VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

MAL-2026-236None
8mo ago

Malicious code in graponater (PyPI)

Malicious code in graponater (PyPI)

▾ Sunlitgraponater · graponatervia OSV
CVE-2025-14279High· 8.1
8mo ago

MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation

MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation

▾ Twilightmlflow · mlflowEPSS 0.21%via OSV
CVE-2026-22251Medium· 5.3
8mo ago

Weblate wlc has insecure API key configuration

Weblate wlc has insecure API key configuration

▾ Sunlitwlc · wlcEPSS 0.19%via OSV
CVE-2026-22033High
8mo ago

Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field

Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field

▾ Twilightlabel-studio · label-studioEPSS 0.28%via OSV
CVE-2026-22250Low· 2.5
8mo ago

Weblate command-line client susceptible to SSL verification skip

Weblate command-line client susceptible to SSL verification skip

▾ Sunlitwlc · wlcEPSS 0.16%via OSV
CVE-2025-15506Low· 3.3
8mo ago

AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability

AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability

▾ Sunlitopencolorio · opencolorioEPSS 0.18%via OSV
CVE-2026-22703Medium· 5.5
8mo ago

github.com/sigstore/cosign: Cosign verification accepts any valid Rekor entry under certain conditions (CVE-2026-22703)

A data verification flaw has been discovered in the golang cosign library. A Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the artifact's digest, signature or public key…

▾ SunlitRed Hat · OpenShift PipelinesEPSS 0.11%via CSAF
CVE-2026-22701Medium· 5.3
8mo ago

filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock (CVE-2026-22701)

A Time-of-Check-Time-of-Use (TOCTOU) flaw has been discovered in the pypi filelock package. The TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access…

▾ SunlitRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.13%via CSAF
CVE-2025-15504Low· 3.3
8mo ago

LIEF is vulnerable to segmentation fault

LIEF is vulnerable to segmentation fault

▾ Sunlitlief · liefEPSS 0.27%via OSV
CVE-2026-22606High
8mo ago

Fickling has a bypass via runpy.run_path() and runpy.run_module()

Fickling has a bypass via runpy.run_path() and runpy.run_module()

▾ Twilightfickling · ficklingEPSS 0.49%via OSV
CVE-2026-22609High
8mo ago

Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist

Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist

▾ Twilightfickling · ficklingEPSS 0.64%via OSV
CVE-2026-22607High
8mo ago

Fickling Blocklist Bypass: cProfile.run()

Fickling Blocklist Bypass: cProfile.run()

▾ Twilightfickling · ficklingEPSS 0.53%via OSV
CVE-2026-22612High
8mo ago

Fickling vulnerable to detection bypass due to "builtins" blindness

Fickling vulnerable to detection bypass due to "builtins" blindness

▾ Twilightfickling · ficklingEPSS 0.31%via OSV
CVE-2026-22608High
8mo ago

Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection

Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection

▾ Twilightfickling · ficklingEPSS 0.40%via OSV
CVE-2026-22690Low
8mo ago

pypdf has possible long runtimes for missing /Root object with large /Size values

pypdf has possible long runtimes for missing /Root object with large /Size values

▾ Sunlitpypdf · pypdfEPSS 0.44%via OSV
CVE-2026-22691Low
8mo ago

pypdf has possible long runtimes for malformed startxref

pypdf has possible long runtimes for malformed startxref

▾ Sunlitpypdf · pypdfEPSS 0.44%via OSV
CVE-2025-68151Medium
8mo ago

CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages

CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages

▾ Sunlitcoredns · github.com/coredns/corednsEPSS 0.48%via OSV
CVE-2023-7333Medium· 5.3
8mo ago

records-mover Injection vulnerability

records-mover Injection vulnerability

▾ Sunlitrecords-mover · records-moverEPSS 0.19%via OSV
CVE-2026-21874Medium· 5.3
8mo ago

NiceGUI has Redis connection leak via tab storage causes service degradation

NiceGUI has Redis connection leak via tab storage causes service degradation

▾ Sunlitnicegui · niceguiEPSS 0.56%via OSV
CVE-2026-21873High· 7.2
8mo ago

NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS

NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS

▾ Twilightnicegui · niceguiEPSS 0.26%via OSV
CVE-2026-21872Medium· 6.1
8mo ago

NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links

NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links

▾ Sunlitnicegui · niceguiEPSS 0.27%via OSV
CVE-2025-68158Medium· 5.7
8mo ago

Authlib has 1-click Account Takeover vulnerability

Authlib has 1-click Account Takeover vulnerability

▾ Sunlitauthlib · authlibEPSS 0.28%via OSV
CVE-2026-53872High· 7.5
8mo ago

picklescan has Arbitrary file read using `io.FileIO`

picklescan has Arbitrary file read using `io.FileIO`

▾ Twilightpicklescan · picklescanEPSS 0.69%via OSV
CVE-2026-21860Medium· 5.3
8mo ago

Werkzeug safe_join() allows Windows special device names with compound extensions

Werkzeug safe_join() allows Windows special device names with compound extensions

▾ Sunlitwerkzeug · werkzeugEPSS 0.48%via OSV
CVE-2026-21871Medium· 6.1
8mo ago

NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()

NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()

▾ Sunlitnicegui · niceguiEPSS 0.28%via OSV
CVE-2025-61782Medium· 6.1
8mo ago

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redi…

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.3, an open redirect vulnerability exists in the OpenCTI platform's SAML authentication endpoint (/auth/saml/callbac…

▾ Sunlitpycti · pyctiEPSS 0.26%via OSV
CVE-2026-22041Low
8mo ago

loggingredactor converts non-string types to string types in logs

loggingredactor converts non-string types to string types in logs

▾ Sunlitloggingredactor · loggingredactorEPSS 0.27%via OSV
CVE-2026-21441High· 7.5
8mo ago

urllib3 is an HTTP client library for Python

urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urll…

▾ Twilightpython · urllib3EPSS 3.0%via NVD
MAL-2026-96None
8mo ago

Malicious code in pycolorom (PyPI)

Malicious code in pycolorom (PyPI)

▾ Sunlitpycolorom · pycoloromvia OSV
CVE-2025-69230Medium· 5.3
8mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an a…

▾ Sunlitaiohttp · aiohttpEPSS 0.37%via NVD
CVEs tagged “osv” — page 96 · VulnSea