Mmaitre314
Mmaitre314 Picklescan: vulnerabilidades y CVE
Mmaitre314 Picklescan tiene 57 vulnerabilidades publicadas, 49 de ellas en los últimos 12 meses. 11 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE57
Últimos 12 meses49
Críticas11
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-71375 | Alta (7.6) | 0.46% | — | 4 jul 2026 | picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade… |
| CVE-2025-71373 | Alta (7.6) | 0.56% | — | 4 jul 2026 | picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads using… |
| CVE-2025-71372 | Alta (7.6) | 0.48% | — | 4 jul 2026 | Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary… |
| CVE-2025-71367 | Alta (7.6) | 0.56% | — | 4 jul 2026 | picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using _operator.attrgetter… |
| CVE-2025-71366 | Alta (7.6) | 0.56% | — | 4 jul 2026 | picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. Remote attackers can embed undetected code in… |
| CVE-2025-71364 | Alta (7.6) | 0.70% | — | 4 jul 2026 | picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. Attackers can craft malicious pickle files embedding… |
| CVE-2025-71362 | Alta (7.6) | 0.43% | — | 4 jul 2026 | picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. Attackers can embed malicious code in pickle files that executes when loaded from… |
| CVE-2025-71360 | Alta (7.6) | 0.38% | — | 4 jul 2026 | picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded… |
| CVE-2025-71359 | Alta (7.6) | 0.61% | — | 4 jul 2026 | picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing remote code execution. Attackers can craft pickle files embedding… |
| CVE-2025-71356 | Alta (7.6) | 0.38% | — | 4 jul 2026 | picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function calls in pickle files. Attackers can embed undetected code in pickle files that… |
| CVE-2025-71353 | Alta (7.6) | 0.38% | — | 4 jul 2026 | picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attackers can craft pickle files with embedded code that evades picklescan… |
| CVE-2025-71347 | Alta (7.6) | 0.56% | — | 4 jul 2026 | picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed undetected… |
| CVE-2025-71345 | Alta (7.6) | 0.54% | — | 4 jul 2026 | picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during… |
| CVE-2025-71343 | Alta (7.6) | 0.38% | — | 4 jul 2026 | picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded code… |
| CVE-2025-71342 | Alta (7.6) | 0.54% | — | 4 jul 2026 | picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling… |
| CVE-2025-71374 | Alta (7.6) | 0.72% | — | 30 jun 2026 | picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle… |
| CVE-2025-71371 | Alta (7.6) | 0.57% | — | 30 jun 2026 | picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce methods. Attackers can craft pickle payloads that bypass picklescan detection and execute arbitrary… |
| CVE-2025-71368 | Alta (7.6) | 0.84% | — | 30 jun 2026 | picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files embedding… |
| CVE-2025-71363 | Alta (7.6) | 0.67% | — | 30 jun 2026 | picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files with cProfile.run payloads… |
| CVE-2025-71355 | Alta (7.6) | 0.63% | — | 30 jun 2026 | Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass static analysis and execute arbitrary code during deserialization. Attackers can craft malicious pickle… |
| CVE-2025-71352 | Alta (7.6) | 0.72% | — | 30 jun 2026 | picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle… |
| CVE-2025-71350 | Alta (7.6) | 0.45% | — | 30 jun 2026 | picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded… |
| CVE-2025-71349 | Alta (7.6) | 0.61% | — | 30 jun 2026 | picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using… |
| CVE-2025-71340 | Alta (7.6) | 0.38% | — | 25 jun 2026 | picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attackers can embed undetected code in pickle files that executes arbitrary… |
| CVE-2025-71361 | Alta (7.6) | 0.43% | — | 24 jun 2026 | picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attackers can embed undetected payloads in pickle files that execute arbitrary… |
| CVE-2025-71354 | Alta (7.6) | 0.45% | — | 24 jun 2026 | picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. Attackers can craft pickle files with embedded code that bypasses… |
| CVE-2026-56315 | Crítica (9.3) | 1.1% | — | 23 jun 2026 | picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functions that provide direct arbitrary… |
| CVE-2025-71376 | Alta (7.6) | 0.38% | — | 23 jun 2026 | picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoComplete.fetch_completions in reduce methods. Attackers can embed undetected code in pickle files that executes arbitrary… |
| CVE-2025-71370 | Alta (7.6) | 0.48% | — | 23 jun 2026 | picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded in pickle files. Attackers can craft malicious pickle files that bypass picklescan detection and… |
| CVE-2025-71365 | Alta (7.6) | 0.38% | — | 23 jun 2026 | picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.myeval function through the reduce method. Attackers can craft malicious pickle files embedding arbitrary code that… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.