69 CVEs published July 4, 2026: 1 critical, 30 high, 14 medium, 24 low; 0 in KEV; 3 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 44 in the results table.
Yesterday's Results
69 CVEs published. 25 box scores, 44 table rows — nothing truncated.
Linux Linux — KVM: x86: Fix shadow paging use-after-free due to unexpected role
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N C H H H 8.8 .0091 57.0 —
AFFECTED
Product Versions Fixed
Linux 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 – —
Linux 2.6.36 – 6.1.177
TIMELINE
Jun 9 Reserved by CNA
Jul 4 Published (CNA: Linux)
NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L N N 5.5 .0067 49.1 —
AFFECTED
Product Versions Fixed
hermes-agent 2026.5.0 – —
TIMELINE
Jul 3 Reserved by CNA
Jul 4 Published (CNA: VulDB)
kirilkirkov Ecommerce-CodeIgniter-Bootstrap ShoppingCart.php getCartItems deserialization
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L N H 7.8 .0061 46.3 —
AFFECTED
Product Versions Fixed
Ecommerce-CodeIgniter-Bootstrap 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7 – —
TIMELINE
Jul 3 Reserved by CNA
Jul 4 Published (CNA: VulDB)
picklescan - Arbitrary Code Execution via Undetected asyncio.unix_events._UnixSubprocessTransport._start
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N P H H N 7.6 .0056 43.7 —
AFFECTED
Product Versions Fixed
picklescan unspecified 0.0.30
TIMELINE
Jun 20 Reserved by CNA
Jul 4 Published (CNA: VulnCheck)
picklescan - Undetected Remote Code Execution via numpy.f2py.crackfortran.param_eval
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N P H H N 7.6 .0044 37.0 —
AFFECTED
Product Versions Fixed
picklescan unspecified 0.0.33
TIMELINE
Jun 20 Reserved by CNA
Jul 4 Published (CNA: VulnCheck)
picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_cprofile
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N P H H N 7.6 .0044 37.0 —
AFFECTED
Product Versions Fixed
picklescan unspecified 0.0.28
TIMELINE
Jun 20 Reserved by CNA
Jul 4 Published (CNA: VulnCheck)
picklescan - Remote Code Execution via _operator.attrgetter Detection Bypass
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N P H H N 7.6 .0044 37.0 —
AFFECTED
Product Versions Fixed
picklescan unspecified 0.0.34
TIMELINE
Jun 20 Reserved by CNA
Jul 4 Published (CNA: VulnCheck)
picklescan - Unsafe Deserialization via torch.utils.data.datapipes.utils.decoder.basichandlers
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N P H H N 7.6 .0044 37.0 —
AFFECTED
Product Versions Fixed
picklescan unspecified 0.0.28
TIMELINE
Jun 20 Reserved by CNA
Jul 4 Published (CNA: VulnCheck)
picklescan - Remote Code Execution via operator.methodcaller Detection Bypass
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N P H H N 7.6 .0044 36.9 —
AFFECTED
Product Versions Fixed
picklescan unspecified 0.0.33
TIMELINE
Jun 20 Reserved by CNA
Jul 4 Published (CNA: VulnCheck)
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Multi-Image Endpoint AddProduct.php path traversal
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0044 36.5 —
AFFECTED
Product Versions Fixed
Ecommerce-CodeIgniter-Bootstrap 222ff31c06687b1c6d0e1ab63953f82c3674c52b – —
TIMELINE
Jul 3 Reserved by CNA
Jul 4 Published (CNA: VulDB)
picklescan - Undetected Remote Code Execution via idlelib.run.Executive.runcode
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N P H H N 7.6 .0043 35.6 —
AFFECTED
Product Versions Fixed
picklescan unspecified 0.0.30
TIMELINE
Jun 20 Reserved by CNA
Jul 4 Published (CNA: VulnCheck)
picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_autograd_prof
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N P H H N 7.6 .0043 35.6 —
AFFECTED
Product Versions Fixed
picklescan unspecified 0.0.30
TIMELINE
Jun 20 Reserved by CNA
Jul 4 Published (CNA: VulnCheck)
picklescan - Unsafe Deserialization via lib2to3.pgen2.grammar.Grammar.loads
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N P H H N 7.6 .0043 35.6 —
AFFECTED
Product Versions Fixed
picklescan unspecified 0.0.29
TIMELINE
Jun 20 Reserved by CNA
Jul 4 Published (CNA: VulnCheck)
myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can inser…
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H N N 8.5 .0042 35.4 —
AFFECTED
Product Versions Fixed
vesta unspecified —
TIMELINE
Jun 14 Reserved by CNA
Jul 4 Published (CNA: PRJBLK)
n8n - Arbitrary Command Execution via Execute Command Node
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 8.7 .0041 34.4 —
AFFECTED
Product Versions Fixed
n8n unspecified —
TIMELINE
Jun 20 Reserved by CNA
Jul 4 Published (CNA: VulnCheck)
jairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authentication
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0041 34.0 —
AFFECTED
Product Versions Fixed
restaurant-website-php-mysql 521428b5b612449df0cf4a5d15ee40cba67f3d35 – —
TIMELINE
Jul 3 Reserved by CNA
Jul 4 Published (CNA: VulDB)
Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.getlincoef Gadget
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N P H H N 7.6 .0038 31.1 —
AFFECTED
Product Versions Fixed
Picklescan unspecified 0.0.33
TIMELINE
Jun 20 Reserved by CNA
Jul 4 Published (CNA: VulnCheck)
NousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authentication
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H N N N L L L 2.9 .0037 29.9 —
AFFECTED
Product Versions Fixed
hermes-agent 0.15.0 – —
TIMELINE
Jul 3 Reserved by CNA
Jul 4 Published (CNA: VulDB)
trailofbits fickling — Fickling check_safety() bypass via unlisted standard library modules (_posixsubprocess, site, atexit)
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R U H H H 8.8 .0037 29.7 —
AFFECTED
Product Versions Fixed
fickling unspecified 0.1.11
TIMELINE
Jul 3 Reserved by CNA
Jul 4 Public exploit reference published
Jul 4 Published (CNA: BombadilSystems)
picklescan - Undetected Remote Code Execution via _operator.methodcaller
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N P H H N 7.6 .0037 29.6 —
AFFECTED
Product Versions Fixed
picklescan unspecified 0.0.34
TIMELINE
Jun 20 Reserved by CNA
Jul 4 Published (CNA: VulnCheck)
code-projects Online Voting System Login authentication.php test_input sql injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0035 27.8 —
AFFECTED
Product Versions Fixed
Online Voting System 0.* – —
TIMELINE
Jul 3 Reserved by CNA
Jul 4 Published (CNA: VulDB)
trailofbits fickling — Fickling MLAllowlist analysis pass rendered inoperative by shared mutable state in AnalysisContext.shorten_code()
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .0033 26.1 —
AFFECTED
Product Versions Fixed
fickling unspecified 0.1.12
TIMELINE
Jul 3 Reserved by CNA
Jul 4 Public exploit reference published
Jul 4 Published (CNA: BombadilSystems)
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Image Manager AddProduct.php do_upload_others_images path traversal
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N N L L 5.3 .0032 25.1 —
AFFECTED
Product Versions Fixed
Ecommerce-CodeIgniter-Bootstrap 23105f25dadf57b4314fc015a63a7c6e910c89df – —
TIMELINE
Jul 3 Reserved by CNA
Jul 4 Published (CNA: VulDB)
omec-project amf NGAP Message RRCInactiveTransitionReport denial of service
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N N N L 2.1 .0032 24.4 —
AFFECTED
Product Versions Fixed
amf 2.1.0 – —
TIMELINE
Jul 3 Reserved by CNA
Jul 4 Published (CNA: VulDB)
omec-project amf NGSetupRequest handler.go denial of service
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N N N L 2.1 .0032 24.4 —
AFFECTED
Product Versions Fixed
amf 2.0.0 – —
TIMELINE
Jul 3 Reserved by CNA
Jul 4 Published (CNA: VulDB)
Remainder (ranked, continued)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
| CVE-2026-14618 | 2.1 | 24.3 | n/a | Open5GS | CWE-404 | Open5GS AMF nnrf-handler.c amf_nnrf_handle_nf_discover denial of service |
| CVE-2026-14629 | 2.1 | 23.5 | n/a | RT-Thread | CWE-369 | RT-Thread Parameter lwp_syscall.c sys_ioctl divide by zero |
| CVE-2025-71343 | 7.6 | 22.6 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via lib2to3.pgen2.pgen.ParserGenerator.… |
| CVE-2025-71353 | 7.6 | 22.6 | picklescan | picklescan | CWE-502 | picklescan - Remote Code Execution via torch._dynamo.guards.GuardBuilder.get |
| CVE-2025-71356 | 7.6 | 22.6 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via torch.fx.experimental.symbolic_shap… |
| CVE-2025-71360 | 7.6 | 22.6 | picklescan | picklescan | CWE-502 | picklescan - Remote Code Execution via Undetected idlelib.calltip.get_entity |
| CVE-2025-71362 | 7.6 | 22.6 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via Unsafe Deserialization in numpy.f2p… |
| CVE-2026-14633 | 2.1 | 21.2 | kirilkirkov | Ecommerce-CodeIgniter-Bootstrap | CWE-79 | kirilkirkov Ecommerce-CodeIgniter-Bootstrap Hidden REST API Endpoint set cros… |
| CVE-2026-14634 | 2.1 | 21.2 | kirilkirkov | Ecommerce-CodeIgniter-Bootstrap | CWE-79 | kirilkirkov Ecommerce-CodeIgniter-Bootstrap Subscribed Emails Admin MY_Contro… |
| CVE-2026-14656 | 2.1 | 20.3 | code-projects | Assessment Management | CWE-79 | code-projects Assessment Management remove-user.php cross site scripting |
| CVE-2026-14626 | 2.1 | 20.1 | NousResearch | hermes-agent | CWE-404 | NousResearch hermes-agent HTTP API run_agent.py AIAgent.run_conversation deni… |
| CVE-2026-14632 | 2.1 | 19.6 | kirilkirkov | Ecommerce-CodeIgniter-Bootstrap | CWE-601 | kirilkirkov Ecommerce-CodeIgniter-Bootstrap Trusted Backend MY_Controller.php… |
| CVE-2026-14649 | 6.9 | 19.1 | code-projects | Online Voting System | CWE-74 | code-projects Online Voting System saveVote.php test_input sql injection |
| CVE-2026-14642 | 5.5 | 19.1 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_class2.php sql injection |
| CVE-2026-14652 | 5.5 | 19.1 | SourceCodester | Simple and Nice Shopping Cart Script | CWE-74 | SourceCodester Simple and Nice Shopping Cart Script Admin Login login.php sql… |
| CVE-2026-14653 | 5.5 | 19.1 | SourceCodester | Simple and Nice Shopping Cart Script | CWE-74 | SourceCodester Simple and Nice Shopping Cart Script mensproductdeletequery.ph… |
| CVE-2026-14654 | 5.5 | 19.1 | SourceCodester | Simple and Nice Shopping Cart Script | CWE-74 | SourceCodester Simple and Nice Shopping Cart Script girlsproductdeletequery.p… |
| CVE-2026-14641 | 5.5 | 18.5 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_course.php sql injection |
| CVE-2026-53362 | 7.8 | 18.5 | Linux | Linux | — | ipv6: account for fraggap on the paged allocation path |
| CVE-2026-14640 | 5.5 | 18.2 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System Login index.php sql injection |
| CVE-2026-14660 | 5.5 | 18.2 | code-projects | Online Job Portal | CWE-74 | code-projects Online Job Portal login.php sql injection |
| CVE-2026-12196 | 8.3 | 17.4 | hestiacp | hestiacp | CWE-287 | HestiaCP Admin Takeover |
| CVE-2026-14647 | 2.1 | 17.0 | n/a | onnx | CWE-119 | onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds |
| CVE-2026-12194 | 2.3 | 16.6 | phpipam | phpipam | CWE-98 | PHPIPAM Authenticated LFI |
| CVE-2026-54424 | 8.4 | 16.0 | Unity | Parsec | CWE-648 | An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows … |
| CVE-2026-14621 | 1.3 | 15.4 | FederatedAI | FATE | CWE-488 | FederatedAI FATE OSX Broker QueuePushReqStreamObserver.java QueuePushReqStrea… |
| CVE-2026-14625 | 2.1 | 13.3 | NousResearch | hermes-agent | CWE-693 | NousResearch hermes-agent server.py shell.exec protection mechanism |
| CVE-2026-14655 | 1.9 | 12.1 | code-projects | Assessment Management | CWE-79 | code-projects Assessment Management view-users.php cross site scripting |
| CVE-2026-14619 | 2.1 | 10.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System medicine.php sql injection |
| CVE-2026-14657 | 2.1 | 10.7 | code-projects | Assessment Management | CWE-74 | code-projects Assessment Management Database Query marking-scheme.php sql inj… |
| CVE-2026-14638 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patient.php sql injection |
| CVE-2026-14639 | 2.1 | 10.2 | CodeAstro | Ecommerce Website | CWE-74 | CodeAstro Ecommerce Website my_account.php sql injection |
| CVE-2026-14658 | 2.1 | 10.2 | code-projects | Assessment Management | CWE-74 | code-projects Assessment Management marking-scheme.php sql injection |
| CVE-2026-14659 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patientappointment.php sql injection |
| CVE-2026-12252 | 7.8 | 9.5 | nltk | nltk/nltk | CWE-94 | Untrusted JAR Code Execution in Multiple Stanford Interface Classes in nltk/nltk |
| CVE-2026-12746 | 8.1 | 8.5 | BIAFRA | Dancer2::Plugin::Auth::OAuth::Provider | CWE-352 | Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not s… |
| CVE-2026-53360 | 8.8 | 8.1 | Linux | Linux | CWE-125 | KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use |
| CVE-2024-1248 | 5.3 | 8.1 | WSO2 | WSO2 API Manager | CWE-298 | Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enable… |
| CVE-2026-12740 | 8.1 | 6.9 | CORNELIUS | Plack::Middleware::OAuth | CWE-352 | Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OA… |
| CVE-2026-14630 | 1.3 | 5.6 | ForceInjection | AI-fundermentals | CWE-327 | ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_c… |
| CVE-2025-13475 | 7.3 | 5.5 | WSO2 | WSO2 Identity Server | CWE-288 | Cross-Tenant Access via Application Consent Mismanagement in Multiple WSO2 Pr… |
| CVE-2026-53361 | 7.1 | 3.1 | Linux | Linux | — | af_unix: Set gc_in_progress to true in unix_gc(). |
| CVE-2026-14650 | 1.9 | 1.9 | connorskees | grass | CWE-404 | connorskees grass UTF-8 Character raw_to_parse_error denial of service |
| CVE-2026-14651 | 1.9 | 1.8 | connorskees | grass | CWE-404 | connorskees grass visitor denial of service |