CVE Vulnerability Database
Search and browse 393,396 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71374 | HIGH | 8.1 | 0.6% | Jun 30, 2026 | picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce met... |
| CVE-2025-71371 | HIGH | 8.1 | 0.5% | Jun 30, 2026 | picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce meth... |
| CVE-2025-71368 | HIGH | 8.1 | 0.8% | Jun 30, 2026 | picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attacke... |
| CVE-2025-71363 | HIGH | 8.1 | 0.6% | Jun 30, 2026 | picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to exe... |
| CVE-2025-71355 | HIGH | 7.6 | 0.6% | Jun 30, 2026 | Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass stat... |
| CVE-2025-71352 | HIGH | 8.1 | 0.6% | Jun 30, 2026 | picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce... |
| CVE-2025-71350 | HIGH | 8.1 | 0.4% | Jun 30, 2026 | picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce met... |
| CVE-2025-71349 | HIGH | 8.1 | 0.6% | Jun 30, 2026 | picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing att... |
| CVE-2026-58450 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthentic... |
| CVE-2026-58449 | CRITICAL | 9.8 | 0.7% | Jun 30, 2026 | txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolve... |
| CVE-2026-58448 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticate... |
| CVE-2026-58447 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that... |
| CVE-2026-58446 | MEDIUM | 6.9 | 0.4% | Jun 30, 2026 | Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authenticat... |
| CVE-2026-57585 | HIGH | 7.5 | 0.3% | Jun 30, 2026 | MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/cras... |
| CVE-2026-57204 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An at... |
| CVE-2026-52868 | HIGH | 8.8 | 0.4% | Jun 30, 2026 | An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area... |
| CVE-2026-52196 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-50254 | HIGH | 8.7 | 0.4% | Jun 30, 2026 | An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against store... |
| CVE-2026-50003 | CRITICAL | 9.8 | 0.4% | Jun 30, 2026 | A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside th... |
| CVE-2026-37106 | CRITICAL | 9.8 | 0.5% | Jun 30, 2026 | An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register functio... |
| CVE-2026-35505 | HIGH | 8.7 | 0.4% | Jun 30, 2026 | An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process dep... |
| CVE-2026-11541 | CRITICAL | 9.8 | 0.3% | Jun 30, 2026 | IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 an... |
| CVE-2026-10585 | MEDIUM | 5.4 | 0.3% | Jun 30, 2026 | A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated att... |
| CVE-2026-9132 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to r... |
| CVE-2026-9106 | MEDIUM | 5.5 | 0.3% | Jun 30, 2026 | A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gai... |
