Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'osv'

View all threats tagged with 'osv'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: osv

Threats Tagged 'osv'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability was found in itsourcecode Hospital Management System 1.0. (CVE-2026-75087)CVE-2026-75087
0

A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 in the /viewdepartment.php file via manipulation of the delid argument. This vulnerability can be exploited remotely and has a CVSS score of 6.3, indicating a moderate severity. No patch or remediation information is currently available. Exploit code has been made public, but there are no known exploits in the wild at this time.

Join the discussion
A vulnerability was determined in itsourcecode Hospital Management System 1.0. (CVE-2026-75088)CVE-2026-75088
0

A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 in the /viewbilling.php file via manipulation of the delid argument. This vulnerability can be exploited remotely and has been publicly disclosed. The CVSS score is 6.3, indicating a medium severity level. No patch or remediation information is currently available.

Join the discussion
A vulnerability has been found in itsourcecode Hospital Management System 1.0. (CVE-2026-75086)CVE-2026-75086
0

A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 within the /viewroom.php file via manipulation of the delid argument. This vulnerability can be exploited remotely and has publicly disclosed exploit code. The CVSS 3.1 base score is 6.3, indicating a medium severity level with low privileges required and no user interaction needed.

Join the discussion
A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. (CVE-2026-75090)CVE-2026-75090
0

A vulnerability in EricLBuehler Mistral.rs up to version 0.8.22 allows remote attackers to cause an out-of-bounds read via manipulation of tokenizer arguments. The issue affects the convert_gguf_to_hf_tokenizer function in the GGUF Tokenizer component. This vulnerability has a low severity score and can be resolved by upgrading to version 0.8.23.

Join the discussion
A security vulnerability has been detected in sonos tract up to 0.23.4. (CVE-2026-75093)CVE-2026-75093
0

A security vulnerability (CVE-2026-75093) exists in sonos tract up to version 0.23.4 in the ONNX Initializer Loader component. It affects the function Tensor::from_raw_dt_align in the file data/src/tensor.rs, causing incorrect calculation of buffer size. The vulnerability can be exploited remotely and has been publicly disclosed. The CVSS score is 4.3, indicating a low severity impact primarily affecting availability. A patch identified by commit 66b10bda8895f4bfaf8c205361f0125cdf51f99b is recommended to resolve the issue.

Join the discussion
A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. (CVE-2026-75151)CVE-2026-75151
0

SourceCodester Online Examination & Learning Management System 1.0 contains a cross-site request forgery (CSRF) vulnerability. This vulnerability allows remote attackers to trick authenticated users into performing unwanted actions. The affected functionality is unspecified. The vulnerability has a CVSS 3.1 score of 4.3, indicating a medium severity level.

Join the discussion
Malicious code in sui-move-graphql (npm)
0

The npm package 'sui-move-graphql' contains malicious code that compromises any computer on which it is installed or running. Installation of this package may lead to full system compromise, including unauthorized access to secrets and keys stored on the affected machine. Removal of the package alone does not guarantee elimination of all malicious software introduced. Immediate rotation of all secrets and keys from a separate, secure computer is strongly advised.

Join the discussion
Malicious code in ulebkit (npm)
0

The ulebkit package in the npm ecosystem contains malicious code that compromises any computer on which it is installed or running. The compromise is severe enough that all secrets and keys stored on the affected system should be rotated immediately from a different, trusted machine. Removing the package alone does not guarantee removal of all malicious software introduced by it.

Join the discussion
Malicious code in blastradar (npm)
0

The npm package 'blastradar' contains malicious code that compromises any computer on which it is installed or running. Installation of this package can lead to full system compromise, including unauthorized access to secrets and keys stored on the affected machine. Removal of the package alone does not guarantee elimination of all malicious software introduced. Immediate rotation of all secrets and keys from a separate, uncompromised system is strongly advised.

Join the discussion
Malicious code in core-tailwindcss-utility (npm)
0

The npm package core-tailwindcss-utility, version 3.7.1, is a malicious package masquerading as a Tailwind CSS utility. Instead of providing CSS utilities, it executes remote code fetched from a hardcoded IP address by dynamically evaluating JavaScript code in the Node.js environment. The package includes suspicious dependencies unrelated to its stated purpose, which facilitate credential decryption and remote command-and-control communication. This behavior enables execution of arbitrary code on the host system, posing a significant security risk.

Join the discussion

Showing 1 to 10 of 11316 results

Filters:Tag: osv
Page 1 of 1132
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses