xp3s

2 exploits Active since Feb 2025
CVE-2025-45250 NOMISEC MEDIUM WORKING POC
mrdoc < 0.95 - Server-Side Request Forgery via validate_url Function
MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file.
CVSS 5.5
CVE-2025-1716 NOMISEC CRITICAL TROJAN
picklescan <0.0.21 - Code Injection
picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on pypi.org or GitHub) via `pip.main()`. Because pip is not a restricted global, the model, when scanned with picklescan, would pass security checks and appear to be safe, when it could instead prove to be problematic.
CVSS 9.8