Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 4 July 2026

RSS

248 vulnerabilities published on 4 July 2026

Severity:
Fickling MLAllowlist fails to check imports due to shared state
CVE-2026-14535
A bug in Fickling's import checking system allows malicious code to run by bypassing safety checks. This affects Fickling versions up to 0.1.11. To fix this, update to the latest version of Fickling.
9.8
Red Hat Hardened Images RPMs Updated to Fix Security Issues
RHSA-2026:30135
Red Hat Hardened Images RPMs have been updated to fix security issues and improve functionality. This update is important for users who rely on these images for secure and hardened environments. If yo...
9.1
Picklescan fails to detect malicious code in Python pickle files
GHSA-955r-x9j8-7rhh CVE-2025-71375
Picklescan is a library used to detect malicious pickle files, but it has a flaw that allows attackers to bypass its detection. This means that attackers can embed malicious code in pickle files that ...
9.1
Picklescan fails to detect malicious code in Python pickle files
GHSA-q77w-mwjj-7mqx CVE-2025-71364
Picklescan, a library used to detect malicious Python pickle files, has a weakness that can allow attackers to embed hidden code that executes when a pickle file is loaded. This can be used in supply ...
9.1
Fickling on Python 0.1.10 and earlier allows malicious code execution
CVE-2026-14534
Fickling versions up to 0.1.10 fail to block certain standard library modules, which can lead to malicious code being executed when deserializing untrusted data. To fix this, update to a version of fi...
8.8
Debian Linux: Unsecured Files in /usr/share/ca-certificates
DEBIAN-CVE-2026-53360
Debian Linux users may be at risk if their system has unsecured files in the /usr/share/ca-certificates directory. This could allow an attacker to trick the system into accepting a fake certificate, p...
8.8
KVM: SEV: Guest can corrupt host memory with malicious payload
CVE-2026-53360
This vulnerability affects the Linux kernel's KVM-SEV feature, which allows a malicious guest to corrupt the host's kernel heap memory and leak sensitive information. This is a significant risk becaus...
8.8
KVM: Fix Shadow Paging Use-After-Free on Linux
CVE-2026-53359
A vulnerability in the Linux kernel's KVM module has been fixed. It could have caused a use-after-free error when changing a guest's memory mapping. This could lead to data corruption or system crashe...
8.8
Debian Linux: Unauthenticated Code Execution via Samba
DEBIAN-CVE-2026-53359
A vulnerability in Debian's Samba package allows an attacker to execute malicious code on a vulnerable system without needing a password. This could allow an attacker to gain control of the system. De...
8.8
KVM: Shadow Paging Use-After-Free Risk on Linux
CVE-2026-53359
A Linux kernel issue affects KVM shadow paging, potentially leading to use-after-free errors when deleting a memory slot. This could cause data corruption or system crashes. To mitigate this risk, ens...
8.8
n8n - Malicious commands can be executed on the host system
CVE-2025-71380
The Execute Command node in n8n allows users to run arbitrary system commands. This means attackers can use a legitimate user's access to compromise the system, steal data, or disrupt services. To pro...
8.7
myVesta allows malicious users to run commands as admin
CVE-2026-12195
An attacker with a low-level account in myVesta can execute commands as the admin user, potentially taking control of the system. This is a serious issue because it allows unauthorized access to sensi...
8.5
Parsec on Windows: Elevation of Privilege via Malicious AppData
CVE-2026-54424
A vulnerability in Parsec for Windows allows a malicious user to potentially gain elevated system privileges. This could happen if a user controls the AppData environment variable, which is a setting ...
8.4
HestiaCP Admin Passwordless Access
CVE-2026-12196
A security issue in HestiaCP allows low-privilege users to gain full control over the web server and take over administrator accounts. This could lead to unauthorized access and changes to the system....
8.3
kirilkirkov Ecommerce CodeIgniter Bootstrap ShoppingCart deserialization risk
CVE-2026-14637
A security issue exists in the kirilkirkov Ecommerce CodeIgniter Bootstrap shopping cart system. If exploited, an attacker could access sensitive information or take control of the system. To fix this...
7.8
Dancer2::Plugin::Auth::OAuth: OAuth login vulnerable to account takeover
CVE-2026-12746
If you use this plugin for OAuth login, an attacker can hijack your users' accounts by tricking them into completing an authorization request started by the attacker. This can happen if an attacker co...
8.1
Perl's Plack::Middleware::OAuth allows login cross-site request forgery
CVE-2026-12740
An attacker can trick users into logging in with their own account, gaining access to the victim's account. This can happen if you use this Perl middleware for OAuth 2.0 login without updating to a su...
8.1
Red Hat Hardened Images RPMs Security Update for Linux
RHSA-2026:34975
This update addresses security vulnerabilities and improves functionality in Red Hat's Hardened Images RPMs, which are used to create secure and isolated Linux environments. Affected users should upda...
8.1
picklescan - Malicious Code Evades Detection in Pickle Files
CVE-2025-71375
picklescan versions before 0.0.34 can't detect certain malicious code in pickle files. This allows attackers to sneak in malicious code that can execute without being caught. Update to the latest vers...
7.6
picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads usi...
CVE-2025-71373
picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads using ...
7.6
Picklescan - Malicious Pickle Files Can Execute Arbitrary Code
CVE-2025-71372
Picklescan, a tool for detecting malicious pickle files, has a flaw in versions before 0.0.33. This means attackers can create fake pickle files that execute unauthorized code when loaded, which can b...
7.6
picklescan - Malicious Code Execution via Pickle Files
CVE-2025-71369
picklescan before version 0.0.28 fails to detect malicious pickle files, which can be exploited by attackers to execute malicious code remotely. This vulnerability affects the safety of picklescan whe...
7.6
picklescan: Malicious Pickle Files Can Execute Code Remotely
CVE-2025-71367
picklescan, a tool used to detect malicious pickle files, has a flaw that allows attackers to create malicious files that can execute code remotely. This means that attackers can potentially take cont...
7.6
picklescan before 0.0.28: Malicious Code Can Run Without Detection
CVE-2025-71366
picklescan, a tool for detecting malicious code in pickle files, has a flaw before version 0.0.28. This means attackers can sneak in malicious code that won't be caught, allowing them to run arbitrary...
7.6
picklescan - Remote Code Execution via Malicious Pickle Files
CVE-2025-71364
An outdated version of picklescan can execute arbitrary code if it loads a malicious pickle file. This means an attacker could potentially take control of the system by sending a specially crafted fil...
7.6