VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2026-21892Medium· 5.3
8mo ago

Parsl Monitoring Visualization Vulnerable to SQL Injection

Parsl Monitoring Visualization Vulnerable to SQL Injection

▾ Sunlitparsl · parslEPSS 0.27%via OSV
CVE-2026-21851Medium· 5.3
8mo ago

MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download

MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download

▾ Sunlitmonai · monaiEPSS 0.36%via OSV
CVE-2026-21883Medium
8mo ago

Bokeh server applications have Incomplete Origin Validation in WebSockets

Bokeh server applications have Incomplete Origin Validation in WebSockets

▾ Sunlitbokeh · bokehEPSS 0.18%via OSV
MAL-2026-42None
8mo ago

Malicious code in pyrogrom (PyPI)

Malicious code in pyrogrom (PyPI)

▾ Sunlitpyrogrom · pyrogromvia OSV
CVE-2026-21439Low
8mo ago

badkeys vulnerable to ASCII control character injection on console via malformed input

badkeys vulnerable to ASCII control character injection on console via malformed input

▾ Sunlitbadkeys · badkeysEPSS 0.34%via OSV
CVE-2025-69225Low
8mo ago

AIOHTTP has unicode match groups in regexes for ASCII protocol elements

AIOHTTP has unicode match groups in regexes for ASCII protocol elements

▾ Sunlitaiohttp · aiohttpEPSS 0.28%via OSV
CVE-2025-69227High· 7.5
8mo ago

aiohttp: aiohttp: Denial of Service via specially crafted POST request (CVE-2025-69227)

A flaw was found in aiohttp, an asynchronous HTTP client/server framework for Python. A remote attacker could exploit this vulnerability by sending a specially crafted POST request to an application using the Request.post() method, provide…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.39%via CSAF
CVE-2025-69229Medium
8mo ago

AIOHTTP vulnerable to DoS through chunked messages

AIOHTTP vulnerable to DoS through chunked messages

▾ Sunlitaiohttp · aiohttpEPSS 0.40%via OSV
CVE-2025-69228Medium· 6.8
8mo ago

aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request (CVE-2025-69228)

A flaw was found in aiohttp. A remote attacker can craft a malicious request that, when processed by an aiohttp server using the `Request.post()` method, causes the server's memory to fill uncontrollably. This can lead to a Denial of Servi…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.40%via CSAF
CVE-2025-69224Low
8mo ago

AIOHTTP's unicode processing of header values could cause parsing discrepancies

AIOHTTP's unicode processing of header values could cause parsing discrepancies

▾ Sunlitaiohttp · aiohttpEPSS 0.24%via OSV
CVE-2025-69226Low
8mo ago

AIOHTTP vulnerable to brute-force leak of internal static file path components

AIOHTTP vulnerable to brute-force leak of internal static file path components

▾ Sunlitaiohttp · aiohttpEPSS 0.36%via OSV
CVE-2025-69223High· 7.5
8mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that …

▾ Twilightaiohttp · aiohttpEPSS 0.57%via NVD
CVE-2026-21445HighPoC
9mo ago

Langflow Missing Authentication on Critical API Endpoints

Langflow Missing Authentication on Critical API Endpoints

▾ Midnightlangflow-base · langflow-baseEPSS 33%via OSV
CVE-2025-68131Medium
9mo ago

CBORDecoder reuse can leak shareable values across decode calls

CBORDecoder reuse can leak shareable values across decode calls

▾ Sunlitcbor2 · cbor2EPSS 0.46%via OSV
MAL-2025-193011None
9mo ago

Malicious code in requeses (PyPI)

Malicious code in requeses (PyPI)

▾ Sunlitrequeses · requesesvia OSV
MAL-2025-193010None
9mo ago

Malicious code in pyrogrqm (PyPI)

Malicious code in pyrogrqm (PyPI)

▾ Sunlitpyrogrqm · pyrogrqmvia OSV
MAL-2025-193008None
9mo ago

Malicious code in telegreph (PyPI)

Malicious code in telegreph (PyPI)

▾ Sunlittelegreph · telegrephvia OSV
MAL-2025-193007None
9mo ago

Malicious code in aiogrem (PyPI)

Malicious code in aiogrem (PyPI)

▾ Sunlitaiogrem · aiogremvia OSV
MAL-2025-192991None
9mo ago

Malicious code in pyrogrem (PyPI)

Malicious code in pyrogrem (PyPI)

▾ Sunlitpyrogrem · pyrogremvia OSV
CVE-2025-69277Medium· 4.5
9mo ago

libsodium has Incomplete List of Disallowed Inputs

libsodium has Incomplete List of Disallowed Inputs

▾ Sunlitparagonie · paragonie/sodium_compatEPSS 0.18%via OSV
CVE-2025-34469High· 7.5
9mo ago

Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl

Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl. In the default emulated shell configuration, these command emulations perform real outbound …

▾ Twilightcowrie · cowrieEPSS 0.68%via NVD
CVE-2025-71339Medium
9mo ago

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length

▾ Sunlitpicklescan · picklescanEPSS 0.52%via OSV
CVE-2025-71321High
9mo ago

Picklescan vulnerable to Arbitrary File Writing

Picklescan vulnerable to Arbitrary File Writing

▾ Twilightpicklescan · picklescanEPSS 0.62%via OSV
CVE-2025-71322High· 8.8
9mo ago

Picklescan Bypasses Unsafe Globals Check using pty.spawn

Picklescan Bypasses Unsafe Globals Check using pty.spawn

▾ Twilightpicklescan · picklescanEPSS 0.38%via OSV
CVE-2025-71320High
9mo ago

Picklescan has Incomplete List of Disallowed Inputs

Picklescan has Incomplete List of Disallowed Inputs

▾ Twilightpicklescan · picklescanEPSS 0.62%via OSV
CVE-2025-71323Critical· 9.8
9mo ago

Picklescan does not block ctypes

Picklescan does not block ctypes

▾ Midnightpicklescan · picklescanEPSS 0.76%via OSV
CVE-2025-71365High· 8.1
9mo ago

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

▾ Twilightpicklescan · picklescanEPSS 0.43%via OSV
CVE-2025-68939High· 8.2
9mo ago

Gitea allows attackers to add attachments with forbidden file extensions

Gitea allows attackers to add attachments with forbidden file extensions

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.33%via OSV
MAL-2025-192943None
9mo ago

Malicious code in telegrem (PyPI)

Malicious code in telegrem (PyPI)

▾ Sunlittelegrem · telegremvia OSV
MAL-2025-192942None
9mo ago

Malicious code in telebot-bot (PyPI)

Malicious code in telebot-bot (PyPI)

▾ Sunlittelebot-bot · telebot-botvia OSV
CVEs tagged “osv” — page 97 · VulnSea