CVE Vulnerability Database

Search and browse 393,396 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-71374HIGH8.1picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce met...
CVE-2025-71371HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce meth...
CVE-2025-71368HIGH8.1picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attacke...
CVE-2025-71363HIGH8.1picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to exe...
CVE-2025-71355HIGH7.6Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass stat...
CVE-2025-71352HIGH8.1picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce...
CVE-2025-71350HIGH8.1picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce met...
CVE-2025-71349HIGH8.1picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing att...
CVE-2026-58450MEDIUM5.3Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthentic...
CVE-2026-58449CRITICAL9.8txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolve...
CVE-2026-58448HIGH7.1yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticate...
CVE-2026-58447HIGH7.1Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that...
CVE-2026-58446MEDIUM6.9Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authenticat...
CVE-2026-57585HIGH7.5MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/cras...
CVE-2026-57204MEDIUM6.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An at...
CVE-2026-52868HIGH8.8An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area...
CVE-2026-52196HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-50254HIGH8.7An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against store...
CVE-2026-50003CRITICAL9.8A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside th...
CVE-2026-37106CRITICAL9.8An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register functio...
CVE-2026-35505HIGH8.7An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process dep...
CVE-2026-11541CRITICAL9.8IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 an...
CVE-2026-10585MEDIUM5.4A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated att...
CVE-2026-9132MEDIUM6.5A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to r...
CVE-2026-9106MEDIUM5.5A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gai...