Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2026-21892Medium· 5.3Parsl Monitoring Visualization Vulnerable to SQL Injection
Parsl Monitoring Visualization Vulnerable to SQL Injection
CVE-2026-21851Medium· 5.3MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download
MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download
CVE-2026-21883MediumBokeh server applications have Incomplete Origin Validation in WebSockets
Bokeh server applications have Incomplete Origin Validation in WebSockets
MAL-2026-42NoneMalicious code in pyrogrom (PyPI)
Malicious code in pyrogrom (PyPI)
CVE-2026-21439Lowbadkeys vulnerable to ASCII control character injection on console via malformed input
badkeys vulnerable to ASCII control character injection on console via malformed input
CVE-2025-69225LowAIOHTTP has unicode match groups in regexes for ASCII protocol elements
AIOHTTP has unicode match groups in regexes for ASCII protocol elements
CVE-2025-69227High· 7.5aiohttp: aiohttp: Denial of Service via specially crafted POST request (CVE-2025-69227)
A flaw was found in aiohttp, an asynchronous HTTP client/server framework for Python. A remote attacker could exploit this vulnerability by sending a specially crafted POST request to an application using the Request.post() method, provide…
CVE-2025-69229MediumAIOHTTP vulnerable to DoS through chunked messages
AIOHTTP vulnerable to DoS through chunked messages
CVE-2025-69228Medium· 6.8aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request (CVE-2025-69228)
A flaw was found in aiohttp. A remote attacker can craft a malicious request that, when processed by an aiohttp server using the `Request.post()` method, causes the server's memory to fill uncontrollably. This can lead to a Denial of Servi…
CVE-2025-69224LowAIOHTTP's unicode processing of header values could cause parsing discrepancies
AIOHTTP's unicode processing of header values could cause parsing discrepancies
CVE-2025-69226LowAIOHTTP vulnerable to brute-force leak of internal static file path components
AIOHTTP vulnerable to brute-force leak of internal static file path components
CVE-2025-69223High· 7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that …
CVE-2026-21445HighPoCLangflow Missing Authentication on Critical API Endpoints
Langflow Missing Authentication on Critical API Endpoints
CVE-2025-68131MediumCBORDecoder reuse can leak shareable values across decode calls
CBORDecoder reuse can leak shareable values across decode calls
MAL-2025-193011NoneMalicious code in requeses (PyPI)
Malicious code in requeses (PyPI)
MAL-2025-193010NoneMalicious code in pyrogrqm (PyPI)
Malicious code in pyrogrqm (PyPI)
MAL-2025-193008NoneMalicious code in telegreph (PyPI)
Malicious code in telegreph (PyPI)
MAL-2025-193007NoneMalicious code in aiogrem (PyPI)
Malicious code in aiogrem (PyPI)
MAL-2025-192991NoneMalicious code in pyrogrem (PyPI)
Malicious code in pyrogrem (PyPI)
CVE-2025-69277Medium· 4.5libsodium has Incomplete List of Disallowed Inputs
libsodium has Incomplete List of Disallowed Inputs
CVE-2025-34469High· 7.5Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl
Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl. In the default emulated shell configuration, these command emulations perform real outbound …
CVE-2025-71339MediumPicklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
CVE-2025-71321HighPicklescan vulnerable to Arbitrary File Writing
Picklescan vulnerable to Arbitrary File Writing
CVE-2025-71322High· 8.8Picklescan Bypasses Unsafe Globals Check using pty.spawn
Picklescan Bypasses Unsafe Globals Check using pty.spawn
CVE-2025-71320HighPicklescan has Incomplete List of Disallowed Inputs
Picklescan has Incomplete List of Disallowed Inputs
CVE-2025-71323Critical· 9.8Picklescan does not block ctypes
Picklescan does not block ctypes
CVE-2025-71365High· 8.1Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
CVE-2025-68939High· 8.2Gitea allows attackers to add attachments with forbidden file extensions
Gitea allows attackers to add attachments with forbidden file extensions
MAL-2025-192943NoneMalicious code in telegrem (PyPI)
Malicious code in telegrem (PyPI)
MAL-2025-192942NoneMalicious code in telebot-bot (PyPI)
Malicious code in telebot-bot (PyPI)