CVE Vulnerability Database
Search and browse 390,091 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12252 | HIGH | 7.8 | 0.1% | Jul 4, 2026 | In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, Stanford... |
| CVE-2025-71380 | HIGH | 8.8 | 0.4% | Jul 4, 2026 | The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n ru... |
| CVE-2025-71375 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for mal... |
| CVE-2025-71373 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to byp... |
| CVE-2025-71372 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, all... |
| CVE-2025-71369 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basich... |
| CVE-2025-71367 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to b... |
| CVE-2025-71366 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle... |
| CVE-2025-71364 | HIGH | 8.1 | 0.6% | Jul 4, 2026 | picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle redu... |
| CVE-2025-71362 | HIGH | 8.1 | 0.3% | Jul 4, 2026 | picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbi... |
| CVE-2025-71360 | HIGH | 8.1 | 0.3% | Jul 4, 2026 | picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce meth... |
| CVE-2025-71359 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in t... |
| CVE-2025-71356 | HIGH | 8.1 | 0.3% | Jul 4, 2026 | picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expres... |
| CVE-2025-71353 | HIGH | 8.1 | 0.3% | Jul 4, 2026 | picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get funct... |
| CVE-2025-71347 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in red... |
| CVE-2025-71345 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd... |
| CVE-2025-71343 | HIGH | 8.1 | 0.3% | Jul 4, 2026 | picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_lab... |
| CVE-2025-71342 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. A... |
| CVE-2026-54424 | HIGH | 8.4 | 0.2% | Jul 4, 2026 | An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Pri... |
| CVE-2026-58523 | MEDIUM | 6.5 | 0.5% | Jul 3, 2026 | Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over ... |
| CVE-2026-14617 | LOW | 3.1 | 0.2% | Jul 3, 2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function Gatewa... |
| CVE-2026-58597 | MEDIUM | 4.3 | 0.4% | Jul 3, 2026 | Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to pe... |
| CVE-2026-58524 | MEDIUM | 6.1 | 0.2% | Jul 3, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) ... |
| CVE-2026-58522 | MEDIUM | 6.8 | 0.3% | Jul 3, 2026 | Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. |
| CVE-2026-58426 | CRITICAL | 9.6 | 0.2% | Jul 3, 2026 | Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state w... |
