VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,309 CVE recordsPage 424 of 1288 · EPSS data 2026.08.12
ReviewHigh
CVE-2025-71353

picklescan

picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attackers can craft pickle files with embedded code that evades picklescan detection and executes arbitrary commands when loaded.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-71347

picklescan

picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed undetected code in pickle files that executes during deserialization, enabling arbitrary code execution in applications loading untrusted pickle data.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-71345

picklescan

picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-71343

picklescan

picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded code that evades detection but executes arbitrary commands when pickle.load() is called.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-71342

picklescan

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch models and supply chain attacks.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54424

Unity Parsec

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of parsecd.exe running as NT AUTHORITY\SYSTEM with a user-controlled value of the AppData environment variable.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-58424

Gitea Gitea Open Source Git Server

CVE-2026-58424 affects Gitea Gitea Open Source Git Server. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-58422

Gitea Gitea Open Source Git Server

CVE-2026-58422 affects Gitea Gitea Open Source Git Server. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-58421

Gitea Gitea Open Source Git Server

CVE-2026-58421 affects Gitea Gitea Open Source Git Server. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-58419

Gitea Gitea Open Source Git Server

CVE-2026-58419 affects Gitea Gitea Open Source Git Server. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.