Tagged “osv”
CVEs tagged osv, newest first.
5710 CVEsRSS
CVE-2025-67720Medium· 6.5Pyrofork has a Path Traversal in download_media Method
Pyrofork has a Path Traversal in download_media Method
CVE-2025-67485Medium· 5.3HTTP/HTTPS Traffic Interception Bypass in mad-proxy
HTTP/HTTPS Traffic Interception Bypass in mad-proxy
CVE-2025-66645High· 7.5NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read
NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read
CVE-2025-67502Medium· 5.4Open Redirect Vulnerability in Taguette
Open Redirect Vulnerability in Taguette
CVE-2025-66491Medium· 5.9Traefik Inverted TLS Verification Logic in ingress-nginx Provider
Traefik Inverted TLS Verification Logic in ingress-nginx Provider
CVE-2025-66469Medium· 6.1NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection
NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection
CVE-2025-66470Medium· 6.1PoCNiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
CVE-2025-66564High· 7.5Sigstore Timestamp Authority allocates excessive memory during request parsing
Sigstore Timestamp Authority allocates excessive memory during request parsing
MAL-2025-192323NoneMalicious code in rendom (PyPI)
Malicious code in rendom (PyPI)
CVE-2025-66418High· 7.5urllib3 is a user-friendly HTTP client library for Python
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of co…
CVE-2025-66471High· 7.5urllib3 is a user-friendly HTTP client library for Python
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large H…
CVE-2025-65637HighPoCLogrus is vulnerable to DoS when using Entry.Writer()
Logrus is vulnerable to DoS when using Entry.Writer()
CVE-2025-63681Lowopen-webui is Vulnerable to Incorrect Access Control
open-webui is Vulnerable to Incorrect Access Control
CVE-2025-65958High· 8.5Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
CVE-2025-14010Medium· 5.5Ansible Community General Collection is vulnerable to exposure of sensitive information
Ansible Community General Collection is vulnerable to exposure of sensitive information
CVE-2025-56427High· 7.5ComposioHQ has a directory traversal vulnerability
ComposioHQ has a directory traversal vulnerability
CVE-2025-10543MediumEclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes
Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes
CVE-2025-64460MediumDjango is vulnerable to DoS via XML serializer text extraction
Django is vulnerable to DoS via XML serializer text extraction
CVE-2025-13372Medium· 4.3Django is vulnerable to SQL injection in column aliases
Django is vulnerable to SQL injection in column aliases
CVE-2025-61729NoneExcessive resource consumption when printing error string for host certificate validation in crypto/x509
Excessive resource consumption when printing error string for host certificate validation in crypto/x509
CVE-2025-65896Critical· 9.8asyncmy is vulnerable to SQL injection via crafted dict keys
asyncmy is vulnerable to SQL injection via crafted dict keys
CVE-2025-65858LowPoCCalibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
CVE-2025-12060Critical· 9.8Keras Directory Traversal Vulnerability
Keras Directory Traversal Vulnerability
CVE-2025-66221MediumWerkzeug safe_join() allows Windows special device names
Werkzeug safe_join() allows Windows special device names
CVE-2025-66454Medium· 6.5arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints
arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints
CVE-2025-66416HighModel Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
CVE-2025-64715Medium· 4.0Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
CVE-2025-66040Low· 3.6Spotipy has a XSS vulnerability in its OAuth callback server
Spotipy has a XSS vulnerability in its OAuth callback server
CVE-2025-66448High· 7.5vllm: vLLM: Remote Code Execution via malicious model configuration (CVE-2025-66448)
A remote code execution vulnerability has been identified in vLLM. An attacker can exploit a weakness in the model loading process to silently fetch and run unauthorized, malicious Python code on the host system. This happens because the e…
CVE-2025-66034Medium· 6.3PoCfontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib