Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2026-2473HighGoogle Cloud Vertex AI has a a vulnerability involving predictable bucket naming
Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
CVE-2026-2472HighPoCGoogle Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
CVE-2026-27482Medium· 5.9Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
CVE-2026-24834High· 8.8Kata Container to Guest micro VM privilege escalation
Kata Container to Guest micro VM privilege escalation
CVE-2026-25527Medium· 5.3PoCchangedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` ro…
changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This…
CVE-2026-27194HighD-Tale affected by Remote Code Execution through the /save-column-filter endpoint
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
CVE-2026-27205LowFlask session does not add `Vary: Cookie` header when accessed in some ways
Flask session does not add `Vary: Cookie` header when accessed in some ways
CVE-2026-27199MediumPoCWerkzeug safe_join() allows Windows special device names
Werkzeug safe_join() allows Windows special device names
CVE-2026-27017LowuTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots
uTLS has a fingerprint vulnerability from GREASE ECH mismatch for Chrome parrots
MAL-2026-937NoneMalicious code in telebot-infee (PyPI)
Malicious code in telebot-infee (PyPI)
MAL-2026-935NoneMalicious code in telebot-infoo (PyPI)
Malicious code in telebot-infoo (PyPI)
MAL-2026-934NoneMalicious code in telebot-infoe (PyPI)
Malicious code in telebot-infoe (PyPI)
CVE-2026-27025Mediumpypdf has possible long runtimes/large memory usage for large /ToUnicode streams
pypdf has possible long runtimes/large memory usage for large /ToUnicode streams
CVE-2026-2654Medium· 6.3Hugging Face Smolagents has a Server-Side Request Forgery issue
Hugging Face Smolagents has a Server-Side Request Forgery issue
CVE-2025-33253High· 7.8NVIDIA NeMo Framework Deserializes Untrusted Data
NVIDIA NeMo Framework Deserializes Untrusted Data
CVE-2026-27026Mediumpypdf possibly has long runtimes for malformed FlateDecode streams
pypdf possibly has long runtimes for malformed FlateDecode streams
CVE-2026-27024Mediumpypdf has a possible infinite loop when processing TreeObject
pypdf has a possible infinite loop when processing TreeObject
CVE-2026-53875HighPicklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
CVE-2025-33245High· 8.0NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution
CVE-2025-14009High· 8.8A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions
A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This a…
CVE-2026-25087High· 7.0Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
MAL-2026-931NoneMalicious code in telebot-infe (PyPI)
Malicious code in telebot-infe (PyPI)
MAL-2026-930NoneMalicious code in telebot-info (PyPI)
Malicious code in telebot-info (PyPI)
CVE-2026-26057Medium· 6.5Skill-scanner Unsecured Network Binding Vulnerability
Skill-scanner Unsecured Network Binding Vulnerability
CVE-2026-25739Medium· 5.4Indico Affected by Cross-Site-Scripting via material uploads
Indico Affected by Cross-Site-Scripting via material uploads
CVE-2026-25738MediumIndico has Server-Side Request Forgery (SSRF) in multiple places
Indico has Server-Side Request Forgery (SSRF) in multiple places
CVE-2026-24126Medium· 6.6PoCWeblate has an argument injection in management console
Weblate has an argument injection in management console
GHSA-27jp-wm6q-gp25Mediumsqlparse: formatting list of tuples leads to denial of service
sqlparse: formatting list of tuples leads to denial of service
CVE-2025-67860Low· 3.8NeuVector scanner insecurely handles passwords as command arguments
NeuVector scanner insecurely handles passwords as command arguments
CVE-2026-21438Medium· 5.3webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map
webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map