

ots has a negative expire override that can bypass its secret retention policy

ots has a negative expire override that can bypass its secret retention policy

▾ SunlitLuzifer · github.com/Luzifer/otsvia OSV
CVE-2026-7776High· 7.5
4mo ago

Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes

Hashicorp Boundary workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes

▾ Twilighthashicorp · github.com/hashicorp/boundaryEPSS 0.34%via OSV
CVE-2026-42220Medium· 6.5
4mo ago

Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and r…

Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback

▾ Sunlit0xJacky · github.com/0xJacky/Nginx-UIEPSS 0.40%via OSV
CVE-2026-44219Low· 3.7
4mo ago

ciguard: SCA HTTP client reads response body without size cap

ciguard: SCA HTTP client reads response body without size cap

▾ Sunlitciguard · ciguardEPSS 0.31%via OSV
CVE-2026-7846Low· 2.6
4mo ago

Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API

Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API

▾ Sunlitlangchain-chatchat · langchain-chatchatEPSS 0.23%via OSV
CVE-2026-7845Low· 2.6
4mo ago

Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm

Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm

▾ Sunlitlangchain-chatchat · langchain-chatchatEPSS 0.20%via OSV
CVE-2026-43002Medium· 5.3
4mo ago

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression…

▾ Sunlitopenstack · horizonEPSS 0.60%via NVD
CVE-2026-42175Medium· 6.5
4mo ago

requests-hardened is Vulnerable to Server-Side Request Forgery

requests-hardened is Vulnerable to Server-Side Request Forgery

▾ Sunlitrequests-hardened · requests-hardenedEPSS 0.39%via OSV
CVE-2026-42303Medium
4mo ago

Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection

Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection

▾ Sunlitethyca-fides · ethyca-fidesEPSS 0.55%via OSV
CVE-2026-42080Medium· 4.6
4mo ago

PPTAgent: Arbitrary File Write via `save_generated_slides`

PPTAgent: Arbitrary File Write via `save_generated_slides`

▾ Sunlitpptagent · pptagentEPSS 0.30%via OSV
CVE-2026-40864Medium· 5.4PoC
4mo ago

JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)

JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)

▾ Twilightjupyterhub · jupyterhubEPSS 0.18%via OSV
CVE-2026-7847Low· 2.6
4mo ago

Langchain-Chatchat Uses Insufficiently Random Values

Langchain-Chatchat Uses Insufficiently Random Values

▾ Sunlitlangchain-chatchat · langchain-chatchatEPSS 0.29%via OSV
CVE-2026-44218Low· 3.0
4mo ago

ciguard: Container image runs as root (no USER directive)

ciguard: Container image runs as root (no USER directive)

▾ Sunlitciguard · ciguardEPSS 0.12%via OSV
CVE-2026-42078Medium· 4.6
4mo ago

PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image

PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image

▾ Sunlitpptagent · pptagentEPSS 0.30%via OSV
CVE-2026-44222Medium· 6.5
4mo ago

vLLM Vulnerable to Remote DoS via Special-Token Placeholders

vLLM Vulnerable to Remote DoS via Special-Token Placeholders

▾ Sunlitvllm · vllmEPSS 0.46%via OSV
CVE-2026-44220None· 0.0
4mo ago

ciguard: discover_pipeline_files follows symlinks out of scan root

ciguard: discover_pipeline_files follows symlinks out of scan root

▾ Sunlitciguard · ciguardEPSS 0.15%via OSV
CVE-2026-42079High· 8.6
4mo ago

PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope

PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope

▾ Twilightpptagent · pptagentEPSS 0.21%via OSV
CVE-2026-42874Low· 3.7
4mo ago

Microdot has HTTP response splitting in Response.set_cookie()

Microdot has HTTP response splitting in Response.set_cookie()

▾ Sunlitmicrodot · microdotEPSS 0.34%via OSV
CVE-2026-43901Medium· 6.8
4mo ago

wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configured

wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configured

▾ Sunlitwireshark-mcp · wireshark-mcpEPSS 0.36%via OSV
CVE-2026-40110High
4mo ago

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

▾ Twilightjupyter-server · jupyter-serverEPSS 0.47%via OSV
CVE-2026-43891High· 7.5
4mo ago

changedetection.io has an Arbitrary Local File Read via a crafted backup restore

changedetection.io has an Arbitrary Local File Read via a crafted backup restore

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.50%via OSV
CVE-2026-42997High· 7.7
4mo ago

An issue was discovered in idrac in OpenStack Ironic before 35.0.1

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides…

▾ Twilightopenstack · ironicEPSS 0.54%via NVD
CVE-2026-43868Medium· 5.3
4mo ago

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

▾ Sunlitapache · thriftEPSS 1.2%via NVD
CVE-2026-41181Medium
4mo ago

Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service

Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.50%via OSV
CVE-2026-7482Critical· 9.1PoC
4mo ago

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader

▾ Abyssalollama · github.com/ollama/ollamaEPSS 0.71%via OSV
CVE-2026-42294High· 7.5
4mo ago

Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor

Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor

▾ Twilightargoproj · github.com/argoproj/argo-workflows/v3EPSS 0.74%via OSV
CVE-2026-42295High
4mo ago

Argo vulnerable to exposure of artifact repository credentials

Argo vulnerable to exposure of artifact repository credentials

▾ Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.40%via OSV
CVE-2026-42088High· 8.1
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version …

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from th…

▾ Twilightopenc3 · openc3EPSS 0.49%via OSV
CVE-2026-42087Critical· 9.6
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.…

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSD…

▾ Midnightopenc3 · openc3EPSS 0.45%via OSV
CVEs tagged “osv” — page 70 · VulnSea