VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2026-28222Medium· 6.1
7mo ago

Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes

Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes

▾ Sunlitwagtail · wagtailEPSS 0.59%via OSV
CVE-2026-28223Medium· 6.1
7mo ago

Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interface

Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interface

▾ Sunlitwagtail · wagtailEPSS 0.59%via OSV
CVE-2026-25674Low· 3.7
7mo ago

Django has a Race Condition vulnerability

Django has a Race Condition vulnerability

▾ Sunlitdjango · djangoEPSS 0.33%via OSV
CVE-2026-27905High
7mo ago

BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction

BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction

▾ Twilightbentoml · bentomlEPSS 0.21%via OSV
CVE-2026-27622High· 8.4
7mo ago

OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned in…

▾ TwilightAcademySoftwareFoundation · openexrEPSS 0.21%via CVEORG
CVE-2026-25673High· 7.5
7mo ago

Django vulnerable to Uncontrolled Resource Consumption

Django vulnerable to Uncontrolled Resource Consumption

▾ Twilightdjango · djangoEPSS 1.1%via OSV
CVE-2021-25320Critical· 9.9
7mo ago

Rancher cloud credentials can be used through proxy API by users without access

Rancher cloud credentials can be used through proxy API by users without access

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.85%via OSV
CVE-2022-21951Medium· 6.8
7mo ago

Rancher's weave CNI password is not configured when a cluster is created from an RKE template

Rancher's weave CNI password is not configured when a cluster is created from an RKE template

▾ Sunlitrancher · github.com/rancher/rancherEPSS 0.39%via OSV
CVE-2023-22648High· 8.0
7mo ago

Rancher's Azure AD permission changes are not reflected on active sessions

Rancher's Azure AD permission changes are not reflected on active sessions

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.45%via OSV
CVE-2021-36783Critical· 9.9
7mo ago

Rancher doesn't properly sanitize credentials in cluster template answers

Rancher doesn't properly sanitize credentials in cluster template answers

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.78%via OSV
CVE-2022-31247Critical· 9.1
7mo ago

Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)

Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.98%via OSV
CVE-2026-56315Critical· 9.8
7mo ago

PickleScan has multiple stdlib modules with direct RCE not in blocklist

PickleScan has multiple stdlib modules with direct RCE not in blocklist

▾ Midnightpicklescan · picklescanEPSS 1.1%via OSV
CVE-2026-28350Medium· 6.1
7mo ago

lxml-html-clean has <base> tag injection through default Cleaner configuration

lxml-html-clean has <base> tag injection through default Cleaner configuration

▾ Sunlitlxml-html-clean · lxml-html-cleanEPSS 0.27%via OSV
CVE-2026-27932High· 7.5
7mo ago

joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)

joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)

▾ Twilightjoserfc · joserfcEPSS 0.33%via OSV
CVE-2026-28795High
7mo ago

OpenChatBI has a Path Traversal Vulnerability in save_report Tool

OpenChatBI has a Path Traversal Vulnerability in save_report Tool

▾ Twilightopenchatbi · openchatbiEPSS 0.68%via OSV
CVE-2026-28348Medium· 6.1
7mo ago

lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes

lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes

▾ Sunlitlxml-html-clean · lxml-html-cleanEPSS 0.28%via OSV
CVE-2026-28804Medium
7mo ago

pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams

pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams

▾ Sunlitpypdf · pypdfEPSS 0.52%via OSV
CVE-2026-28438High
7mo ago

CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements

CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements

▾ Twilightcocoindex · cocoindexEPSS 0.50%via OSV
CVE-2026-2256Medium· 6.5PoC
7mo ago

MS-Agent vulnerable to Command Injection

MS-Agent vulnerable to Command Injection

▾ Twilightms-agent · ms-agentEPSS 1.6%via OSV
CVE-2026-28352Medium· 6.5
7mo ago

Indico has a missing access check in the event series management API

Indico has a missing access check in the event series management API

▾ Sunlitindico · indicoEPSS 0.36%via OSV
CVE-2026-28351Medium
7mo ago

pypdf: Manipulated RunLengthDecode streams can exhaust RAM

pypdf: Manipulated RunLengthDecode streams can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.53%via OSV
GHSA-747p-wmpv-9c78Medium· 5.9
7mo ago

AWS CLI: cli_history database does not restrict file permissions on Unix systems

AWS CLI: cli_history database does not restrict file permissions on Unix systems

▾ Sunlitawscli · awsclivia OSV
CVE-2026-28231Critical· 9.1
7mo ago

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the en…

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by provid…

▾ Midnightpi-heif · pi-heifEPSS 0.71%via OSV
CVE-2026-22728Medium· 4.9
7mo ago

Sealed Secrets for Kubernetes: Rotate API Allows Scope Widening from Strict/Namespace-Wide to Cluster-Wide via Untrusted Template Annotat…

Sealed Secrets for Kubernetes: Rotate API Allows Scope Widening from Strict/Namespace-Wide to Cluster-Wide via Untrusted Template Annotations

▾ Sunlitbitnami-labs · github.com/bitnami-labs/sealed-secretsEPSS 0.36%via OSV
CVE-2026-27941Critical· 9.9PoC
7mo ago

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repo…

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from fork…

▾ Abyssalopenlit · openlitEPSS 0.57%via OSV
CVE-2026-27835Medium· 4.3
7mo ago

wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data

wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data

▾ Sunlitwger · wgerEPSS 0.30%via OSV
CVE-2026-27888Medium
7mo ago

pypdf: Manipulated FlateDecode XFA streams can exhaust RAM

pypdf: Manipulated FlateDecode XFA streams can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.64%via OSV
CVE-2026-27457Medium· 4.3
7mo ago

Weblate: Missing access control for the AddonViewSet API exposes all addon configurations

Weblate: Missing access control for the AddonViewSet API exposes all addon configurations

▾ Sunlitweblate · weblateEPSS 0.42%via OSV
CVE-2026-27735Medium
7mo ago

mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries

mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries

▾ Sunlitmcp-server-git · mcp-server-gitEPSS 0.45%via OSV
CVE-2026-27839Medium· 4.3
7mo ago

wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup

wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup

▾ Sunlitwger · wgerEPSS 0.31%via OSV
CVEs tagged “osv” — page 89 · VulnSea