Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2026-28222Medium· 6.1Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes
Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes
CVE-2026-28223Medium· 6.1Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interface
Wagtail Vulnerable to Cross-site Scripting in simple_translation admin interface
CVE-2026-25674Low· 3.7Django has a Race Condition vulnerability
Django has a Race Condition vulnerability
CVE-2026-27905HighBentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction
BentoML Vulnerable to Arbitrary File Write via Symlink Path Traversal in Tar Extraction
CVE-2026-27622High· 8.4OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned in…
CVE-2026-25673High· 7.5Django vulnerable to Uncontrolled Resource Consumption
Django vulnerable to Uncontrolled Resource Consumption
CVE-2021-25320Critical· 9.9Rancher cloud credentials can be used through proxy API by users without access
Rancher cloud credentials can be used through proxy API by users without access
CVE-2022-21951Medium· 6.8Rancher's weave CNI password is not configured when a cluster is created from an RKE template
Rancher's weave CNI password is not configured when a cluster is created from an RKE template
CVE-2023-22648High· 8.0Rancher's Azure AD permission changes are not reflected on active sessions
Rancher's Azure AD permission changes are not reflected on active sessions
CVE-2021-36783Critical· 9.9Rancher doesn't properly sanitize credentials in cluster template answers
Rancher doesn't properly sanitize credentials in cluster template answers
CVE-2022-31247Critical· 9.1Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
CVE-2026-56315Critical· 9.8PickleScan has multiple stdlib modules with direct RCE not in blocklist
PickleScan has multiple stdlib modules with direct RCE not in blocklist
CVE-2026-28350Medium· 6.1lxml-html-clean has <base> tag injection through default Cleaner configuration
lxml-html-clean has <base> tag injection through default Cleaner configuration
CVE-2026-27932High· 7.5joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)
joserfc's PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)
CVE-2026-28795HighOpenChatBI has a Path Traversal Vulnerability in save_report Tool
OpenChatBI has a Path Traversal Vulnerability in save_report Tool
CVE-2026-28348Medium· 6.1lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes
lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes
CVE-2026-28804Mediumpypdf vulnerable to inefficient decoding of ASCIIHexDecode streams
pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams
CVE-2026-28438HighCocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements
CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements
CVE-2026-2256Medium· 6.5PoCMS-Agent vulnerable to Command Injection
MS-Agent vulnerable to Command Injection
CVE-2026-28352Medium· 6.5Indico has a missing access check in the event series management API
Indico has a missing access check in the event series management API
CVE-2026-28351Mediumpypdf: Manipulated RunLengthDecode streams can exhaust RAM
pypdf: Manipulated RunLengthDecode streams can exhaust RAM
GHSA-747p-wmpv-9c78Medium· 5.9AWS CLI: cli_history database does not restrict file permissions on Unix systems
AWS CLI: cli_history database does not restrict file permissions on Unix systems
CVE-2026-28231Critical· 9.1pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the en…
pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by provid…
CVE-2026-22728Medium· 4.9Sealed Secrets for Kubernetes: Rotate API Allows Scope Widening from Strict/Namespace-Wide to Cluster-Wide via Untrusted Template Annotat…
Sealed Secrets for Kubernetes: Rotate API Allows Scope Widening from Strict/Namespace-Wide to Cluster-Wide via Untrusted Template Annotations
CVE-2026-27941Critical· 9.9PoCOpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repo…
OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from fork…
CVE-2026-27835Medium· 4.3wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
CVE-2026-27888Mediumpypdf: Manipulated FlateDecode XFA streams can exhaust RAM
pypdf: Manipulated FlateDecode XFA streams can exhaust RAM
CVE-2026-27457Medium· 4.3Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
CVE-2026-27735Mediummcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
CVE-2026-27839Medium· 4.3wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup
wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup