Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-32967

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks_CVE-2026-32967

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: befo...

Apache Software Foundation Apache DolphinScheduler CVE
HIGH 7.5 CVE-2026-32966

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure_CVE-2026-32966

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apach...

Apache Software Foundation Apache DolphinScheduler CVE
HIGH 7.5 CVE-2026-9675

undici WebSocket client vulnerable to denial of service via cumulative fragment bypass_CVE-2026-9675

Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages....

undici undici 8.0.0 CVE
HIGH 7.1 CVE-2026-53875

picklescan – Scanning Bypass via Dynamic Eval in scan_pytorch_CVE-2026-53875

picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to embed malicious magic number...

picklescan picklescan CVE
CRITICAL 9.3 CVE-2026-53874

picklescan – Arbitrary Code Execution via Obfuscated eval Call_CVE-2026-53874

picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval ca...

picklescan picklescan CVE
CRITICAL 9.3 CVE-2026-53873

picklescan – Arbitrary Code Execution via profile.run() Blocklist Bypass_CVE-2026-53873

picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowi...

picklescan picklescan CVE
HIGH 8.7 CVE-2026-53872

picklescan – Arbitrary File Read via Unsafe Pickle Deserialization_CVE-2026-53872

picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to read arbitrary server files ...

picklescan picklescan CVE
CRITICAL 10 CVE-2026-3490

picklescan – Universal Blocklist Bypass via pkgutil.resolve_name_CVE-2026-3490

picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function ...

picklescan picklescan CVE
MEDIUM 5.7 CVE-2026-35069

CVE-2026-35069_CVE-2026-35069

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') v...

Dell PowerFlex CVE
LOW 3.5 CVE-2026-35068

CVE-2026-35068_CVE-2026-35068

Dell PowerFlex Manager, version(s) [Versions], contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') v...

Dell PowerFlex CVE