2026-07-05
2026-07-05 08:16Z
HIGH

CVE-2026-14721 — The manipulation of the argument ssid leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14721

A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects an unknown function of the file /goform/ConfigWirelessBase_5g of the component Web Endpoint. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-04
2026-07-04 18:16Z
HIGH

CVE-2026-14637 — The manipulation of the argument shopping_cart leads to deserialization.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14637

A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. The manipulation of the argument shopping_cart leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is used by this product. Th CVSSv3.1 8.2 (HIGH)

CWECWE 502CWECWE 20TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 18:16Z
HIGH

CVE-2026-12746 — Dancer2: Any application that uses this plugin for OAuth 2.0 login is exposed to login

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12746

Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting token into the session without verifying that the callback corresponds to an authorization request this session initiated. Any application that uses this plugin for OAuth 2.0 logi CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDDancer2TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 18:16Z
HIGH

CVE-2026-12740 — Plack: Any application that uses this middleware for OAuth 2.0 login is exposed to login

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12740

Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without verifying that the callback corresponds to an authorization request this session initiated. Any application that uses this middleware for OAuth 2.0 login is expose CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDPlackTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 14:16Z
HIGH

CVE-2026-14535 — Trail: With MLAllowlist inoperative, any standard library module not in the UNSAFE_IMPORTS denylist can be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14535

In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. This call registers the shortened code representation in the shared AnalysisContext.reported_shortened_code set. When the MLAllowlist analysis pass subsequently runs, it calls the same shorten_code() method, receives already_reported=Tru CVSSv3.1 8.8 (HIGH)

CWECWE 693VNDTrailTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-04
2026-07-04 14:16Z
HIGH

CVE-2026-14534 — Trail: of Bits fickling versions up to and including 0.1.10 do not include the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14534

Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). Because these modules are absent from the denylist, fickling's check_safety() function returns LIKELY_SAFE with zero findings for pickle payloads that invoke dangerous functions including _posixsubprocess.fork_exec (C-level process spawner capable of executing arbitrary binaries), site.exec CVSSv3.1 8.8 (HIGH)

CWECWE 502CWECWE 184VNDTrailTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-04
2026-07-04 12:17Z
HIGH

CVE-2026-53362 — Linux Linux_kernel: In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53362in the wild

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen i CVSSv3.1 7.8 (HIGH) · EPSS 18th percentile

CWECWE 787CWECWE 122TYPVulnerabilitySTAitw exploited
7.8
CVSS v3.1
89
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-04
2026-07-04 12:17Z
HIGH

CVE-2026-53360 — Linux: Failure to force usage of the GHCB, and a slew of other flaws, lets

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53360

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared buffer. Note, things like Page State Change (PSC) requests _rely_ on this behavior, as the guest can't provide a length when making the request, i.e. the size of the guest payload is bounded by the size of the shared buffer. Failure to forc CVSSv3.1 8.8 (HIGH) · EPSS 18th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-04
2026-07-04 12:17Z
HIGH

CVE-2026-53359 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53359

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. The rmap_remove() call would miss entries created after the PDE change because the CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71380 — Execute: The Execute Command node in n8n allows authenticated users to execute arbitrary commands on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71380

The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service disruption, or complete system compromise. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDExecuteTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71375 — Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71375

picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load(). CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71373 — picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71373

picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads using operator.methodcaller that execute arbitrary code when loaded, compromising systems relying on picklescan for validation. CVSSv3.1 8.1 (HIGH)

CWECWE 693TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71372 — Picklescan: before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71372

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded, bypassing Picklescan's safety checks and enabling supply-chain poisoning of shared model files. CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDPicklescanTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71369 — picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71369

picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. Remote attackers can embed undetected malicious code in pickle files that executes during deserialization, enabling remote code execution. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71367 — picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71367

picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using _operator.attrgetter in reduce methods to execute arbitrary code when pickle.load() processes the file. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71366 — picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71366

picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. Remote attackers can embed undetected code in pickle files to achieve arbitrary code execution when victims load the files. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71364 — picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71364

picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. Attackers can craft malicious pickle files embedding this built-in function that evade detection but execute arbitrary commands when loaded. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71362 — picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71362

picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. Attackers can embed malicious code in pickle files that executes when loaded from untrusted sources. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71360 — picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71360

picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71359 — picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71359

picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing remote code execution. Attackers can craft pickle files embedding dangerous code that evades picklescan detection and executes during pickle.load() deserialization. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71356 — Attackers can embed undetected code in pickle files that executes remote code when loaded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71356

picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle files. Attackers can embed undetected code in pickle files that executes remote code when loaded by victims. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71353 — picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71353

picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attackers can craft pickle files with embedded code that evades picklescan detection and executes arbitrary commands when loaded. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71347 — picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71347

picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed undetected code in pickle files that executes during deserialization, enabling arbitrary code execution in applications loading untrusted pickle data. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71345 — Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71345

picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code execution. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71343 — picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71343

picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded code that evades detection but executes arbitrary commands when pickle.load() is called. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score