VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2026-33936Medium· 5.3PoC
6mo ago

python-ecdsa: Denial of Service via improper DER length validation in crafted private keys

python-ecdsa: Denial of Service via improper DER length validation in crafted private keys

▾ Twilightecdsa · ecdsaEPSS 0.52%via OSV
CVE-2026-34046High
6mo ago

Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

▾ Twilightlangflow · langflowEPSS 0.68%via OSV
CVE-2026-33981High
6mo ago

Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters

Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.48%via OSV
CVE-2026-4963Medium· 6.3
6mo ago

Hugging Face Smolagents has an Injection issue

Hugging Face Smolagents has an Injection issue

▾ Sunlitsmolagents · smolagentsEPSS 0.73%via OSV
CVE-2026-29070Medium· 5.4
6mo ago

Open WebUI has unauthorized deletion of knowledge files

Open WebUI has unauthorized deletion of knowledge files

▾ Sunlitopen-webui · open-webuiEPSS 0.38%via OSV
CVE-2026-28377High· 7.5
6mo ago

Grafana Tempo has Inadequate Encryption Strength

Grafana Tempo has Inadequate Encryption Strength

▾ Twilightgrafana · github.com/grafana/tempoEPSS 0.16%via OSV
CVE-2026-33045Low
6mo ago

Home Assistant has stored XSS in history-graphs

Home Assistant has stored XSS in history-graphs

▾ Sunlithomeassistant · homeassistantEPSS 0.25%via OSV
CVE-2026-27893High· 8.8
6mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the…

▾ Twilightvllm · vllmEPSS 1.8%via NVD
GHSA-wcjx-v2wj-xg87High· 7.5
6mo ago

C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)

C2C CI utils is vulnerable to DoS via pyasn dependency (CVE-2026-30922)

▾ Twilightc2cciutils · c2cciutilsvia OSV
CVE-2026-33758Critical
6mo ago

OpenBao has Reflected XSS in its OIDC authentication error message

OpenBao has Reflected XSS in its OIDC authentication error message

▾ Midnightopenbao · github.com/openbao/openbaoEPSS 0.45%via OSV
CVE-2026-33757Critical· 9.6
6mo ago

OpenBao lacks user confirmation for OIDC direct callback mode

OpenBao lacks user confirmation for OIDC direct callback mode

▾ Midnightopenbao · github.com/openbao/openbaoEPSS 0.61%via OSV
CVE-2026-21724Medium· 5.4
6mo ago

Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 0.26%via OSV
CVE-2026-56765Critical· 9.1
6mo ago

Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR

Vikunja: Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR

▾ Midnightapi · code.vikunja.io/apiEPSS 0.51%via OSV
CVE-2026-33487High· 7.5PoC
6mo ago

goxmlsig provides XML Digital Signatures implemented in Go

goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID.…

▾ Midnightgoxmldsig_project · goxmldsigEPSS 0.42%via NVD
CVE-2026-32285High· 7.5PoC
6mo ago

The Delete function fails to properly validate offsets when processing malformed JSON input

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

▾ Midnightjsonparser_project · jsonparserEPSS 0.97%via NVD
CVE-2026-33809Medium· 5.3
6mo ago

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

▾ Sunlitx · golang.org/x/imageEPSS 0.39%via OSV
CVE-2026-29785High· 7.5
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect …

▾ Twilightlinuxfoundation · nats-serverEPSS 0.97%via NVD
CVE-2026-27602High· 7.2
6mo ago

Modoboa has OS Command Injection

Modoboa has OS Command Injection

▾ Twilightmodoboa · modoboaEPSS 0.69%via OSV
CVE-2025-70887High
6mo ago

Signify allows a remote attacker to escalate privileges via the signed_data.py and the context.py components

Signify allows a remote attacker to escalate privileges via the signed_data.py and the context.py components

▾ Twilightsignify · signifyEPSS 0.34%via OSV
CVE-2026-25645Medium· 4.4PoC
6mo ago

Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function

Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function

▾ Twilightrequests · requestsEPSS 0.18%via OSV
CVE-2026-33699Medium
6mo ago

pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream

pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream

▾ Sunlitpypdf · pypdfEPSS 0.58%via OSV
CVE-2026-33682Medium· 4.7
6mo ago

Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)

Unauthenticated SSRF Vulnerability in Streamlit on Windows (NTLM Credential Exposure)

▾ Sunlitstreamlit · streamlitEPSS 0.41%via OSV
CVE-2026-33634CriticalCISA KEVPoC
6mo ago

Trivy ecosystem supply chain was briefly compromised

Trivy ecosystem supply chain was briefly compromised

▾ Hadalaquasecurity · github.com/aquasecurity/trivyEPSS 1.7%via OSV
CVE-2026-33246Medium· 6.4
6mo ago

NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers

NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers

▾ Sunlitnats-io · github.com/nats-io/nats-server/v2EPSS 0.24%via OSV
CVE-2026-33248Medium· 4.2
6mo ago

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

▾ Sunlitnats-io · github.com/nats-io/nats-server/v2EPSS 0.17%via OSV
CVE-2026-5389High
6mo ago

JustHTML is vulnerable to XSS via code fence breakout in <pre> content

JustHTML is vulnerable to XSS via code fence breakout in <pre> content

▾ Twilightjusthtml · justhtmlEPSS 0.26%via OSV
CVE-2026-24159High· 7.8
6mo ago

NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution

NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution

▾ Twilightnemo-toolkit · nemo-toolkitEPSS 0.64%via OSV
CVE-2026-24157High· 7.8
6mo ago

NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading

NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading

▾ Twilightnemo-toolkit · nemo-toolkitEPSS 0.65%via OSV
CVE-2026-33545Medium· 5.3
6mo ago

MobSF has SQL Injection in its SQLite Database Viewer Utils

MobSF has SQL Injection in its SQLite Database Viewer Utils

▾ Sunlitmobsf · mobsfEPSS 0.40%via OSV
CVE-2026-54685Medium· 5.3
6mo ago

FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel

FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel

▾ Sunlitgtsteffaniak · github.com/gtsteffaniak/filebrowser/backendEPSS 0.47%via OSV
CVEs tagged “osv” — page 85 · VulnSea