VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-42085Medium· 4.3
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions…

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that …

▾ Sunlitopenc3 · openc3EPSS 0.41%via OSV
CVE-2026-42084High· 8.1
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions…

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their passwo…

▾ Twilightopenc3 · openc3EPSS 0.44%via OSV
CVE-2025-67796High· 8.1
4mo ago

IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users

IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users

▾ Twilightrdiffweb · rdiffwebEPSS 0.24%via OSV
CVE-2026-42310Medium· 5.5
4mo ago

Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

▾ Sunlitpillow · pillowEPSS 0.18%via OSV
CVE-2026-7724Medium· 5.0
4mo ago

Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url

Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url

▾ Sunlitprefect · prefectEPSS 0.31%via OSV
CVE-2026-7723High· 7.3
4mo ago

Prefect Unauthenticated Event Injection via /api/events/in WebSocket

Prefect Unauthenticated Event Injection via /api/events/in WebSocket

▾ Twilightprefect · prefectEPSS 0.71%via OSV
CVE-2026-7711High· 7.3
4mo ago

MindsDB has an Improper Access Control Issue

MindsDB has an Improper Access Control Issue

▾ Twilightmindsdb · mindsdbEPSS 0.47%via OSV
CVE-2026-7722Medium· 5.3
4mo ago

Prefect Auth Bypass via endswith() Health Check Exemption

Prefect Auth Bypass via endswith() Health Check Exemption

▾ Sunlitprefect · prefectEPSS 0.77%via OSV
CVE-2026-7725Medium· 6.3
4mo ago

Prefect Git Argument Injection in GitRepository Pull Steps

Prefect Git Argument Injection in GitRepository Pull Steps

▾ Sunlitprefect · prefectEPSS 0.42%via OSV
CVE-2026-42309Medium· 5.5
4mo ago

Pillow has a heap buffer overflow with nested list coordinates

Pillow has a heap buffer overflow with nested list coordinates

▾ Sunlitpillow · pillowEPSS 0.18%via OSV
CVE-2026-41888Medium
4mo ago

Distribution's tag deletion bypasses `storage.delete.enabled` configuration

Distribution's tag deletion bypasses `storage.delete.enabled` configuration

▾ Sunlitdistribution · github.com/distribution/distribution/v3EPSS 0.35%via OSV
CVE-2026-37461High· 7.5
4mo ago

GoBGP has an out-of-bounds read in the ParseIP6Extended function

GoBGP has an out-of-bounds read in the ParseIP6Extended function

▾ Twilightosrg · github.com/osrg/gobgp/v4EPSS 0.61%via OSV
CVE-2026-7737Medium· 5.3
4mo ago

GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer

GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer

▾ Sunlitosrg · github.com/osrg/gobgpEPSS 0.90%via OSV
CVE-2026-7734Medium· 5.3
4mo ago

GoBGP has an Improper Resource Shutdown or Release

GoBGP has an Improper Resource Shutdown or Release

▾ Sunlitosrg · github.com/osrg/gobgp/v4EPSS 0.85%via OSV
CVE-2026-7736High· 7.3
4mo ago

GoBGP has an Integer Underflow Issue

GoBGP has an Integer Underflow Issue

▾ Twilightosrg · github.com/osrg/gobgp/v4EPSS 0.63%via OSV
CVE-2026-42601Critical· 9.8
4mo ago

ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView

ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView

▾ Midnightarchivebox · archiveboxEPSS 0.60%via OSV
CVE-2026-42151High· 7.5
4mo ago

Prometheus is an open-source monitoring system and time series database

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of…

▾ Twilightprometheus · prometheusEPSS 0.41%via NVD
RUSTSEC-2026-0251None
5mo ago

sized-chunks is unmaintained

sized-chunks is unmaintained

▾ Sunlitsized-chunks · sized-chunksvia OSV
RUSTSEC-2026-0250None
5mo ago

im-rc is unmaintained

im-rc is unmaintained

▾ Sunlitim-rc · im-rcvia OSV
RUSTSEC-2026-0249None
5mo ago

smartstring is unmaintained

smartstring is unmaintained

▾ Sunlitsmartstring · smartstringvia OSV
RUSTSEC-2026-0248None
5mo ago

im is unmaintained

im is unmaintained

▾ Sunlitim · imvia OSV
RUSTSEC-2026-0247None
5mo ago

bitmaps is unmaintained

bitmaps is unmaintained

▾ Sunlitbitmaps · bitmapsvia OSV
CVE-2026-7669Medium· 5.6PoC
5mo ago

SGLang has an Improper Input Validation/Injection Issue

SGLang has an Improper Input Validation/Injection Issue

▾ Twilightsglang · sglangEPSS 0.42%via OSV
MAL-2026-3248None
5mo ago

Malicious code in pwn-control (PyPI)

Malicious code in pwn-control (PyPI)

▾ Sunlitpwn-control · pwn-controlvia OSV
CVE-2026-7597Medium· 6.3
5mo ago

mem0ai mem0 has an Improper Input Validation Issue

mem0ai mem0 has an Improper Input Validation Issue

▾ Sunlitmem0ai · mem0aiEPSS 0.43%via OSV
CVE-2026-43003High· 8.0
5mo ago

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a mal…

▾ Twilightopenstack · ironic_python_agentEPSS 1.1%via NVD
CVE-2026-7579High· 7.3
5mo ago

AstrBot Makes Use of Hard-coded Password

AstrBot Makes Use of Hard-coded Password

▾ Twilightastrbot · astrbotEPSS 0.50%via OSV
CVE-2026-43001High· 8.0
5mo ago

OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation (CVE-2026-4…

A flaw was found in OpenStack Keystone. An attacker holding an unrestricted application credential could exploit a vulnerability in the POST /v3/credentials endpoint where the caller-supplied project_id for an EC2-type credential was not v…

▾ TwilightRed Hat · Red Hat OpenStack Platform 17.1EPSS 0.59%via CSAF
CVE-2026-41016Medium· 5.9
5mo ago

apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider

apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider

▾ Sunlitapache-airflow-providers-smtp · apache-airflow-providers-smtpEPSS 0.27%via OSV
CVE-2026-7246High· 7.2
5mo ago

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pa…

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

▾ Twilightclick · clickEPSS 0.92%via OSV
CVEs tagged “osv” — page 71 · VulnSea