Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2025-71344
picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function when scanning pickle files, …
Mitigation only
HIGH 8.1
CVE-2025-71358
picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entity function in reduce methods.…
Mitigation only
CRITICAL 9.2
CVE-2026-45034
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohi…
No fix yet
HIGH 7.8
CVE-2025-71357
picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can…
Picklescan
0.0.30+
HIGH 7.8
CVE-2025-71378
picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. …
Picklescan
0.0.30+
HIGH 7.8
CVE-2025-71348
picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. At…
Picklescan
0.0.28+
MEDIUM 6.3
CVE-2026-12787
A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part o…
Mitigation only
MEDIUM 6.5
CVE-2026-56304
picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte file…
Picklescan
1.0.1+
CRITICAL 9.5
CVE-2026-48909EPSS 8%
SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to …
Mitigation only
HIGH 8.1
CVE-2026-49286
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded the o…
Patch available
CRITICAL 9.0
CVE-2026-12046
Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/updat…
Pgadmin 4
9.16+
HIGH 7.2
CVE-2025-27511
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extens…
Geoserver
2.27.0+
CRITICAL 9.8
CVE-2026-8024
A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access t…
Mitigation only
CRITICAL 9.8
CVE-2026-12569 KEVEPSS 30%
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited t…
Flexplm
11.0m030+
CRITICAL 9.8
CVE-2026-53805
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /…
Patch available
CRITICAL 9.8
CVE-2026-53874
picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval call…
Mitigation only
CRITICAL 9.8
CVE-2025-71321
picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.…
Mitigation only
CRITICAL 9.8
CVE-2026-49108
Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
Mitigation only
HIGH 8.1
CVE-2026-40733
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
Mitigation only
HIGH 8.1
CVE-2026-40738
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
Mitigation only
HIGH 8.1
CVE-2026-40752
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
Mitigation only
HIGH 8.1
CVE-2026-40756
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
Mitigation only
HIGH 8.1
CVE-2026-40757
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
Mitigation only
HIGH 8.1
CVE-2026-39556
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
Mitigation only
HIGH 8.1
CVE-2026-39560
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
Mitigation only
HIGH 8.1
CVE-2026-39576
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
Mitigation only
HIGH 8.1
CVE-2026-39442
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
Mitigation only
HIGH 8.1
CVE-2026-39445
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
Mitigation only
CRITICAL 9.8
CVE-2025-69127
Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.
Mitigation only
HIGH 8.8
CVE-2025-69130
Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3.1.3 versions.
Mitigation only