Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fickling CRITICAL 9.8
CVE-2026-14535

In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(n…

Fix: after 0.1.11
Fix from $2,300 2026-07-04
Fickling HIGH 8.8
CVE-2026-14534

Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in t…

Fix: after 0.1.10
Fix from $1,950 2026-07-04
Rfc3161 Client HIGH 7.5
CVE-2026-33753

rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerab…

Fix: 1.0.6+
Fix from $1,950 2026-04-08
Fickling HIGH 7.8
CVE-2026-22609

Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe_imports() method in Fickling's static analyzer fails…

Fix: 0.1.7+
Fix from $1,950 2026-01-10
Fickling HIGH 7.8
CVE-2026-22612

Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, Fickling is vulnerable to detection bypass due to "builtins" bl…

Fix: 0.1.7+
Fix from $1,950 2026-01-10
Fickling HIGH 7.8
CVE-2026-22606

Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat Python’s runpy module as unsaf…

Fix: 0.1.7+
Fix from $1,950 2026-01-10
Fickling HIGH 7.8
CVE-2026-22607

Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat Python's cProfile module as un…

Fix: 0.1.7+
Fix from $1,950 2026-01-10
Fickling HIGH 7.8
CVE-2026-22608

Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, both ctypes and pydoc modules aren't explicitly blocked. Even o…

Fix: 0.1.7+
Fix from $1,950 2026-01-10
Fickling HIGH 7.8
CVE-2025-67747

Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 are missing `marshal` and `types` from the block list of unsafe…

Fix: 0.1.6+
Fix from $1,950 2025-12-16
Fickling HIGH 7.8
CVE-2025-67748

Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missing from the block list of uns…

Fix: 0.1.6+
Fix from $1,950 2025-12-16
Uthenticode HIGH 7.5
CVE-2023-40012

uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x serie…

Fix: 2.0.0+
Fix from $1,950 2023-08-09
Uthenticode CRITICAL 9.8
CVE-2023-39969

uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire…

Fix: 1.0.9+
Fix from $2,300 2023-08-09