VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5681 CVEsRSS

CVE-2026-40256Medium· 5.0
5mo ago

Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision

Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision

▾ Sunlitweblate · weblateEPSS 0.37%via OSV
CVE-2026-41312Medium· 6.5
5mo ago

pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM

pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.41%via OSV
CVE-2026-40353Medium· 5.4
5mo ago

wger has Stored XSS via Unescaped License Attribution Fields

wger has Stored XSS via Unescaped License Attribution Fields

▾ Sunlitwger · wgerEPSS 0.25%via OSV
CVE-2026-33440Medium· 5.0
5mo ago

Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads

Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads

▾ Sunlitweblate · weblateEPSS 0.31%via OSV
CVE-2026-41313Medium· 6.5
5mo ago

pypdf: Possible long runtimes for wrong size values in incremental mode

pypdf: Possible long runtimes for wrong size values in incremental mode

▾ Sunlitpypdf · pypdfEPSS 0.38%via OSV
CVE-2026-40602Medium· 5.6
5mo ago

Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates

Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates

▾ Sunlithomeassistant-cli · homeassistant-cliEPSS 0.14%via OSV
CVE-2024-53412High· 8.4
5mo ago

NietThijmen ShoppingCart: Command injection in the connect function

NietThijmen ShoppingCart: Command injection in the connect function

▾ TwilightNietThijmen · github.com/NietThijmen/ShoppingCartEPSS 0.56%via OSV
CVE-2026-40574Medium· 6.8
5mo ago

OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims

OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims

▾ Sunlitoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 0.34%via OSV
CVE-2026-40575Critical· 9.1
5mo ago

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

▾ Midnightoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 0.73%via OSV
CVE-2026-6855High· 7.1
5mo ago

instructlab: InstructLab: Path traversal allows arbitrary directory creation and file write (CVE-2026-6855)

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbi…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI (RHEL AI) 3EPSS 0.22%via CSAF
CVE-2026-40347Medium· 5.3
5mo ago

python-multipart affected by Denial of Service via large multipart preamble or epilogue data

python-multipart affected by Denial of Service via large multipart preamble or epilogue data

▾ Sunlitpython-multipart · python-multipartEPSS 0.42%via OSV
CVE-2026-41168Medium· 5.3
5mo ago

pypdf has long runtimes for wrong size values in cross-reference and object streams

pypdf has long runtimes for wrong size values in cross-reference and object streams

▾ Sunlitpypdf · pypdfEPSS 0.52%via OSV
CVE-2026-25219Medium· 6.5
5mo ago

Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

▾ Sunlitapache-airflow · apache-airflowEPSS 0.55%via OSV
CVE-2026-21726Medium· 5.3
5mo ago

Grafana Loki Path Traversal - CVE-2021-36156 Bypass

Grafana Loki Path Traversal - CVE-2021-36156 Bypass

▾ Sunlitgrafana · github.com/grafana/loki/v3EPSS 0.41%via OSV
CVE-2026-40192High· 7.5
5mo ago

Pillow is a Python imaging library

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file coul…

▾ Twilightpython · pillowEPSS 0.87%via NVD
CVE-2026-7808Low
5mo ago

Multiple security fixes in justhtml

Multiple security fixes in justhtml

▾ Sunlitjusthtml · justhtmlEPSS 0.59%via OSV
CVE-2026-40090High· 7.1
5mo ago

Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write

Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write

▾ Twilightzarf-dev · github.com/zarf-dev/zarfEPSS 0.39%via OSV
CVE-2026-40246High· 7.5
5mo ago

free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions

free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions

▾ Twilightfree5gc · github.com/free5gc/udrEPSS 0.45%via OSV
RUSTSEC-2026-0099None
5mo ago

Name constraints were accepted for certificates asserting a wildcard name

Name constraints were accepted for certificates asserting a wildcard name

▾ Sunlitrustls-webpki · rustls-webpkivia OSV
RUSTSEC-2026-0098None
5mo ago

Name constraints for URI names were incorrectly accepted

Name constraints for URI names were incorrectly accepted

▾ Sunlitrustls-webpki · rustls-webpkivia OSV
CVE-2026-40319Medium· 5.5
5mo ago

Giskard has a Regular Expression Denial of Service (ReDoS) in RegexMatching Check

Giskard has a Regular Expression Denial of Service (ReDoS) in RegexMatching Check

▾ Sunlitgiskard-checks · giskard-checksEPSS 0.16%via OSV
CVE-2026-40683High· 7.7
5mo ago

OpenStack Keystone: OpenStack Keystone: Unauthorized access due to incorrect LDAP user status handling (CVE-2026-40683)

A flaw was found in OpenStack Keystone. When using the LDAP identity backend, the system incorrectly processes the user enabled attribute if the user_enabled_invert configuration option is set to False. This error causes users marked as di…

▾ TwilightRed Hat · Red Hat OpenStack Platform 13 (Queens)EPSS 0.37%via CSAF
CVE-2026-40320High· 7.8
5mo ago

Giskard has Unsandboxed Jinja2 Template Rendering in ConformityCheck

Giskard has Unsandboxed Jinja2 Template Rendering in ConformityCheck

▾ Twilightgiskard-checks · giskard-checksEPSS 0.21%via OSV
CVE-2026-40491Medium· 6.5
5mo ago

gdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall

gdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall

▾ Sunlitgdown · gdownEPSS 0.77%via OSV
CVE-2026-41133High· 8.8
5mo ago

pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)

pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)

▾ Twilightpyload-ng · pyload-ngEPSS 0.47%via OSV
CVE-2026-40922Medium· 5.4
5mo ago

SiYuan has incomplete fix for CVE-2026-33066: XSS

SiYuan has incomplete fix for CVE-2026-33066: XSS

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.38%via OSV
CVE-2025-66236High· 7.5
5mo ago

Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI

Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager …

▾ TwilightApache Software Foundation · apache-airflowEPSS 0.44%via CVEORG
CVE-2026-34476High· 7.1
5mo ago

Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server

Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server

▾ Twilightapache · github.com/apache/skywalking-mcpEPSS 0.54%via OSV
CVE-2026-1462High· 7.8
5mo ago

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the secu…

▾ Twilightkeras · kerasEPSS 0.40%via NVD
CVE-2026-1116Medium· 6.1
5mo ago

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms pr…

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the…

▾ Sunlitlollms · lollmsEPSS 0.26%via OSV
CVEs tagged “osv” — page 76 · VulnSea