Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Picklescan HIGH 7.8
CVE-2025-71357

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can…

Fix: 0.0.30+
Fix from $1,950 2026-06-21
Picklescan HIGH 7.8
CVE-2025-71378

picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. …

Fix: 0.0.30+
Fix from $1,950 2026-06-21
Picklescan HIGH 7.8
CVE-2025-71348

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. At…

Fix: 0.0.28+
Fix from $1,950 2026-06-21
Picklescan MEDIUM 6.5
CVE-2026-56304

picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte file…

Fix: 1.0.1+
Fix from $1,600 2026-06-20
Picklescan HIGH 7.8
CVE-2025-10157

A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsa…

Fix: 0.0.31+
Fix from $1,950 2025-09-17
Picklescan CRITICAL 9.8
CVE-2025-10156

An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker …

Fix: 0.0.31+
Fix from $2,300 2025-09-17
Picklescan HIGH 7.8
CVE-2025-10155

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacke…

Fix: 0.0.31+
Fix from $1,950 2025-09-17
Picklescan HIGH 7.5
CVE-2025-46417

The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deseria…

Fix: 0.0.25+
Fix from $1,950 2025-04-24
Picklescan CRITICAL 9.8
CVE-2025-1945

picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flippi…

Fix: 0.0.23+
Fix from $2,300 2025-03-10
Picklescan MEDIUM 6.5
CVE-2025-1944

picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model…

Fix: 0.0.23+
Fix from $1,600 2025-03-10
Picklescan CRITICAL 9.8
CVE-2025-1889

picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious …

Fix: 0.0.22+
Fix from $2,300 2025-03-03
Picklescan CRITICAL 9.8
CVE-2025-1716

picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious …

Fix: 0.0.22+
Fix from $2,300 2025-02-26