Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'osv'

View all threats tagged with 'osv'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: osv

Threats Tagged 'osv'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. (CVE-2026-19360)CVE-2026-19360
0

CVE-2026-19360 is a medium severity vulnerability in wongcyrus ExcelLexBot up to version 0.0.3 affecting the Lambda Function Handler component ExcelLexBotS3TriggerFunction. It involves improper privilege management that can be exploited remotely. The product is no longer supported by the maintainer, and no vendor response or patch is available.

Join the discussion
A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. (CVE-2026-19359)CVE-2026-19359
0

CVE-2026-19359 is a medium severity security vulnerability in the nxp-auto-goldvip gvip software up to version 1.4.0. The issue affects the SitewiseCustomFunction within the Lambda Function Handler component, leading to improper access controls. This vulnerability can be exploited remotely. The problem stems from a known historical IAM permission misconfiguration that was addressed starting with version 1.13.0, with further permission updates in version 1.15.0. Users are advised to upgrade to version 1.15.0 or later to remediate the issue.

Join the discussion
A vulnerability has been found in lmammino oidc-authorizer 0.4.0. (CVE-2026-19362)CVE-2026-19362
0

A denial of service vulnerability exists in lmammino oidc-authorizer version 0.4.0 affecting the Authorization Header Parsing component. The flaw is in the parse_token_from_header function, where manipulation of the authorization_token argument can cause a denial of service. Remote exploitation is possible, and the vulnerability has been publicly disclosed. The vendor has not responded to the disclosure, and no patch or fix is currently available.

Join the discussion
A vulnerability was determined in itsourcecode Hospital Management System 1.0. (CVE-2026-19364)CVE-2026-19364
0

A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 in the /viewdoctorconsultancycharge.php file via manipulation of the delid argument. The vulnerability can be exploited remotely and the exploit has been publicly disclosed. The CVSS 3.1 base score is 6.3, indicating a medium severity level with low complexity and no user interaction required.

Join the discussion
A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. (CVE-2026-19363)CVE-2026-19363
0

A vulnerability exists in lmammino oidc-authorizer up to version 0.4.0 in the unwrap function of src/handler.rs. The issue involves manipulation of the jwtClaims argument leading to unsafe deserialization. This vulnerability can be exploited remotely. The vendor has not responded to disclosure attempts. The CVSS score is 5.3, indicating a medium severity risk.

Join the discussion
Malicious code in kotanku (PyPI)
0

The kotanku package on PyPI version 0.1.0 contains malicious code that exfiltrates cryptocurrency wallet files during import. This behavior is part of a campaign identified as 2026-08-kotanku, which uses a Telegram bot for exfiltration. No official patch or remediation guidance is provided. There is no evidence of active exploitation in the wild at this time.

Join the discussion
A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. (CVE-2026-19368)CVE-2026-19368
0

CVE-2026-19368 is a path traversal vulnerability in PV-Bhat gemsuite-mcp version 1.0.0. It affects an unknown functionality in the file src/handlers/unified-gemini.ts related to components gemini_search, gemini_reason, gemini_process, and gemini_analyze. The vulnerability allows local attackers with low privileges to manipulate file path arguments to perform path traversal. No patch or vendor response has been reported yet.

Join the discussion
A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. (CVE-2026-19367)CVE-2026-19367
0

NocteDefensor LudusMCP version 1.0.24 contains a server-side request forgery (SSRF) vulnerability in the read_range_config component, specifically in the src/tools/rangeConfig.ts file. The vulnerability arises from manipulation of the 'Source' argument, which can be exploited remotely. The project has been informed but has not yet responded or issued a fix. The CVSS score is 6.3, indicating a medium severity impact.

Join the discussion
A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. (CVE-2026-19369)CVE-2026-19369
0

CVE-2026-19369 is a server-side request forgery (SSRF) vulnerability in KS-GEN-AI jira-mcp-server version 0.2.0. It affects the axios.get function in the add_attachment_from_public_url component, specifically in the src/index.ts file. The vulnerability arises from manipulation of the imageUrl argument, allowing an attacker with local access to induce the server to make unintended requests. The issue was reported early to the project, but no response or fix has been provided yet.

Join the discussion
A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. (CVE-2026-19365)CVE-2026-19365
0

A path traversal vulnerability exists in Ichigo3766 image-gen-mcp version 0.1.0 in an unknown function within src/index.ts related to the upscale_images component. The vulnerability allows local attackers with low privileges to manipulate the output_path argument to perform path traversal. The issue was reported early to the project but has not yet received a response or fix.

Join the discussion

Showing 1 to 10 of 15184 results

Filters:Tag: osv
Page 1 of 1519
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses