Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2026-27948Medium· 5.4Copyparty vulnerable to reflected XSS via setck parameter
Copyparty vulnerable to reflected XSS via setck parameter
CVE-2026-27838Low· 3.1wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
CVE-2026-27809Mediumpsd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
CVE-2026-26717Medium· 4.8PoCOpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
CVE-2026-25733High· 7.3Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
CVE-2026-27645Medium· 6.1PoCchangedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
CVE-2026-27794Medium· 6.6LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution
LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution
CVE-2026-25734Medium· 6.1Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
CVE-2026-25136High· 8.1Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
CVE-2026-25736Medium· 6.1Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
CVE-2026-25735Medium· 6.1Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
CVE-2026-27695Medium· 4.3zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service
zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service
CVE-2026-27696High· 8.6changedetection.io is Vulnerable to SSRF via Watch URLs
changedetection.io is Vulnerable to SSRF via Watch URLs
CVE-2026-25138Medium· 5.3Rucio WebUI has Username Enumeration via Login Error Message
Rucio WebUI has Username Enumeration via Login Error Message
CVE-2026-27628High· 7.5pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams (CVE-2026-27628)
A flaw was found in pypdf. Processing a specially crafted PDF document, specifically with circular /Prev references in the cross-reference (xref) chain, can cause an infinite loop and a high consumption of CPU, resulting in a denial of ser…
CVE-2024-56373High· 8.4Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
CVE-2026-23984HighApache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
CVE-2026-23983LowApache Superset allows authenticated users to view sensitive data without explicit permissions
Apache Superset allows authenticated users to view sensitive data without explicit permissions
CVE-2026-23980MediumPoCApache Superset allows privileged users to conduct error-based SQL Injection
Apache Superset allows privileged users to conduct error-based SQL Injection
CVE-2026-27469Medium· 6.1Isso affected by Stored XSS via comment website field
Isso affected by Stored XSS via comment website field
CVE-2025-27555Medium· 6.5Apache Airflow exposes sensitive information in its log files
Apache Airflow exposes sensitive information in its log files
CVE-2026-27156Medium· 6.1NiceGUI vulnerable to XSS via Code Injection during client-side element function execution
NiceGUI vulnerable to XSS via Code Injection during client-side element function execution
CVE-2026-23969MediumApache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
CVE-2026-27483High· 8.8PoCMindsDB: Path Traversal in /api/files Leading to Remote Code Execution
MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
CVE-2026-23982HighApache Superset Improper Authorization allows low-privileged users to bypass access controls
Apache Superset Improper Authorization allows low-privileged users to bypass access controls
CVE-2026-2969Medium· 4.7datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler
datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler
CVE-2026-2970Medium· 4.6datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache
datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache
CVE-2026-26331High· 8.8PoCyt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
CVE-2026-2033High· 8.10dayMLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
CVE-2025-65995Medium· 6.5Apache Airflow error reporting may expose full kwargs
Apache Airflow error reporting may expose full kwargs