Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2026-34881Medium· 5.0OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
OpenStack Glance is affected by Server-Side Request Forgery (SSRF)
CVE-2025-64340Medium· 6.7FastMCP has a Command Injection vulnerability - Gemini CLI
FastMCP has a Command Injection vulnerability - Gemini CLI
CVE-2026-34400Mediumalerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API
alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API
CVE-2026-32727High· 8.1SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
CVE-2026-27489Highonnx Vulnerable to Path Traversal via Symlink
onnx Vulnerable to Path Traversal via Symlink
CVE-2026-34070High· 7.5PoCLangChain is a framework for building agents and LLM-powered applications
LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating again…
CVE-2026-33030High· 8.8nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys
CVE-2025-15036Critical· 9.6MLFlow path traversal vulnerability
MLFlow path traversal vulnerability
CVE-2025-15379Critical· 10.0A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependen…
CVE-2026-34231Medium· 6.1Slippers Vulnerable to Cross-Site Scripting (XSS) in `attrs` Template Tag
Slippers Vulnerable to Cross-Site Scripting (XSS) in `attrs` Template Tag
CVE-2026-33641High· 7.8PoCGlances Vulnerable to Command Injection via Dynamic Configuration Values
Glances Vulnerable to Command Injection via Dynamic Configuration Values
CVE-2026-33533HighGlances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
CVE-2026-27018HighGotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)
Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)
CVE-2026-32287High· 7.5XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion
XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion
GHSA-46wh-3698-f2cxHighTraefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
CVE-2026-0560High· 7.5PoCA Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/exp…
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails …
CVE-2026-0558Critical· 9.8PoCA vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through t…
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other f…
CVE-2026-32695MediumTraefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
CVE-2026-33748Medium· 6.5github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components (CVE-2026-33748)
A flaw was found in BuildKit. Insufficient validation of Git URL fragment subdirectory components may allow a remote attacker to access files outside the checked-out Git repository root. This access is limited to files on the same mounted …
CVE-2026-33747High· 8.2BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend (CVE-2026-33747)
A flaw was found in BuildKit, a toolkit for converting source code to build artifacts. An untrusted BuildKit frontend can be leveraged to craft a malicious API message, allowing files to be written outside of the designated BuildKit state …
CVE-2026-34204High· 7.1MinIO is Vulnerable to SSE Metadata Injection via Replication Headers
MinIO is Vulnerable to SSE Metadata Injection via Replication Headers
CVE-2026-27877Medium· 6.5Grafana public dashboards disclose all direct mode datasources
Grafana public dashboards disclose all direct mode datasources
CVE-2026-34073Medium· 5.3cryptography has incomplete DNS name constraint enforcement on peer names
cryptography has incomplete DNS name constraint enforcement on peer names
CVE-2026-29071Low· 3.1Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
CVE-2026-28786Medium· 4.3Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`
Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`
CVE-2026-33980High· 8.3PoCAzure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries
Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries
CVE-2026-33044LowHome Assistant has stored XSS in Map-card through malicious device name
Home Assistant has stored XSS in Map-card through malicious device name
CVE-2026-28788High· 7.1Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite
Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite
CVE-2025-15381High· 8.1MLFlow allows Tracing + Assessments Access
MLFlow allows Tracing + Assessments Access
CVE-2026-34172HighGiskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment