Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-42085Medium· 4.3OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions…
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that …
CVE-2026-42084High· 8.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions…
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their passwo…
CVE-2025-67796High· 8.1IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
CVE-2026-42310Medium· 5.5Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
CVE-2026-7724Medium· 5.0Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url
Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url
CVE-2026-7723High· 7.3Prefect Unauthenticated Event Injection via /api/events/in WebSocket
Prefect Unauthenticated Event Injection via /api/events/in WebSocket
CVE-2026-7711High· 7.3MindsDB has an Improper Access Control Issue
MindsDB has an Improper Access Control Issue
CVE-2026-7722Medium· 5.3Prefect Auth Bypass via endswith() Health Check Exemption
Prefect Auth Bypass via endswith() Health Check Exemption
CVE-2026-7725Medium· 6.3Prefect Git Argument Injection in GitRepository Pull Steps
Prefect Git Argument Injection in GitRepository Pull Steps
CVE-2026-42309Medium· 5.5Pillow has a heap buffer overflow with nested list coordinates
Pillow has a heap buffer overflow with nested list coordinates
CVE-2026-41888MediumDistribution's tag deletion bypasses `storage.delete.enabled` configuration
Distribution's tag deletion bypasses `storage.delete.enabled` configuration
CVE-2026-37461High· 7.5GoBGP has an out-of-bounds read in the ParseIP6Extended function
GoBGP has an out-of-bounds read in the ParseIP6Extended function
CVE-2026-7737Medium· 5.3GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer
GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2026-7734Medium· 5.3GoBGP has an Improper Resource Shutdown or Release
GoBGP has an Improper Resource Shutdown or Release
CVE-2026-7736High· 7.3GoBGP has an Integer Underflow Issue
GoBGP has an Integer Underflow Issue
CVE-2026-42601Critical· 9.8ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
CVE-2026-42151High· 7.5Prometheus is an open-source monitoring system and time series database
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of…
RUSTSEC-2026-0251Nonesized-chunks is unmaintained
sized-chunks is unmaintained
RUSTSEC-2026-0250Noneim-rc is unmaintained
im-rc is unmaintained
RUSTSEC-2026-0249Nonesmartstring is unmaintained
smartstring is unmaintained
RUSTSEC-2026-0248Noneim is unmaintained
im is unmaintained
RUSTSEC-2026-0247Nonebitmaps is unmaintained
bitmaps is unmaintained
CVE-2026-7669Medium· 5.6PoCSGLang has an Improper Input Validation/Injection Issue
SGLang has an Improper Input Validation/Injection Issue
MAL-2026-3248NoneMalicious code in pwn-control (PyPI)
Malicious code in pwn-control (PyPI)
CVE-2026-7597Medium· 6.3mem0ai mem0 has an Improper Input Validation Issue
mem0ai mem0 has an Improper Input Validation Issue
CVE-2026-43003High· 8.0An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a mal…
CVE-2026-7579High· 7.3AstrBot Makes Use of Hard-coded Password
AstrBot Makes Use of Hard-coded Password
CVE-2026-43001High· 8.0OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation (CVE-2026-4…
A flaw was found in OpenStack Keystone. An attacker holding an unrestricted application credential could exploit a vulnerability in the POST /v3/credentials endpoint where the caller-supplied project_id for an EC2-type credential was not v…
CVE-2026-41016Medium· 5.9apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider
apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider
CVE-2026-7246High· 7.2Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pa…
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.