VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5710 CVEsRSS

CVE-2026-23877Medium
8mo ago

Swing Music has a Directory Traversal & Filesystem can be accessed by a non-admin user

Swing Music has a Directory Traversal & Filesystem can be accessed by a non-admin user

▾ Sunlitswingmusic · swingmusicEPSS 0.58%via OSV
CVE-2026-23996Low· 3.7
8mo ago

FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection

FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection

▾ Sunlitfastapi-api-key · fastapi-api-keyEPSS 0.30%via OSV
CVE-2026-23833Medium
8mo ago

ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component

ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component

▾ Sunlitesphome · esphomeEPSS 0.30%via OSV
CVE-2026-23986High· 7.1
8mo ago

Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true

Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true

▾ Twilightcopier · copierEPSS 0.26%via OSV
CVE-2026-23946Medium· 6.8
8mo ago

Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization

Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization

▾ Sunlittendenci · tendenciEPSS 0.85%via OSV
CVE-2026-22807High· 8.8PoC
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…

▾ Midnightvllm · vllmEPSS 0.83%via NVD
CVE-2026-23644High
8mo ago

esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages

esm.sh has a path traversal in extractPackageTarball enables file writes from malicious packages

▾ Twilightesm-dev · github.com/esm-dev/esm.shEPSS 0.55%via OSV
CVE-2026-23842High· 7.5PoC
8mo ago

ChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion

ChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion

▾ Midnightchatterbot · chatterbotEPSS 0.55%via OSV
CVE-2026-22219High· 7.7
8mo ago

Chainlit contain a server-side request forgery (SSRF) vulnerability

Chainlit contain a server-side request forgery (SSRF) vulnerability

▾ Twilightchainlit · chainlitEPSS 5.1%via OSV
MAL-2026-326None
8mo ago

Malicious code in urlssser (PyPI)

Malicious code in urlssser (PyPI)

▾ Sunliturlssser · urlssservia OSV
MAL-2026-325None
8mo ago

Malicious code in marshel (PyPI)

Malicious code in marshel (PyPI)

▾ Sunlitmarshel · marshelvia OSV
CVE-2025-68675High· 7.5
8mo ago

Apache Airflow proxy credentials for various providers might leak in task logs

Apache Airflow proxy credentials for various providers might leak in task logs

▾ Twilightapache-airflow · apache-airflowEPSS 2.0%via OSV
CVE-2025-68438High· 7.5
8mo ago

Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

▾ Twilightapache-airflow · apache-airflowEPSS 0.66%via OSV
CVE-2026-23528Medium
8mo ago

Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard

Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard

▾ Sunlitdistributed · distributedEPSS 0.24%via OSV
CVE-2026-23535High· 8.0
8mo ago

Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command

Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command

▾ Twilightwlc · wlcEPSS 0.39%via OSV
CVE-2026-23490High· 7.5PoC
8mo ago

pyasn1 is a generic ASN.1 library for Python

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

▾ Midnightpyasn1 · pyasn1EPSS 0.77%via NVD
CVE-2026-23519High
8mo ago

RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`

RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`

▾ Twilightcmov · cmovEPSS 0.57%via OSV
CVE-2025-69725Medium· 4.7
8mo ago

chi has an open redirect vulnerability in the RedirectSlashes middleware

chi has an open redirect vulnerability in the RedirectSlashes middleware

▾ Sunlitgo-chi · github.com/go-chi/chi/v5EPSS 0.22%via OSV
CVE-2025-68492Medium· 4.2
8mo ago

Chainlit contains an authorization bypass vulnerability

Chainlit contains an authorization bypass vulnerability

▾ Sunlitchainlit · chainlitEPSS 0.23%via OSV
CVE-2026-22779Medium
8mo ago

BlackSheep's ClientSession is vulnerable to CRLF injection

BlackSheep's ClientSession is vulnerable to CRLF injection

▾ Sunlitblacksheep · blacksheepEPSS 0.36%via OSV
CVE-2026-21889Low
8mo ago

Weblate leaks information via screenshots

Weblate leaks information via screenshots

▾ Sunlitweblate · weblateEPSS 0.38%via OSV
CVE-2026-22772Medium· 5.8
8mo ago

Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass

Fulcio is vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass

▾ Sunlitsigstore · github.com/sigstore/fulcioEPSS 0.24%via OSV
CVE-2026-22871High
8mo ago

GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE

GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE

▾ Twilightguarddog · guarddogEPSS 1.1%via OSV
CVE-2026-21226High· 7.5
8mo ago

Azure Core is vulnerable to deserialization of untrusted data

Azure Core is vulnerable to deserialization of untrusted data

▾ Twilightazure-core · azure-coreEPSS 0.93%via OSV
CVE-2026-22798Medium· 5.9
8mo ago

hermes's raw options logging may disclose secrets passed in via subcommand options argument

hermes's raw options logging may disclose secrets passed in via subcommand options argument

▾ Sunlithermes · hermesEPSS 0.18%via OSV
CVE-2026-22870High
8mo ago

GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS

GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS

▾ Twilightguarddog · guarddogEPSS 0.52%via OSV
CVE-2026-22702Medium· 4.5
8mo ago

virtualenv Has TOCTOU Vulnerabilities in Directory Creation

virtualenv Has TOCTOU Vulnerabilities in Directory Creation

▾ Sunlitvirtualenv · virtualenvEPSS 0.10%via OSV
CVE-2026-23949High· 8.6
8mo ago

jaraco.context Has a Path Traversal Vulnerability

jaraco.context Has a Path Traversal Vulnerability

▾ Twilightjaraco-context · jaraco-contextEPSS 0.62%via OSV
CVE-2026-22777High· 7.5PoC
8mo ago

ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler

ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler

▾ Midnightcomfy-cli · comfy-cliEPSS 0.35%via OSV
MAL-2026-237None
8mo ago

Malicious code in formater (PyPI)

Malicious code in formater (PyPI)

▾ Sunlitformater · formatervia OSV
CVEs tagged “osv” — page 95 · VulnSea