VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2026-27948Medium· 5.4
7mo ago

Copyparty vulnerable to reflected XSS via setck parameter

Copyparty vulnerable to reflected XSS via setck parameter

▾ Sunlitcopyparty · copypartyEPSS 0.27%via OSV
CVE-2026-27838Low· 3.1
7mo ago

wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

▾ Sunlitwger · wgerEPSS 0.25%via OSV
CVE-2026-27809Medium
7mo ago

psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps

psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps

▾ Sunlitpsd-tools · psd-toolsEPSS 0.69%via OSV
CVE-2026-26717Medium· 4.8PoC
7mo ago

OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function

OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function

▾ Twilightrichie · richieEPSS 0.51%via OSV
CVE-2026-25733High· 7.3
7mo ago

Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function

Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function

▾ Twilightrucio-webui · rucio-webuiEPSS 0.41%via OSV
CVE-2026-27645Medium· 6.1PoC
7mo ago

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.49%via OSV
CVE-2026-27794Medium· 6.6
7mo ago

LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution

LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution

▾ Sunlitlanggraph-checkpoint · langgraph-checkpointEPSS 0.96%via OSV
CVE-2026-25734Medium· 6.1
7mo ago

Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata

Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata

▾ Sunlitrucio-webui · rucio-webuiEPSS 0.46%via OSV
CVE-2026-25136High· 8.1
7mo ago

Rucio WebUI has a Reflected Cross-site Scripting Vulnerability

Rucio WebUI has a Reflected Cross-site Scripting Vulnerability

▾ Twilightrucio-webui · rucio-webuiEPSS 0.27%via OSV
CVE-2026-25736Medium· 6.1
7mo ago

Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute

Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute

▾ Sunlitrucio-webui · rucio-webuiEPSS 0.46%via OSV
CVE-2026-25735Medium· 6.1
7mo ago

Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name

Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name

▾ Sunlitrucio-webui · rucio-webuiEPSS 0.46%via OSV
CVE-2026-27695Medium· 4.3
7mo ago

zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service

zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service

▾ Sunlitzae-limiter · zae-limiterEPSS 0.40%via OSV
CVE-2026-27696High· 8.6
7mo ago

changedetection.io is Vulnerable to SSRF via Watch URLs

changedetection.io is Vulnerable to SSRF via Watch URLs

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.48%via OSV
CVE-2026-25138Medium· 5.3
7mo ago

Rucio WebUI has Username Enumeration via Login Error Message

Rucio WebUI has Username Enumeration via Login Error Message

▾ Sunlitrucio-webui · rucio-webuiEPSS 0.33%via OSV
CVE-2026-27628High· 7.5
7mo ago

pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams (CVE-2026-27628)

A flaw was found in pypdf. Processing a specially crafted PDF document, specifically with circular /Prev references in the cross-reference (xref) chain, can cause an infinite loop and a high consumption of CPU, resulting in a denial of ser…

▾ TwilightRed Hat · Red Hat Quay 3.16EPSS 0.61%via CSAF
CVE-2024-56373High· 8.4
7mo ago

Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table

Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table

▾ Twilightapache-airflow · apache-airflowEPSS 1.1%via OSV
CVE-2026-23984High
7mo ago

Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections

Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections

▾ Twilightapache-superset · apache-supersetEPSS 0.36%via OSV
CVE-2026-23983Low
7mo ago

Apache Superset allows authenticated users to view sensitive data without explicit permissions

Apache Superset allows authenticated users to view sensitive data without explicit permissions

▾ Sunlitapache-superset · apache-supersetEPSS 0.42%via OSV
CVE-2026-23980MediumPoC
7mo ago

Apache Superset allows privileged users to conduct error-based SQL Injection

Apache Superset allows privileged users to conduct error-based SQL Injection

▾ Twilightapache-superset · apache-supersetEPSS 0.65%via OSV
CVE-2026-27469Medium· 6.1
7mo ago

Isso affected by Stored XSS via comment website field

Isso affected by Stored XSS via comment website field

▾ Sunlitisso · issoEPSS 0.37%via OSV
CVE-2025-27555Medium· 6.5
7mo ago

Apache Airflow exposes sensitive information in its log files

Apache Airflow exposes sensitive information in its log files

▾ Sunlitapache-airflow · apache-airflowEPSS 0.37%via OSV
CVE-2026-27156Medium· 6.1
7mo ago

NiceGUI vulnerable to XSS via Code Injection during client-side element function execution

NiceGUI vulnerable to XSS via Code Injection during client-side element function execution

▾ Sunlitnicegui · niceguiEPSS 0.27%via OSV
CVE-2026-23969Medium
7mo ago

Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine

Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine

▾ Sunlitapache-superset · apache-supersetEPSS 0.62%via OSV
CVE-2026-27483High· 8.8PoC
7mo ago

MindsDB: Path Traversal in /api/files Leading to Remote Code Execution

MindsDB: Path Traversal in /api/files Leading to Remote Code Execution

▾ Midnightmindsdb · mindsdbEPSS 8.8%via OSV
CVE-2026-23982High
7mo ago

Apache Superset Improper Authorization allows low-privileged users to bypass access controls

Apache Superset Improper Authorization allows low-privileged users to bypass access controls

▾ Twilightapache-superset · apache-supersetEPSS 0.45%via OSV
CVE-2026-2969Medium· 4.7
7mo ago

datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler

datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler

▾ Sunlitdatapizza-ai-core · datapizza-ai-coreEPSS 0.79%via OSV
CVE-2026-2970Medium· 4.6
7mo ago

datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache

datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache

▾ Sunlitdatapizza-ai-core · datapizza-ai-coreEPSS 1.1%via OSV
CVE-2026-26331High· 8.8PoC
7mo ago

yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

▾ Midnightyt-dlp · yt-dlpEPSS 2.0%via OSV
CVE-2026-2033High· 8.10day
7mo ago

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

▾ Abyssalmlflow · mlflowEPSS 1.7%via OSV
CVE-2025-65995Medium· 6.5
7mo ago

Apache Airflow error reporting may expose full kwargs

Apache Airflow error reporting may expose full kwargs

▾ Sunlitapache-airflow · apache-airflowEPSS 0.81%via OSV
CVEs tagged “osv” — page 90 · VulnSea