Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 CVE-2026-53874

picklescan – Arbitrary Code Execution via Obfuscated eval Call_CVE-2026-53874

picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval ca...

picklescan picklescan CVE
CRITICAL 9.3 CVE-2026-53873

picklescan – Arbitrary Code Execution via profile.run() Blocklist Bypass_CVE-2026-53873

picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowi...

picklescan picklescan CVE
CRITICAL 10 CVE-2026-3490

picklescan – Universal Blocklist Bypass via pkgutil.resolve_name_CVE-2026-3490

picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function ...

picklescan picklescan CVE
CRITICAL 9.1 CVE-2026-20181

Cisco Identity Services Engine Remote Code Execution Vulnerability_CVE-2026-20181

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating sy...

Cisco Cisco Identity Services Engine Software 3.1.0 CVE
CRITICAL 9.3 CVE-2025-71325

picklescan – Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw_CVE-2025-71325

picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track argument...

picklescan picklescan CVE
CRITICAL 9.3 CVE-2025-71323

picklescan – Remote Code Execution via Unblocked ctypes Module_CVE-2025-71323

picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and acce...

picklescan picklescan CVE
CRITICAL 9.3 CVE-2025-71321

picklescan – Arbitrary File Writing via distutils Module Bypass_CVE-2025-71321

picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutil...

picklescan picklescan CVE
CRITICAL 9.3 CVE-2025-71320

picklescan – Remote Code Execution via Incomplete Disallowed Inputs_CVE-2025-71320

picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers ...

picklescan picklescan CVE
CRITICAL 9.4 PACKETSTORM:223657

📄 dedoc/scramble 0.13.2 Remote Code Execution_PACKETSTORM:223657

This is a Metasploit exploit module for CVE-2026-44262, an unauthenticated remote code execution vulnerability in the Laravel-based tool dedoc/scra...

N/A N/A PACKETSTORM
CRITICAL 10 AE6219F6-F23B-

Exploit for CVE-2026-48907_AE6219F6-F23B-5FB3-886B-AFFE2FBDB4B1

CVE-2026-48907 CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated...

N/A N/A GITHUBEXPLOIT