VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2026-2473High
7mo ago

Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming

Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming

▾ Twilightgoogle-cloud-aiplatform · google-cloud-aiplatformEPSS 0.46%via OSV
CVE-2026-2472HighPoC
7mo ago

Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)

Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)

▾ Midnightgoogle-cloud-aiplatform · google-cloud-aiplatformEPSS 0.54%via OSV
CVE-2026-27482Medium· 5.9
7mo ago

Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)

Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)

▾ Sunlitray · rayEPSS 0.40%via OSV
CVE-2026-24834High· 8.8
7mo ago

Kata Container to Guest micro VM privilege escalation

Kata Container to Guest micro VM privilege escalation

▾ Twilightkata-containers · github.com/kata-containers/kata-containers/src/runtimeEPSS 0.22%via OSV
CVE-2026-25527Medium· 5.3PoC
7mo ago

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` ro…

changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This…

▾ Twilightchangedetection-io · changedetection-ioEPSS 0.89%via OSV
CVE-2026-27194High
7mo ago

D-Tale affected by Remote Code Execution through the /save-column-filter endpoint

D-Tale affected by Remote Code Execution through the /save-column-filter endpoint

▾ Twilightdtale · dtaleEPSS 0.96%via OSV
CVE-2026-27205Low
7mo ago

Flask session does not add `Vary: Cookie` header when accessed in some ways

Flask session does not add `Vary: Cookie` header when accessed in some ways

▾ Sunlitflask · flaskEPSS 0.42%via OSV
CVE-2026-27199MediumPoC
7mo ago

Werkzeug safe_join() allows Windows special device names

Werkzeug safe_join() allows Windows special device names

▾ Twilightwerkzeug · werkzeugEPSS 0.54%via OSV
CVE-2026-27017Low
7mo ago

uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots

uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots

▾ Sunlitrefraction-networking · github.com/refraction-networking/utlsEPSS 0.19%via OSV
MAL-2026-937None
7mo ago

Malicious code in telebot-infee (PyPI)

Malicious code in telebot-infee (PyPI)

▾ Sunlittelebot-infee · telebot-infeevia OSV
MAL-2026-935None
7mo ago

Malicious code in telebot-infoo (PyPI)

Malicious code in telebot-infoo (PyPI)

▾ Sunlittelebot-infoo · telebot-infoovia OSV
MAL-2026-934None
7mo ago

Malicious code in telebot-infoe (PyPI)

Malicious code in telebot-infoe (PyPI)

▾ Sunlittelebot-infoe · telebot-infoevia OSV
CVE-2026-27025Medium
7mo ago

pypdf has possible long runtimes/large memory usage for large /ToUnicode streams

pypdf has possible long runtimes/large memory usage for large /ToUnicode streams

▾ Sunlitpypdf · pypdfEPSS 0.18%via OSV
CVE-2026-2654Medium· 6.3
7mo ago

Hugging Face Smolagents has a Server-Side Request Forgery issue

Hugging Face Smolagents has a Server-Side Request Forgery issue

▾ Sunlitsmolagents · smolagentsEPSS 0.55%via OSV
CVE-2025-33253High· 7.8
7mo ago

NVIDIA NeMo Framework Deserializes Untrusted Data

NVIDIA NeMo Framework Deserializes Untrusted Data

▾ Twilightnemo-toolkit · nemo-toolkitEPSS 0.19%via OSV
CVE-2026-27026Medium
7mo ago

pypdf possibly has long runtimes for malformed FlateDecode streams

pypdf possibly has long runtimes for malformed FlateDecode streams

▾ Sunlitpypdf · pypdfEPSS 0.18%via OSV
CVE-2026-27024Medium
7mo ago

pypdf has a possible infinite loop when processing TreeObject

pypdf has a possible infinite loop when processing TreeObject

▾ Sunlitpypdf · pypdfEPSS 0.18%via OSV
CVE-2026-53875High
7mo ago

Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

▾ Twilightpicklescan · picklescanEPSS 0.69%via OSV
CVE-2025-33245High· 8.0
7mo ago

NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution

NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution

▾ Twilightnemo-toolkit · nemo-toolkitEPSS 0.54%via OSV
CVE-2025-14009High· 8.8
7mo ago

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This a…

▾ Twilightnltk · nltkEPSS 0.95%via NVD
CVE-2026-25087High· 7.0
7mo ago

Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering

Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering

▾ Twilightpyarrow · pyarrowEPSS 0.82%via OSV
MAL-2026-931None
7mo ago

Malicious code in telebot-infe (PyPI)

Malicious code in telebot-infe (PyPI)

▾ Sunlittelebot-infe · telebot-infevia OSV
MAL-2026-930None
7mo ago

Malicious code in telebot-info (PyPI)

Malicious code in telebot-info (PyPI)

▾ Sunlittelebot-info · telebot-infovia OSV
CVE-2026-26057Medium· 6.5
7mo ago

Skill-scanner Unsecured Network Binding Vulnerability

Skill-scanner Unsecured Network Binding Vulnerability

▾ Sunlitcisco-ai-skill-scanner · cisco-ai-skill-scannerEPSS 0.45%via OSV
CVE-2026-25739Medium· 5.4
7mo ago

Indico Affected by Cross-Site-Scripting via material uploads

Indico Affected by Cross-Site-Scripting via material uploads

▾ Sunlitindico · indicoEPSS 0.29%via OSV
CVE-2026-25738Medium
7mo ago

Indico has Server-Side Request Forgery (SSRF) in multiple places

Indico has Server-Side Request Forgery (SSRF) in multiple places

▾ Sunlitindico · indicoEPSS 0.33%via OSV
CVE-2026-24126Medium· 6.6PoC
7mo ago

Weblate has an argument injection in management console

Weblate has an argument injection in management console

▾ Twilightweblate · weblateEPSS 0.47%via OSV
GHSA-27jp-wm6q-gp25Medium
7mo ago

sqlparse: formatting list of tuples leads to denial of service

sqlparse: formatting list of tuples leads to denial of service

▾ Sunlitsqlparse · sqlparsevia OSV
CVE-2025-67860Low· 3.8
7mo ago

NeuVector scanner insecurely handles passwords as command arguments

NeuVector scanner insecurely handles passwords as command arguments

▾ Sunlitneuvector · github.com/neuvector/scannerEPSS 0.09%via OSV
CVE-2026-21438Medium· 5.3
7mo ago

webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map

webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map

▾ Sunlitquic-go · github.com/quic-go/webtransport-goEPSS 0.38%via OSV
CVEs tagged “osv” — page 91 · VulnSea