2026-07-04
2026-07-04 02:16Z
HIGH

CVE-2025-71342 — Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71342

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch models and supply chain attacks. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-04
2026-07-04 01:16Z
HIGH

CVE-2026-54424 — Incorrect: An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54424

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of parsecd.exe running as NT AUTHORITY\SYSTEM with a user-controlled value of the AppData environment variable. CVSSv3.1 8.4 (HIGH)

CWECWE 648TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-03
2026-07-03 21:17Z
CRIT

CVE-2026-58426 — Gitea: Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58426

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write CVSSv3.1 9.6 (CRITICAL)

CWECWE 347VNDGiteaTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-58424 — Permanent: Fork PR Workflow Approval Gate Bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58424

Permanent Fork PR Workflow Approval Gate Bypass CVSSv3.1 8.9 (HIGH)

CWECWE 285CWECWE 863CWECWE 732VNDPermanentTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-07-03
2026-07-03 21:17Z
CRIT

CVE-2026-58422 — OAuth: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58422

Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

CWECWE 284VNDOauthTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-58295 — Access: of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58295

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.3 (HIGH)

CWECWE 843VNDAccessTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-58293 — External: control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58293

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 73TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-03
2026-07-03 21:17Z
CRIT

CVE-2026-58289 — Access: of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58289

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.0 (CRITICAL)

CWECWE 843VNDAccessTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-58288 — Use: after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58288

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-58287 — Use: after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58287

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-58286 — Microsoft: Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58286

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-58285 — Access: of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58285

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.3 (HIGH)

CWECWE 843VNDAccessTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-58284 — Microsoft: Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58284

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.3 (HIGH)

CWECWE 285VNDMicrosoftTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-58283 — Access: of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58283

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 843VNDAccessTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-58282 — Microsoft: Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58282

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-57983 — Microsoft: Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57983

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.7 (HIGH)

CWECWE 285VNDMicrosoftTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-57981 — Use: after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57981

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-57974 — Integer: overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57974

Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-56645 — Heap: Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56645

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 21:17Z
HIGH

CVE-2026-28744 — Gitea: versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28744

Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDGiteaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-03
2026-07-03 21:16Z
HIGH

CVE-2026-28737 — Gitea: versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28737

Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDGiteaTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 21:16Z
HIGH

CVE-2026-28699 — Gitea: versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28699

Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication. CVSSv3.1 8.1 (HIGH)

CWECWE 284CWECWE 863VNDGiteaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-03
2026-07-03 21:16Z
CRIT

CVE-2026-27780 — Gitea: versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27780

Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks. CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 863VNDGiteaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 21:16Z
HIGH

CVE-2026-27775 — Gitea: 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27775

Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access. CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile

CWECWE 863VNDGiteaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 21:16Z
HIGH

CVE-2026-27771 — Gitea: versions up to and including 1.26.1 have insufficient permission checks for Composer package

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27771

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information. CVSSv3.1 8.2 (HIGH)

CWECWE 862VNDGiteaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score