Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 299 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.43% | — | Microsoft Python | 8/7/2025 | 17/6/2026 | Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.32% | — | Python Pillow | 1/7/2025 | 17/6/2026 | Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only affects users who save untrusted data as a… | |
| Modificada | Media (6.1) | 0.39% | — | Python Urllib3 | 19/6/2025 | 17/6/2026 | urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be… | |
| Modificada | Media (6.1) | 0.47% | — | Python Urllib3 | 19/6/2025 | 17/6/2026 | urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or… | |
| Aplazada | Media (4.3) | 0.59% | — | Python Html.parserAI | 17/6/2025 | 31/7/2026 | The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service. | |
| Analizada | Media (5.1) | 0.86% | — | Themanojdesai Python A2A | 17/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file python_a2a/agent_flow/server/api.py. The manipulation leads to path traversal. Upgrading to version 0.5.6 is able to address this issue. It is recommended to upgrade the… | |
| Analizada | Alta (8.2) | 0.26% | — | Google Protobuf-python | 16/6/2025 | 17/6/2026 | Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with… | |
| Aplazada | Crítica (9.4) | 1.4% | — | Python TarfileAI | 3/6/2025 | 31/7/2026 | Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See… | |
| Aplazada | Alta (7.5) | 0.59% | — | Python TarfileAI | 3/6/2025 | 31/7/2026 | When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped. | |
| Aplazada | Alta (7.5) | 0.94% | — | Python TarfileAI | 3/6/2025 | 31/7/2026 | Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the… | |
| Aplazada | Alta (7.5) | 1.4% | — | PythonAI | 3/6/2025 | 31/7/2026 | Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the… | |
| Aplazada | Media (5.3) | 0.77% | — | PythonAI | 3/6/2025 | 31/7/2026 | Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extraction directory. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using… | |
| Aplazada | Alta (7) | 0.30% | — | Amazon Redshift Python ConnectorAI | 27/5/2025 | 17/6/2026 | When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. An insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. This issue has… | |
| Analizada | Alta (7.7) | 1.5% | — | Python SetuptoolsDebian Linux | 17/5/2025 | 17/6/2026 | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of… | |
| Aplazada | Media (5.9) | 0.22% | — | CpythonAI | 15/5/2025 | 31/7/2026 | There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except… | |
| Aplazada | Media (4.6) | 0.26% | — | Simple Python EncryptionAI | 8/5/2025 | 17/6/2026 | Programs/P73_SimplePythonEncryption.py illustrates a simple Python encryption example using the RSA Algorithm. In versions prior to commit 6ce60b1, an attacker may be able to decrypt the data using brute force attacks and because of this the whole application can be impacted. This issue has been patched in commit… | |
| Analizada | Media (4.8) | 0.40% | — | Oracle Mysql Connector/python | 15/4/2025 | 3/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require… | |
| Aplazada | Media (5.9) | 0.26% | — | Amazon Sagemaker Python SDKAI | 20/3/2025 | 17/6/2026 | A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This issue can cause… | |
| Aplazada | Media (4.4) | 0.40% | — | Python Urllib3AIPython RequestsAI | 12/3/2025 | 17/6/2026 | Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied. | |
| Analizada | Alta (8.8) | 1.6% | — | Nhairs Python Json Logger | 7/3/2025 | 17/6/2026 | Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was… | |
| Analizada | Alta (7.7) | 0.38% | — | Heinlein-support Check MK Python API | 3/3/2025 | 17/6/2026 | Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1 | |
| Aplazada | Baja (2.3) | 0.52% | — | CpythonAI | 14/2/2025 | 17/6/2026 | There is a defect in the CPython standard library module “mimetypes” where on Windows the default list of known file locations are writable meaning other users can create invalid files to cause MemoryError to be raised on Python runtime startup or have file extensions be interpreted as the incorrect file type. This… | |
| Aplazada | Media (6.3) | 1.6% | — | PythonAI | 31/1/2025 | 31/7/2026 | The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing… | |
| Aplazada | Alta (7.9) | 0.40% | — | CpythonAIZope RestrictedpythonAI | 23/1/2025 | 17/6/2026 | RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Via a type confusion bug in versions of the CPython interpreter starting in 3.11 and prior to 3.13.2 when using `try/except*`, RestrictedPython starting in version 6.0 and… | |
| Analizada | Media (6.4) | 0.46% | — | Oracle Mysql Connector/python | 21/1/2025 | 17/6/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require… |