Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2026-33936Medium· 5.3PoCpython-ecdsa: Denial of Service via improper DER length validation in crafted private keys
python-ecdsa: Denial of Service via improper DER length validation in crafted private keys
CVE-2026-34046HighLangflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CVE-2026-33981HighChangedetection.io Discloses Environment Variables via jq env Builtin in Include Filters
Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters
CVE-2026-4963Medium· 6.3Hugging Face Smolagents has an Injection issue
Hugging Face Smolagents has an Injection issue
CVE-2026-29070Medium· 5.4Open WebUI has unauthorized deletion of knowledge files
Open WebUI has unauthorized deletion of knowledge files
CVE-2026-28377High· 7.5Grafana Tempo has Inadequate Encryption Strength
Grafana Tempo has Inadequate Encryption Strength
CVE-2026-33045LowHome Assistant has stored XSS in history-graphs
Home Assistant has stored XSS in history-graphs
CVE-2026-27893High· 8.8vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the…
GHSA-wcjx-v2wj-xg87High· 7.5C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)
C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)
CVE-2026-33758CriticalOpenBao has Reflected XSS in its OIDC authentication error message
OpenBao has Reflected XSS in its OIDC authentication error message
CVE-2026-33757Critical· 9.6OpenBao lacks user confirmation for OIDC direct callback mode
OpenBao lacks user confirmation for OIDC direct callback mode
CVE-2026-21724Medium· 5.4Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
CVE-2026-56765Critical· 9.1Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
CVE-2026-33487High· 7.5PoCgoxmlsig provides XML Digital Signatures implemented in Go
goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID.…
CVE-2026-32285High· 7.5PoCThe Delete function fails to properly validate offsets when processing malformed JSON input
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
CVE-2026-33809Medium· 5.3Go Images vulnerable to an out-of-memory error via a crafted TIFF file
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
CVE-2026-29785High· 7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect …
CVE-2026-27602High· 7.2Modoboa has OS Command Injection
Modoboa has OS Command Injection
CVE-2025-70887HighSignify allows a remote attacker to escalate privileges via the signed_data.py and the context.py components
Signify allows a remote attacker to escalate privileges via the signed_data.py and the context.py components
CVE-2026-25645Medium· 4.4PoCRequests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
CVE-2026-33699Mediumpypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream
pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream
CVE-2026-33682Medium· 4.7Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)
Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)
CVE-2026-33634CriticalCISA KEVPoCTrivy ecosystem supply chain was briefly compromised
Trivy ecosystem supply chain was briefly compromised
CVE-2026-33246Medium· 6.4NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
CVE-2026-33248Medium· 4.2NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
CVE-2026-5389HighJustHTML is vulnerable to XSS via code fence breakout in <pre> content
JustHTML is vulnerable to XSS via code fence breakout in <pre> content
CVE-2026-24159High· 7.8NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution
NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution
CVE-2026-24157High· 7.8NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading
NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading
CVE-2026-33545Medium· 5.3MobSF has SQL Injection in its SQLite Database Viewer Utils
MobSF has SQL Injection in its SQLite Database Viewer Utils
CVE-2026-54685Medium· 5.3FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel
FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel