2026-06-30
2026-06-30 23:16Z
CRIT

CVE-2026-13775 — Google Chrome: Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13775

Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.8 (CRITICAL)

CWECWE 416VNDGoogleTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 23:16Z
HIGH

CVE-2026-13774 — Google Chrome: Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13774

Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical) CVSSv3.1 8.1 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:16Z
HIGH

CVE-2025-71374 — picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71374

picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files that bypass picklescan detection and achieve code execution upon deserialization. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:16Z
HIGH

CVE-2025-71371 — Attackers can craft pickle payloads that bypass picklescan detection and execute arbitrary code when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71371

picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce methods. Attackers can craft pickle payloads that bypass picklescan detection and execute arbitrary code when loaded via pickle.load(). CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:16Z
HIGH

CVE-2025-71368 — picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71368

picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files embedding doctest.debug_script calls that bypass picklescan detection and execute arbitrary commands upon pickle.load invocation. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:16Z
HIGH

CVE-2025-71363 — picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71363

picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files with cProfile.run payloads that bypass picklescan detection and achieve code execution upon deserialization. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:16Z
HIGH

CVE-2025-71352 — picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71352

picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files with trace.Trace.runctx payloads that bypass picklescan detection and execute code upon pickle.load() invocation. CVSSv3.1 8.1 (HIGH)

CWECWE 693TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-30
2026-06-30 23:16Z
HIGH

CVE-2025-71350 — picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71350

picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 23:16Z
HIGH

CVE-2025-71349 — Remote attackers can craft malicious pickle files using trace.Trace.run in the reduce method to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71349

picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using trace.Trace.run in the reduce method to achieve arbitrary code execution when pickle.load processes the file. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 22:16Z
CRIT

CVE-2026-58449 — When the API is exposed with no TOKEN configured (authentication is opt-in, so all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58449

txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver, which performs __import__ and getattr on the caller-supplied dotted path with no allowlist. When the API is exposed with no TOKEN configured (authentication is opt-in, so all endpoints are unauthenticated) and the index is configured writable, a remote attacker can set function to an arbitrary callable such as subprocess.getout CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 22:16Z
HIGH

CVE-2026-52868 — An unauthenticated attacker can read worklist records from a directory outside the intended per-AE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52868

An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation. CVSSv3.1 8.2 (HIGH)

CWECWE 22TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 22:16Z
CRIT

CVE-2026-50003 — A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50003

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 22:16Z
CRIT

CVE-2026-37106 — DokuWiki: An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-37106

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). CVSSv3.1 9.8 (CRITICAL)

CWECWE 640VNDDokuwikiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 21:16Z
HIGH

CVE-2026-11594 — IBM: WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11594

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console. CVSSv3.1 8.5 (HIGH)

CWECWE 79VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-30
2026-06-30 21:16Z
HIGH

CVE-2025-36359 — IBM: DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-36359

IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system. CVSSv3.1 8.1 (HIGH)

CWECWE 613VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 20:17Z
CRIT

CVE-2026-7874 — IBM: Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7874

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encryption at rest. CVSSv3.1 9.1 (CRITICAL)

CWECWE 338VNDIbmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-30
2026-06-30 20:17Z
CRIT

CVE-2026-7873 — IBM: Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7873

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDIbmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-30
2026-06-30 20:17Z
CRIT

CVE-2026-7871 — IBM: Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7871

IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 20:17Z
CRIT

CVE-2026-7803 — IBM: Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7803

IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 20:17Z
CRIT

CVE-2026-7663 — IBM: Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7663

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint. CVSSv3.1 9.1 (CRITICAL)

CWECWE 285VNDIbmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-30
2026-06-30 20:17Z
HIGH

CVE-2026-11714 — IBM: WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11714

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-30
2026-06-30 20:17Z
CRIT

CVE-2026-11712 — IBM: WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11712

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system. CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDIbmTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-30
2026-06-30 20:17Z
CRIT

CVE-2026-11708 — IBM: WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11708

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help system. CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDIbmTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-30
2026-06-30 20:17Z
HIGH

CVE-2026-10564 — IBM: Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10564

IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in searxng.py make unvalidated HTTP requests to user-controlled URLs, bypassing SSRF protections introduced in version 1.9.3. An authenticated attacker can exploit this to access internal resources including cloud metadata services (AWS/Azure/GCP IMDS), potentially exfiltrating IAM credentials and enumerating internal networks. The CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 20:17Z
HIGH

CVE-2026-10560 — IBM: Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10560

IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service. CVSSv3.1 8.2 (HIGH)

CWECWE 287VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score