VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2026-25122Medium· 5.5
7mo ago

apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams

apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams

▾ Sunlitapko · chainguard.dev/apkoEPSS 0.11%via OSV
CVE-2026-25121High· 7.5
7mo ago

apko has a path traversal in apko dirFS which allows filesystem writes outside base

apko has a path traversal in apko dirFS which allows filesystem writes outside base

▾ Twilightapko · chainguard.dev/apkoEPSS 0.39%via OSV
CVE-2025-64712Critical· 9.8
7mo ago

Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write

Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write

▾ Midnightunstructured · unstructuredEPSS 0.64%via OSV
CVE-2026-1285Low
7mo ago

Django has Inefficient Algorithmic Complexity

Django has Inefficient Algorithmic Complexity

▾ Sunlitdjango · djangoEPSS 1.1%via OSV
CVE-2025-14550Low
7mo ago

Django has Inefficient Algorithmic Complexity

Django has Inefficient Algorithmic Complexity

▾ Sunlitdjango · djangoEPSS 1.1%via OSV
CVE-2025-13473Low
7mo ago

Django has Observable Timing Discrepancy

Django has Observable Timing Discrepancy

▾ Sunlitdjango · djangoEPSS 0.76%via OSV
CVE-2025-70560High· 8.4
7mo ago

Boltz contains an insecure deserialization vulnerability in its molecule loading functionality

Boltz contains an insecure deserialization vulnerability in its molecule loading functionality

▾ Twilightboltz · boltzEPSS 0.15%via OSV
CVE-2026-25517Medium
7mo ago

Wagtail has improper permission handling on admin preview endpoints

Wagtail has improper permission handling on admin preview endpoints

▾ Sunlitwagtail · wagtailEPSS 0.45%via OSV
CVE-2026-1312Medium· 5.4PoC
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject to SQL injection in column aliases containing periods when the same alias is, using a suitably crafted dictionary, w…

▾ Twilightdjangoproject · djangoEPSS 0.85%via NVD
CVE-2026-1287Medium· 5.4
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansio…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to SQL injection in column aliases via control characters, using a suitably crafted dictionary, with dictionary expansio…

▾ Sunlitdjangoproject · djangoEPSS 0.80%via NVD
CVE-2026-1207Medium· 5.4PoC
7mo ago

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField`` (only implemented on PostGIS) allows remote attackers to inject SQL via the band index parameter. Earlier, unsupport…

▾ Twilightdjangoproject · djangoEPSS 13%via NVD
CVE-2026-56304Medium
8mo ago

picklescan vulnerable to arbitrary file create using logging.FileHandler

picklescan vulnerable to arbitrary file create using logging.FileHandler

▾ Sunlitpicklescan · picklescanEPSS 0.44%via OSV
CVE-2025-70960Medium· 5.4
8mo ago

A stored cross-site scripting (XSS) vulnerability in the Forums module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web …

A stored cross-site scripting (XSS) vulnerability in the Forums module of Tendenci CMS v15.3.7 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

▾ Sunlittendenci · tendenciEPSS 0.25%via OSV
CVE-2026-25481Critical
8mo ago

Langroid has WAF Bypass Leading to RCE in TableChatAgent

Langroid has WAF Bypass Leading to RCE in TableChatAgent

▾ Midnightlangroid · langroidEPSS 0.73%via OSV
CVE-2026-1777High· 7.2
8mo ago

SageMaker Python SDK has Exposed HMAC

SageMaker Python SDK has Exposed HMAC

▾ Twilightsagemaker · sagemakerEPSS 0.48%via OSV
CVE-2026-0599High· 7.5
8mo ago

Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption

Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption

▾ Twilighttext-generation · text-generationEPSS 28%via OSV
CVE-2026-53874High
8mo ago

picklescan missing detection by simple obfuscation of a `builtins.eval` call

picklescan missing detection by simple obfuscation of a `builtins.eval` call

▾ Twilightpicklescan · picklescanEPSS 0.76%via OSV
CVE-2026-1117High· 8.2
8mo ago

Lollms has an Improper Access Control vulnerability

Lollms has an Improper Access Control vulnerability

▾ Twilightlollms · lollmsEPSS 0.56%via OSV
CVE-2025-69207Medium· 5.4
8mo ago

Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning

Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning

▾ Sunlitkhoj · khojEPSS 0.38%via OSV
CVE-2026-1703Low
8mo ago

pip Path Traversal vulnerability

pip Path Traversal vulnerability

▾ Sunlitpip · pipEPSS 0.41%via OSV
CVE-2026-1778Medium· 5.9
8mo ago

SageMaker Python SDK has Insecure TLS Configuration

SageMaker Python SDK has Insecure TLS Configuration

▾ Sunlitsagemaker · sagemakerEPSS 0.25%via OSV
CVE-2025-10279High· 7.0
8mo ago

mlflow Creates of Temporary File in Directory with Insecure Permissions

mlflow Creates of Temporary File in Directory with Insecure Permissions

▾ Twilightmlflow · mlflowEPSS 0.23%via OSV
CVE-2025-6208Medium· 5.3
8mo ago

llama-index-core vulnerable to Uncontrolled Resource Consumption

llama-index-core vulnerable to Uncontrolled Resource Consumption

▾ Sunlitllama-index-core · llama-index-coreEPSS 0.39%via OSV
CVE-2026-22778Critical· 9.8PoC
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…

▾ Abyssalvllm · vllmEPSS 10%via NVD
MAL-2026-623None
8mo ago

Malicious code in marshl (PyPI)

Malicious code in marshl (PyPI)

▾ Sunlitmarshl · marshlvia OSV
CVE-2026-25211Low· 3.2PoC
8mo ago

Llama Stack exposes secret in initialization log

Llama Stack exposes secret in initialization log

▾ Twilightllama-stack · llama-stackEPSS 0.24%via OSV
CVE-2025-62349Medium· 6.2
8mo ago

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

▾ Sunlitsalt · saltEPSS 0.46%via OSV
CVE-2025-62348High· 7.8
8mo ago

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

▾ Twilightsalt · saltEPSS 0.20%via OSV
CVE-2026-24780High
8mo ago

AutoGPT is Vulnerable to RCE via Disabled Block Execution

AutoGPT is Vulnerable to RCE via Disabled Block Execution

▾ Twilightagpt · agptEPSS 1.3%via OSV
CVE-2025-61730Medium· 5.3
8mo ago

crypto/tls: Handshake messages may be processed at the incorrect encryption level in crypto/tls (CVE-2025-61730)

A TLS connection handling flaw has been discovered in the golang crypto/tls library. During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted E…

▾ SunlitRed Hat · Red Hat Ceph Storage 6EPSS 0.33%via CSAF
CVEs tagged “osv” — page 93 · VulnSea