vciy

CVEs we hold for Os

Records whose assigning authority named Os as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8905Osiris Signature Banner <= 0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'prepend_text' Parameterosiris8 Osiris Signature Banner
CVE-2026-8406openSIS Classic 9.3 - Insecure Direct Object Reference in Sent MailOS4ED openSIS-Classic
CVE-2026-8213OSGeo gdal Grid File GDapi.c GDSDfldsrch heap-based overflowOSGeo gdal
CVE-2026-8212OSGeo gdal SWapi.c SWSDfldsrch heap-based overflowOSGeo gdal
CVE-2026-8194osTicket Dispatcher class.dispatcher.php cross-site request forgeryn/a osTicket
CVE-2026-8088OSGeo gdal GDapi.c GDfieldinfo out-of-boundsOSGeo gdal
CVE-2026-8087OSGeo gdal GDapi.c GDnentries heap-based overflowOSGeo gdal
CVE-2026-8086OSGeo gdal SWapi.c SWnentries heap-based overflowOSGeo gdal
CVE-2026-8084OSGeo gdal HDF-EOS Grid File SWapi.c memmove out-of-boundsOSGeo gdal
CVE-2026-7737osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-boundsosrg GoBGP
CVE-2026-7736osrg GoBGP mrt.go parseRibEntry integer underflowosrg GoBGP
CVE-2026-7735osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflowosrg GoBGP
CVE-2026-7734osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of serviceosrg GoBGP
CVE-2026-75895Out of bounds read at smpp34_unpack()Osmocom libsmpp34
CVE-2026-75894Reachable assertion at ranap_handle_co_dt()Osmocom osmo-iuh
CVE-2026-75893Heap based buffer overflow at ipaccess_proxy_read_msg()Osmocom osmo-bsc
CVE-2026-75892Out of bounds write in PDP ctx GSN-Address decodeOsmocom osmo-ggsn
CVE-2026-7179OSPG binwalk WinCE Extraction Plugin winceextract.py read_null_terminated_string path traversalOSPG binwalk
CVE-2026-6574osuuu LightPicture API Upload Endpoint lp.sql hard-coded credentialsosuuu LightPicture
CVE-2026-57171Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of…oscal-compass compliance-trestle
CVE-2026-57170Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)oscal-compass compliance-trestle
CVE-2026-54757Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Dataoscal-compass compliance-trestle
CVE-2026-54001osquery: Heap buffer overflow via `authenticode` table (Windows)osquery
CVE-2026-54000osquery: Heap buffer overflow in `getProcessCurrentDirectory()` via `processes` table (Windows)osquery
CVE-2026-52776Trestle URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0oscal-compass compliance-trestle
CVE-2026-5124osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access controlosrg GoBGP
CVE-2026-5123osrg GoBGP bgp.go DecodeFromBytes off-by-oneosrg GoBGP
CVE-2026-5122osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access controlosrg GoBGP
CVE-2026-49838GoBGP confederation validation panics on empty AS_PATH attributeosrg gobgp
CVE-2026-49837GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundariesosrg gobgp
CVE-2026-4738GDAL Bundled zlib (inftree9.c) Pointer Offset Optimization Undefined Behavior Allows Heap Corruption or Remote Code…OSGeo gdal
CVE-2026-46439compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)oscal-compass compliance-trestle
CVE-2026-46388osquery: Unprivileged users can temporarily read file carve contentsosquery
CVE-2026-46380compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystemoscal-compass compliance-trestle
CVE-2026-46345compliance-trestle - jinja has an Arbitrary File Write via Path Traversaloscal-compass compliance-trestle
CVE-2026-45774compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversaloscal-compass compliance-trestle
CVE-2026-45725compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversaloscal-compass compliance-trestle
CVE-2026-44371Open OnDemand: Specially crafted filenames can execute javascript in the file browserOSC ondemand
CVE-2026-4303WP Visitor Statistics (Real Time Traffic) <= 8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via…osamaesh WP Visitor Statistics (Real Time Traffic)
CVE-2026-42285GoBGP: Panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)osrg gobgp
CVE-2026-41643GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATEosrg gobgp
CVE-2026-41642GoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attributeosrg gobgp
CVE-2026-36214no title heldosTicket
CVE-2026-26002OnDemand susceptible to malicious input when navigating to a directory.OSC ondemand
CVE-2026-18592osCommerce Email Template Configuration EmailController.php EmailController sql injectionn/a osCommerce
CVE-2026-18265OSNEXUS QuantaStor Missing Authentication Remote Code Execution VulnerabilityOSNEXUS QuantaStor
CVE-2026-14871osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosureosTicket
CVE-2026-11944openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment downloadOS4ED openSIS-Classic
CVE-2026-10880Unauthenticated SQL Injection in Osnexus QuantastorOsnexus QuantaStor
CVE-2025-7464osrg GoBGP rtr.go SplitRTR out-of-boundsosrg GoBGP
CVE-2025-67983WordPress WP Visitor Statistics (Real Time Traffic) plugin <= 8.3 - Cross Site Scripting (XSS) vulnerabilityosama.esh WP Visitor Statistics (Real Time Traffic)
CVE-2025-66029Open OnDemand affected by Apache proxy passing sensitive headersOSC ondemand
CVE-2025-64185Open OnDemand RPM packages create world writable locationsOSC ondemand
CVE-2025-62724Open OnDemand allowlist bypass using symlinks in directory downloads (TOCTOU)OSC ondemand
CVE-2025-61926Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secretossf allstar
CVE-2025-5940Osom Blocks <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via class_name Parameterosompress Osom Blocks
CVE-2025-58435Open OnDemand didn't rotate password for VNC batch_connectOSC ondemand
CVE-2025-53636Open OnDemand Shell App closed websocket DoSOSC ondemand
CVE-2025-53566WordPress WP Visitor Statistics (Real Time Traffic) plugin <= 7.8 - Cross Site Scripting (XSS) Vulnerabilityosama.esh WP Visitor Statistics (Real Time Traffic)
CVE-2025-53235WordPress Easy Social plugin <= 1.3 - Cross Site Scripting (XSS) vulnerabilityosuthorpe Easy Social
CVE-2025-49996WordPress WP Visitor Statistics (Real Time Traffic) plugin <= 8.4 - Broken Access Control vulnerabilityosama.esh WP Visitor Statistics (Real Time Traffic)
CVE-2025-49400WordPress WP Visitor Statistics (Real Time Traffic) Plugin <= 8.2 - Cross Site Scripting (XSS) Vulnerabilityosama.esh WP Visitor Statistics (Real Time Traffic)
CVE-2025-46822Unauthenticated Arbitrary File Read via Absolute PathOsamaTaher Java-springboot-codebase
CVE-2025-40674Reflected Cross-Site Scripting (XSS) in osCommerceosCommerce
CVE-2025-24675WordPress WP Visitor Statistics (Real Time Traffic) plugin <= 7.2 - Cross Site Scripting (XSS) vulnerabilityosama.esh WP Visitor Statistics (Real Time Traffic)
CVE-2025-23825WordPress Easy Shortcode Buttons plugin <= 1.2 - Cross Site Scripting (XSS) vulnerabilityosuthorpe Easy Shortcode Buttons
CVE-2025-23503WordPress Customizable Captcha and Contact us plugin <= 1.0.2 - Reflected Cross Site Scripting (XSS) vulnerabilityosolwordpress Customizable Captcha and Contact Us
CVE-2025-22656WordPress Cookie Monster Plugin <= 1.2.2 - Local File Inclusion vulnerabilityOscar Alvarez Cookie Monster
CVE-2025-22304WordPress WP Visitor Statistics plugin <= 7.5 - Broken Access Control vulnerabilityosama.esh WP Visitor Statistics (Real Time Traffic)
CVE-2025-1835osuuu LightPicture Api.php upload unrestricted uploadosuuu LightPicture
CVE-2025-13676JustClick registration plugin <= 0.1 - Reflected Cross-Site Scripting via PHP_SELFostin654 JustClick registration plugin
CVE-2025-12666Google Drive upload and download link <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scriptingoscaruh Google Drive upload and download link
CVE-2025-12652Ungapped Widgets <= 1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeoscaruribe Ungapped Widgets
CVE-2024-7460OSWAPP Warehouse Inventory System change_password.php cross-site request forgeryOSWAPP Warehouse Inventory System
CVE-2024-7459OSWAPP Warehouse Inventory System edit_account.php cross-site request forgeryOSWAPP Warehouse Inventory System
CVE-2024-6876Out-of-bounds read in OSCAT-Libraryoscat.de OSCAT Basic Library; CODESYS OSCAT Basic Library
CVE-2024-54681Ossur Mobile Logic Application Command InjectionOssur Mobile Logic Application
CVE-2024-53683Ossur Mobile Logic Application Exposure of Sensitive System Information to an Unauthorized Control SphereOssur Mobile Logic Application
CVE-2024-52302common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)OsamaTaher Java-springboot-codebase
CVE-2024-45832Ossur Mobile Logic Application Use of Hard-coded CredentialsOssur Mobile Logic Application
CVE-2024-4348osCommerce all-products cross site scriptingn/a osCommerce
CVE-2024-37163SkyScrape Secure API Requestsoslabs-beta SkyScraper
CVE-2024-29882SRS DOM - XSS on JSONP callbackossrs srs
CVE-2024-24867WordPress WP Stats Manager plugin <= 6.9.4 - Sensitive Data Exposure vulnerabilityOsamaesh WP Visitor Statistics (Real Time Traffic)
CVE-2024-1921osuuu LightPicture Setup.php unrestricted uploadosuuu LightPicture
CVE-2024-1920osuuu LightPicture TokenVerify.php handle hard-coded keyosuuu LightPicture
CVE-2024-13141osuuu LightPicture SVG File Upload upload cross site scriptingosuuu LightPicture
CVE-2024-1244Remote code execution and local privilege escalation due to UNC access and NetNTLMv2 hash theftOSSEC-HIDS Agent
CVE-2023-6609osCommerce all-products cross site scriptingn/a osCommerce
CVE-2023-6579osCommerce POST Parameter shopping-cart sql injectionn/a osCommerce
CVE-2023-6296osCommerce Instant Message compare cross site scriptingn/a osCommerce
CVE-2023-53947OCS Inventory NG 2.3.0.0 Unquoted Service Path Privilege Escalationoscinventory OCS Inventory NG
CVE-2023-5112Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-5111Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-46069WordPress Ajax Archive Calendar Plugin <= 2.6.7 is vulnerable to Cross Site Scripting (XSS)Osmansorkar Ajax Archive Calendar
CVE-2023-43735Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43734Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43733Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43732Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43731Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43730Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43729Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43728Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43727Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43726Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43725Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43724Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43723Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43722Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43721Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43720Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43719Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43718Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43717Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43716Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43715Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43714Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43713Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43712Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43711Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43710Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43709Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43708Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43707Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43706Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43705Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43704Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43703Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-43702Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)Os Commerce
CVE-2023-35065SQLi in Osofts Paint Production ManagementOsoft Paint Production Management
CVE-2023-34105SRS has command injection vulnerability in demonstration api-server for HTTP callback.ossrs srs
CVE-2023-1320Cross-site Scripting (XSS) - Stored in osticket/osticketosticket/osticket
CVE-2023-1319Cross-site Scripting (XSS) - Stored in osticket/osticketosticket/osticket
CVE-2023-1318Cross-site Scripting (XSS) - Generic in osticket/osticketosticket/osticket
CVE-2023-1317Cross-site Scripting (XSS) - Reflected in osticket/osticketosticket/osticket
CVE-2023-1316Cross-site Scripting (XSS) - Stored in osticket/osticketosticket/osticket
CVE-2023-1315Cross-site Scripting (XSS) - Reflected in osticket/osticketosticket/osticket
CVE-2022-4676OSM – OpenStreetMap <= 6.01 - Contributor+ Stored XSS via ShortcodeUnknown OSM
CVE-2022-4271Cross-site Scripting (XSS) - Reflected in osticket/osticketosticket/osticket
CVE-2022-33965WordPress WP Visitor Statistics plugin <= 5.7 - Multiple Unauthenticated SQL Injection (SQLi) vulnerabilitiesOsamaesh WP Visitor Statistics (WordPress plugin)
CVE-2021-47864OSAS Traverse Extension 11 - 'travextensionhostsvc' Unquoted Service PathOSAS Traverse Extension
CVE-2021-4406Authenticated Remote COmmand Execution as root in OSNEXUS QuantaStor version 6.0.0.355 and othersOSNEXUS QuantaStor
CVE-2021-43553OSIsoft PI VisionOSIsoft PI Vision
CVE-2021-43551OSIsoft PI VisionOSIsoft PI Vision
CVE-2021-43549OSIsoft PI Web APIOSIsoft PI Web API
CVE-2021-42083Authenticated Stored XSS in OSNEXUS QuantaStor 6.0.0.335OSNEXUS QuantaStor
CVE-2021-42082Local Privilege Escalation to root in OSNEXUS QuantaStor before 6.0.0.355OSNEXUS QuantaStor
CVE-2021-42081Authenticated Remote Command Execution vulnerability in OSNEXUS QuantaStor before 6.0.0.355OSNEXUS QuantaStor
CVE-2021-42080Reflected XSS vulnerability in OSNEXUS QuantaStor before 6.0.0.355OSNEXUS QuantaStor
CVE-2021-42079SSRF vulnerability in OSNEXUS QuantaStor before 6.0.0.355OSNEXUS QuantaStor
CVE-2021-38351OSD Subscribe <= 1.2.3 Reflected Cross-Site ScriptingOSD Subscribe
CVE-2021-24978OSMapper <= 2.1.5 - Unauthenticated Arbitrary Post DeletionUnknown OSMapper
CVE-2020-7749Server-side Request Forgery (SSRF)n/a osm-static-maps
CVE-2020-6865no title heldn/a OSCP
CVE-2020-6144no title heldn/a OS4Ed
CVE-2020-6143no title heldn/a OS4Ed
CVE-2020-6142no title heldn/a OS4Ed
CVE-2020-6141no title heldn/a OS4Ed
CVE-2020-6140no title heldn/a OS4Ed
CVE-2020-6139no title heldn/a OS4Ed
CVE-2020-6138no title heldn/a OS4Ed
CVE-2020-6137no title heldn/a OS4Ed
CVE-2020-6136no title heldn/a OS4Ed
CVE-2020-6135no title heldn/a OS4Ed
CVE-2020-6134no title heldn/a OS4Ed
CVE-2020-6133no title heldn/a OS4Ed
CVE-2020-6132no title heldn/a OS4Ed
CVE-2020-6131no title heldn/a OS4ED
CVE-2020-6130no title heldn/a OS4ED
CVE-2020-6129no title heldn/a OS4ED
CVE-2020-6128no title heldn/a OS4Ed
CVE-2020-6127no title heldn/a OS4Ed
CVE-2020-6126no title heldn/a OS4Ed
CVE-2020-6125no title heldn/a OS4Ed
CVE-2020-6124no title heldn/a OS4Ed
CVE-2020-6123no title heldn/a OS4Ed
CVE-2020-6122no title heldn/a OS4Ed
CVE-2020-6121no title heldn/a OS4Ed
CVE-2020-6120no title heldn/a OS4Ed
CVE-2020-6119no title heldn/a OS4Ed
CVE-2020-6118no title heldn/a OS4ED"
CVE-2020-6117no title heldn/a OS4ED"
CVE-2020-26273sqlite ATTACH allows some filesystem accessosquery
CVE-2020-25167OSIsoft PI Vision Incorrect AuthorizationOSIsoft PI Vision
CVE-2020-25163OSIsoft PI Vision Cross-site ScriptingOSIsoft PI Vision
CVE-2020-1802no title heldn/a OSCA-550;OSCA-550A;OSCA-550AX;OSCA-550X
CVE-2020-12021no title heldn/a OSIsoft PI Web API 2019
CVE-2020-11081osquery susceptible to DLL search order hijacking of zlib1.dllosquery
CVE-2020-10643OSIsoft PI SystemOSIsoft PI Vision
CVE-2020-10614no title heldn/a OSIsoft PI System multiple products and versions
CVE-2020-10610no title heldn/a OSIsoft PI System multiple products and versions
CVE-2020-10608no title heldn/a OSIsoft PI System multiple products and versions
CVE-2020-10606no title heldn/a OSIsoft PI System multiple products and versions
CVE-2020-10604no title heldn/a OSIsoft PI System multiple products and versions
CVE-2020-10602no title heldn/a OSIsoft PI System multiple products and versions
CVE-2020-10600OSIsoft PI SystemOSIsoft PI Data Archive
CVE-2019-25497osCommerce 2.3.4.1 SQL Injection via currency ParameterosCommerce
CVE-2019-25496osCommerce 2.3.4.1 SQL Injection via products_id ParameterosCommerce
CVE-2019-25495osCommerce 2.3.4.1 SQL Injection via reviews_id ParameterosCommerce
CVE-2019-18275no title heldn/a OSIsoft PI Vision

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.