Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.68%—Python-sqlAI27/12/202417/6/2026
A vulnerability was found in python-sql where unary operators do not escape non-Expression.
AplazadaAlta (8.8)2.1%—Python-libarchiveAI12/12/202417/6/2026
python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract.
AplazadaBaja (2.7)0.25%—Sigstore-pythonAI10/12/202417/6/2026
sigstore-python is a Python tool for generating and verifying Sigstore signatures. Versions of sigstore-python newer than 2.0.0 but prior to 3.6.0 perform insufficient validation of the "integration time" present in "v2" and "v3" bundles during the verification flow: the "integration time" is verified *if* a source of…
AplazadaAlta (8.7)1.9%—PythonAI6/12/202431/7/2026
Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark". Because of this, Protocols would not periodically drain the write buffer potentially leading to…
AplazadaAlta (7.5)0.64%—Fastapiexpert Python-multipartAI2/12/202417/6/2026
python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks (CR \r or LF \n) in front of the first boundary and any tailing bytes after the last boundary. This happens one byte at a time and emits a log event each time, which may cause excessive logging for…
AnalizadaMedia (6.1)0.48%—Fedoralovespython Lxml Html Clean19/11/202417/6/2026
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, the HTML Parser in lxml does not properly handle context-switching for special HTML tags such as `<svg>`, `<math>` and `<noscript>`. This behavior deviates from how web browsers parse and interpret…
AnalizadaAlta (7.5)0.55%—Timgreen Python Book15/11/202417/6/2026
python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.
AnalizadaCrítica (9.8)0.99%—Timgreen Python Book15/11/202417/6/2026
The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.
AplazadaAlta (7.5)0.47%—Python Food Ordering SystemAI15/11/202417/6/2026
The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access it through https://ip:port/api/myapp/index/user/info?id=1 And modify the ID value to obtain sensitive user information beyond authorization.
AplazadaMedia (5.4)0.15%—Intel Distribution FOR PythonAI13/11/202417/6/2026
Incorrect default permissions in some Intel(R) Distribution for Python software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.3)0.66%—Python UrllibAI12/11/202417/6/2026
The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.
AnalizadaAlta (8.8)1.2%—Microsoft Python12/11/202417/6/2026
Visual Studio Code Python Extension Remote Code Execution Vulnerability
AplazadaCrítica (9.8)17%—Pyload-ngAIPythonAI28/10/202417/6/2026
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.
ModificadaMedia (5.3)0.65%—Python22/10/202417/6/2026
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual…
AnalizadaAlta (8.7)0.72%—Zope Restrictedpython30/9/202417/6/2026
RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will be fixed in version 7.3. As a workaround, If the application does not require…
AnalizadaMedia (6.9)0.99%—Micropython17/9/202417/6/2026
A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch…
AnalizadaMedia (6.3)1.0%—Micropython17/9/202417/6/2026
A vulnerability was found in MicroPython 1.22.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file py/objarray.c. The manipulation leads to use after free. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to…
AnalizadaMedia (6.9)1.0%—Micropython17/9/202417/6/2026
A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umount of the file extmod/vfs.c of the component VFS Unmount Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed…
AplazadaMedia (4.3)0.55%—Openstack IronicAIOpenstack Ironic-python-agentAIQemu-imgAI6/9/202417/6/2026
In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, in which a crafted image could be used by an authenticated user to exploit undesired behaviors in qemu-img, including possible unauthorized access to potentially sensitive data. The affected/fixed…
ModificadaAlta (7.5)2.2%—Python3/9/202417/6/2026
There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
AplazadaAlta (8.7)1.3%—CpythonAI22/8/202417/6/2026
There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the more common API "zipfile.ZipFile" class is unaffected. When iterating over names of entries in a zip archive (for example, methods of "zipfile.Path" like "namelist()", "iterdir()", etc) the process can…
ModificadaAlta (7.5)2.3%—Python19/8/202417/6/2026
There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while…
AplazadaMedia (5.5)1.1%—CpythonAI1/8/202417/6/2026
There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.
AplazadaMedia (5.1)0.25%—CpythonAI29/7/202417/6/2026
The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows. This pure-Python implementation uses AF_INET or AF_INET6 to create a local connected pair of sockets. The connection between the two sockets was not verified before passing…
ModificadaMedia (6.3)0.42%—Oracle Mysql Connector/python16/7/202417/6/2026
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this…