Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
picklescan versions before 0.0.29 fail to detect malicious pickle files that exploit the idlelib.calltip.get_entity function in reduce methods. This allows attackers to embed code in pickle files that executes remote commands when loaded by victims. The vulnerability is classified under CWE-502 (Deserialization of Untrusted Data) and is considered high severity. No patch or official fix is currently documented. No known exploits in the wild have been reported. Join the discussion | GCVE Database | 07/04/2026, 03:31:02 UTC Added: 07/04/2026, 22:34:38 UTC |
picklescan versions before 0.0.33 do not detect operator.methodcaller function calls in pickle files, enabling attackers to bypass security checks. This allows remote attackers to craft malicious pickle payloads that execute arbitrary code when loaded, potentially compromising systems relying on picklescan for validation. Join the discussion | GCVE Database | 07/04/2026, 03:31:02 UTC Added: 07/04/2026, 22:34:38 UTC |
picklescan versions before 0.0.30 fail to detect the asyncio.unix_events._UnixSubprocessTransport._start function when used in pickle reduce methods. This allows attackers to craft malicious pickle files that evade detection but execute arbitrary commands upon loading, leading to remote code execution. Join the discussion | GCVE Database | 07/04/2026, 03:31:02 UTC Added: 07/04/2026, 22:34:38 UTC |
picklescan versions before 0.0.28 fail to detect malicious pickle files that exploit the torch._dynamo.guards.GuardBuilder.get function in reduce methods. This allows attackers to craft pickle files containing embedded code that bypasses picklescan detection and executes arbitrary commands upon loading. The vulnerability is categorized under CWE-502 (Deserialization of Untrusted Data) and is considered high severity. Join the discussion | GCVE Database | 07/04/2026, 03:31:02 UTC Added: 07/04/2026, 22:34:38 UTC |
Picklescan versions before 0.0.33 fail to detect a specific malicious gadget in pickle __reduce__ methods, enabling attackers to execute arbitrary Python code by crafting malicious pickle files. This bypasses Picklescan's safety checks and can lead to supply-chain poisoning of shared model files. Join the discussion | GCVE Database | 07/04/2026, 03:31:02 UTC Added: 07/04/2026, 22:34:38 UTC |
picklescan versions before 0.0.28 fail to detect malicious function calls to torch.utils.bottleneck.__main__.run_cprofile embedded in pickle files. This allows attackers to bypass safety checks and embed undetected code that can lead to arbitrary code execution when victims load these pickle files. Join the discussion | GCVE Database | 07/04/2026, 03:31:02 UTC Added: 07/04/2026, 22:34:38 UTC |
0 picklescan versions before 0.0.34 do not detect _operator.attrgetter function calls in pickle payloads. This allows attackers to craft malicious pickle files that use _operator.attrgetter in reduce methods to bypass security checks and execute arbitrary code during pickle.load(). Join the discussion | GCVE Database | 07/04/2026, 03:31:02 UTC Added: 07/04/2026, 22:34:38 UTC |
picklescan versions before 0.0.30 fail to detect malicious pickle files that invoke the torch.utils.bottleneck.__main__.run_autograd_prof function. This allows attackers to embed code in pickle files that executes during deserialization, enabling remote code execution. Join the discussion | GCVE Database | 07/04/2026, 03:31:02 UTC Added: 07/04/2026, 22:34:38 UTC |
picklescan versions before 0.0.34 do not detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. This allows attackers to craft malicious pickle payloads that evade detection and execute arbitrary code upon loading with pickle.load(). Join the discussion | GCVE Database | 07/04/2026, 03:31:02 UTC Added: 07/04/2026, 22:34:38 UTC |
Picklescan versions before 0.0.28 fail to detect malicious pickle files that exploit torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods. This allows attackers to bypass safety checks and embed malicious code that executes during deserialization, enabling remote code execution. Join the discussion | GCVE Database | 07/04/2026, 03:31:02 UTC Added: 07/04/2026, 22:34:36 UTC |
Showing 1 to 10 of 23 results