VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-40171High· 8.8
5mo ago

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

▾ Twilightjupyter-notebook · @jupyter-notebook/help-extensionEPSS 0.66%via OSV
CVE-2025-13030High· 7.1
5mo ago

django-mdeditor is Missing Authentication for Critical Function

django-mdeditor is Missing Authentication for Critical Function

▾ Twilightdjango-mdeditor · django-mdeditorEPSS 0.31%via OSV
CVE-2026-41654Medium
5mo ago

Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url

Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url

▾ Sunlitweblate · weblateEPSS 0.50%via OSV
CVE-2026-42032Medium
5mo ago

CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`

CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`

▾ Sunlitckan · ckanEPSS 0.41%via OSV
CVE-2026-41519Medium· 4.2
5mo ago

Weblate Doesn't Invalidate API Token on Password Change

Weblate Doesn't Invalidate API Token on Password Change

▾ Sunlitweblate · weblateEPSS 0.37%via OSV
CVE-2026-42254High
5mo ago

Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation

Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation

▾ Twilighthickory-recursor · hickory-recursorEPSS 0.26%via OSV
CVE-2026-40280Critical· 9.3PoC
5mo ago

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection

▾ Abyssalgotenberg · github.com/gotenberg/gotenberg/v8EPSS 2.1%via OSV
CVE-2026-41643High· 7.5
5mo ago

GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE

GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE

▾ Twilightosrg · github.com/osrg/gobgp/v4EPSS 0.60%via OSV
CVE-2026-41132Medium
5mo ago

CKAN has no certificate validation on STMP connection

CKAN has no certificate validation on STMP connection

▾ Sunlitckan · ckanEPSS 0.21%via OSV
CVE-2026-41255Medium· 6.1
5mo ago

CKAN has CSRF exemption primed by anonymous requests

CKAN has CSRF exemption primed by anonymous requests

▾ Sunlitckan · ckanEPSS 0.14%via OSV
CVE-2026-42352High· 8.6
5mo ago

pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber

pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber

▾ Twilightpygeoapi · pygeoapiEPSS 0.56%via OSV
CVE-2026-42031HighPoC
5mo ago

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

▾ Midnightckan · ckanEPSS 2.2%via OSV
CVE-2026-42351High· 7.5
5mo ago

pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider

pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider

▾ Twilightpygeoapi · pygeoapiEPSS 0.61%via OSV
CVE-2026-7404High· 7.3
5mo ago

mcpo-simple-server has a Path Traversal issue

mcpo-simple-server has a Path Traversal issue

▾ Twilightmcpo-simple-server · mcpo-simple-serverEPSS 0.59%via OSV
CVE-2026-32936High· 7.5
5mo ago

CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification

CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification

▾ Twilightcoredns · github.com/coredns/corednsEPSS 0.61%via OSV
CVE-2026-32934High· 7.5
5mo ago

CoreDNS' DoQ worker pool does not bound stream backlog

CoreDNS' DoQ worker pool does not bound stream backlog

▾ Twilightcoredns · github.com/coredns/corednsEPSS 0.63%via OSV
CVE-2026-30246Medium· 6.5
5mo ago

Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters

Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters

▾ Sunlitgofiber · github.com/gofiber/fiber/v3EPSS 0.37%via OSV
MAL-2026-3129None
5mo ago

Malicious code in supertag (crates.io)

Malicious code in supertag (crates.io)

▾ Sunlitsupertag · supertagvia OSV
MAL-2026-3126None
5mo ago

Malicious code in lsh (crates.io)

Malicious code in lsh (crates.io)

▾ Sunlitlsh · lshvia OSV
CVE-2026-7159High· 7.3
5mo ago

mkdocs-mcp-plugin has a Path Traversal issue

mkdocs-mcp-plugin has a Path Traversal issue

▾ Twilightmkdocs-mcp-plugin · mkdocs-mcp-pluginEPSS 0.61%via OSV
CVE-2026-7212High· 7.3
5mo ago

notes-mcp has a Path Traversal issue

notes-mcp has a Path Traversal issue

▾ Twilightnotes-mcp · notes-mcpEPSS 0.59%via OSV
CVE-2026-7206High· 7.3
5mo ago

sqlite-mcp has an Injection issue

sqlite-mcp has an Injection issue

▾ Twilightsqlite-mcp · sqlite-mcpEPSS 0.43%via OSV
CVE-2026-42510Medium· 6.6
5mo ago

OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

▾ Sunlitironic · ironicEPSS 0.74%via OSV
MAL-2026-3103None
5mo ago

Malicious code in amzn_codewhisperer_streaming_client (crates.io)

Malicious code in amzn_codewhisperer_streaming_client (crates.io)

▾ Sunlitamzn-codewhisperer-streaming-client · amzn-codewhisperer-streaming-clientvia OSV
MAL-2026-3102None
5mo ago

Malicious code in semantic_search_client (crates.io)

Malicious code in semantic_search_client (crates.io)

▾ Sunlitsemantic-search-client · semantic-search-clientvia OSV
MAL-2026-3101None
5mo ago

Malicious code in amzn_consolas_client (crates.io)

Malicious code in amzn_consolas_client (crates.io)

▾ Sunlitamzn-consolas-client · amzn-consolas-clientvia OSV
CVE-2026-7141Medium· 5.6
5mo ago

vLLM makes Use of Uninitialized Resource

vLLM makes Use of Uninitialized Resource

▾ Sunlitvllm · vllmEPSS 0.48%via OSV
CVE-2026-7142Medium· 6.3
5mo ago

Wooey has an Incorrect Privilege Assignment issue

Wooey has an Incorrect Privilege Assignment issue

▾ Sunlitwooey · wooeyEPSS 0.37%via OSV
CVE-2026-7150Medium· 6.3
5mo ago

auto-favicon has a Server-Side Request Forgery issue

auto-favicon has a Server-Side Request Forgery issue

▾ Sunlitauto-favicon · auto-faviconEPSS 0.35%via OSV
CVE-2026-7149High· 7.3
5mo ago

kaggle-mcp has a Path Traversal issue

kaggle-mcp has a Path Traversal issue

▾ Twilightkaggle-mcp · kaggle-mcpEPSS 0.59%via OSV
CVEs tagged “osv” — page 72 · VulnSea