VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2026-33046High
6mo ago

Indico discloses local files resulting in Remote Code Execution through LaTeX injection

Indico discloses local files resulting in Remote Code Execution through LaTeX injection

▾ Twilightindico · indicoEPSS 1.0%via OSV
CVE-2026-26209Medium· 5.5⚖ disputed
6mo ago

cbor2: cbor2: Denial of Service due to uncontrolled recursion via crafted CBOR payloads (CVE-2026-26209)

A flaw was found in cbor2, a library for encoding and decoding Concise Binary Object Representation (CBOR) data. A remote attacker can exploit this vulnerability by sending a specially crafted CBOR payload containing deeply nested structur…

▾ SunlitRed Hat · Red Hat Enterprise Linux AI (RHEL AI) 3EPSS 0.65%via CSAF
CVE-2026-4539Low· 3.3
6mo ago

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

▾ Sunlitpygments · pygmentsEPSS 0.16%via OSV
CVE-2026-4506Medium· 6.3
6mo ago

MindSQL is vulnerable to Code Injection through its ask_db function

MindSQL is vulnerable to Code Injection through its ask_db function

▾ Sunlitmindsql · mindsqlEPSS 0.39%via OSV
CVE-2026-33022Medium· 6.5
6mo ago

github.com/tektoncd/pipeline: Tekton Pipelines: Denial of Service via long resolver names (CVE-2026-33022)

A denial of service flaw was found in Tekton Pipelines. Any user who can create a TaskRun or PipelineRun to crash the controller cluster-wide by setting .spec.taskRef.resolver (or .spec.pipelineRef.resolver) to a string of 31+ characters. …

▾ SunlitRed Hat · OpenShift PipelinesEPSS 0.45%via CSAF
RUSTSEC-2026-0049None
6mo ago

CRLs not considered authoritative by Distribution Point due to faulty matching logic

CRLs not considered authoritative by Distribution Point due to faulty matching logic

▾ Sunlitrustls-webpki · rustls-webpkivia OSV
CVE-2026-32711High· 7.8
6mo ago

pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root

pydicom has a path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root

▾ Twilightpydicom · pydicomEPSS 0.22%via OSV
CVE-2026-33154High· 7.5PoC
6mo ago

dynaconf: jinja2: Dynaconf: Arbitrary code execution via Server-Side Template Injection (CVE-2026-33154)

A flaw was found in dynaconf, a Python configuration management tool. This Server-Side Template Injection (SSTI) vulnerability occurs due to unsafe template evaluation in the @Jinja resolver when the jinja2 package is installed. A remote a…

▾ MidnightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.57%via CSAF
CVE-2026-33236High· 8.1
6mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the…

▾ Twilightnltk · nltkEPSS 0.71%via NVD
CVE-2026-33231High· 7.5PoC
6mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthentic…

▾ Midnightnltk · nltkEPSS 1.5%via NVD
CVE-2026-33509High· 7.5
6mo ago

pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration

pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration

▾ Twilightpyload-ng · pyload-ngEPSS 0.58%via OSV
CVE-2026-33322Critical
6mo ago

MinIO has JWT Algorithm Confusion in OIDC Authentication

MinIO has JWT Algorithm Confusion in OIDC Authentication

▾ Midnightminio · github.com/minio/minioEPSS 0.61%via OSV
CVE-2026-33320Medium· 6.2PoC
6mo ago

Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service

Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service

▾ Twilighttomwright · github.com/tomwright/dasel/v3EPSS 0.17%via OSV
CVE-2026-26933Medium· 5.7
6mo ago

Packetbeat does not properly validate an array index in multiple protocol parser components

Packetbeat does not properly validate an array index in multiple protocol parser components

▾ Sunlitelastic · github.com/elastic/beats/v7EPSS 0.29%via OSV
CVE-2026-26931Medium· 5.7
6mo ago

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

▾ Sunlitelastic · metricbeatEPSS 0.29%via NVD
CVE-2026-33332Medium· 5.3
6mo ago

NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustion

NiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustion

▾ Sunlitnicegui · niceguiEPSS 0.69%via OSV
CVE-2025-15031High· 8.1
6mo ago

Arbitrary file write via tar traversal in mlflow

Arbitrary file write via tar traversal in mlflow

▾ Twilightmlflow · mlflowEPSS 0.85%via OSV
CVE-2026-27953High· 7.1
6mo ago

ormar Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model Constructor

ormar Pydantic Validation Bypass via __pk_only__ and __excluded__ Kwargs Injection in Model Constructor

▾ Twilightormar · ormarEPSS 0.91%via OSV
CVE-2026-32889Medium· 6.5
6mo ago

Denial of service via non-terminating SYLT frame parsing loop in tinytag

Denial of service via non-terminating SYLT frame parsing loop in tinytag

▾ Sunlittinytag · tinytagEPSS 0.49%via OSV
CVE-2026-3029Medium
6mo ago

PyMuPDF has a path traversal in _main_.py

PyMuPDF has a path traversal in _main_.py

▾ Sunlitpymupdf · pymupdfEPSS 0.41%via OSV
CVE-2026-33310High· 8.8PoC
6mo ago

Intake has a Command Injection via shell() Expansion in Parameter Defaults

Intake has a Command Injection via shell() Expansion in Parameter Defaults

▾ Midnightintake · intakeEPSS 0.49%via OSV
CVE-2026-32761Medium· 6.5
6mo ago

File Browser has an Authorization Policy Bypass in Public Share Download Flow

File Browser has an Authorization Policy Bypass in Public Share Download Flow

▾ Sunlithttps: · https://github.com/filebrowser/filebrowserEPSS 0.46%via OSV
CVE-2026-8630Medium
6mo ago

JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)

JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)

▾ Sunlitjusthtml · justhtmlEPSS 0.26%via OSV
CVE-2026-8445Medium
6mo ago

JustHTML has a Sanitizer Bypass (in Markdown)

JustHTML has a Sanitizer Bypass (in Markdown)

▾ Sunlitjusthtml · justhtmlEPSS 0.64%via OSV
CVE-2026-32874High· 7.5
6mo ago

UltraJSON has a Memory Leak parsing large integers allows DoS

UltraJSON has a Memory Leak parsing large integers allows DoS

▾ Twilightujson · ujsonEPSS 0.68%via OSV
CVE-2026-33125High· 7.1
6mo ago

Frigte has broken access control viewer user can delete admin and other users account

Frigte has broken access control viewer user can delete admin and other users account

▾ Twilightfrigate · frigateEPSS 0.37%via OSV
CVE-2026-33139High
6mo ago

PySpector has a Plugin Sandbox Bypass leads to Arbitrary Code Execution

PySpector has a Plugin Sandbox Bypass leads to Arbitrary Code Execution

▾ Twilightpyspector · pyspectorEPSS 0.18%via OSV
CVE-2026-33123Medium
6mo ago

pypdf has inefficient decoding of array-based streams

pypdf has inefficient decoding of array-based streams

▾ Sunlitpypdf · pypdfEPSS 0.37%via OSV
CVE-2026-30922High· 7.5PoC
6mo ago

pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)

An unbounded recursion flaw has been discovered in the pypi pyasn1 library. This uncontrolled recursion occurs when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing nested SEQUENCE (0x3…

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.93%via CSAF
CVE-2026-33230Medium· 6.1
6mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk

▾ Sunlitnltk · nltkEPSS 0.39%via OSV
CVEs tagged “osv” — page 86 · VulnSea