Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.2) | 0.24% | — | Jaraco ZippAICpythonAI | 9/7/2024 | 17/6/2026 | A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when processing a specially crafted zip file that leads to an infinite loop. This issue also impacts the zipfile module of CPython, as features from the third-party zipp… | |
| Aplazada | Media (6.5) | 0.74% | — | CpythonAIOpensslAI | 27/6/2024 | 31/7/2026 | CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see CVE-2024-5535 for OpenSSL). This vulnerability is of low severity due to NPN being not widely… | |
| Analizada | Media (6.5) | 1.1% | — | Python Urllib3Debian LinuxNetapp Active IQ Unified Manager | 17/6/2024 | 17/6/2026 | urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured proxy, as expected. However, when sending HTTP requests *without* using urllib3's proxy support, it's possible to accidentally configure the… | |
| Aplazada | Alta (7.4) | 0.81% | — | CpythonAI | 17/6/2024 | 17/6/2026 | A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS… | |
| Aplazada | Alta (7.5) | 1.1% | — | CpythonAI | 17/6/2024 | 17/6/2026 | The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes,… | |
| Aplazada | Crítica (9.6) | 26% | — | Llama-cpp-pythonAIPocoo Jinja2AI | 14/5/2024 | 17/6/2026 | llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA,… | |
| Aplazada | Alta (7.1) | 0.30% | — | PythonAI | 7/5/2024 | 17/6/2026 | On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users, instead usually inheriting the correct permissions from the default location. Alternate configurations or users without a profile directory may not have… | |
| Aplazada | Alta (7.8) | 1.2% | — | Amazon Sagemaker-python-sdkAI | 3/5/2024 | 17/6/2026 | sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. In affected versions the capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils` module allows for potentially unsafe Operating System (OS) Command Injection if inappropriate… | |
| Aplazada | Alta (7.8) | 0.41% | — | Amazon Sagemaker-python-sdkAI | 3/5/2024 | 17/6/2026 | sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. The sagemaker.base_deserializers.NumpyDeserializer module before v2.218.0 allows potentially unsafe deserialization when untrusted data is passed as pickled object arrays. This consequently may allow an… | |
| Analizada | Media (5.3) | 0.78% | — | Python-jose Project Python-jose | 26/4/2024 | 17/6/2026 | python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319. | |
| Analizada | Media (6.5) | 0.31% | — | Python-jose Project Python-jose | 26/4/2024 | 17/6/2026 | python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217. | |
| Aplazada | Media (4.9) | 0.58% | — | Python Social AuthAIMysqlAIMariadbAI | 24/4/2024 | 17/6/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match. This issue has been addressed by a fix released in… | |
| Analizada | Alta (7.5) | 0.72% | — | Oracle Mysql Connector/python | 16/4/2024 | 17/6/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 8.3.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this… | |
| Modificada | Alta (7) | 1.9% | — | EventletDnspythonFedoraproject FedoraNetapp Bootstrap OS | 11/4/2024 | 17/6/2026 | eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name… | |
| Modificada | Media (5.9) | 1.00% | — | Python PillowDebian Linux | 3/4/2024 | 17/6/2026 | In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy. | |
| Aplazada | Media (6.2) | 0.34% | — | CpythonAI | 19/3/2024 | 17/6/2026 | An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile… | |
| Aplazada | Alta (7.8) | 0.31% | — | CpythonAI | 19/3/2024 | 17/6/2026 | An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are… | |
| Aplazada | Media (5.3) | 0.98% | — | Python BlackAI | 19/3/2024 | 17/6/2026 | Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file. An attacker could exploit this vulnerability by crafting a malicious input that causes a denial of service. Exploiting this vulnerability… | |
| Analizada | Media (5.4) | 0.62% | — | Felixschwarz Mjml-python | 22/2/2024 | 17/6/2026 | The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a markup language created by Mailjet. All users of `FelixSchwarz/mjml-python` who insert untrusted data into mjml templates unless that data is checked in a very strict manner. User input like… | |
| Analizada | Alta (7.8) | 0.16% | — | Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+12 | 14/2/2024 | 17/6/2026 | Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6) | 0.17% | — | Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+12 | 14/2/2024 | 17/6/2026 | Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.5) | 1.5% | — | Fastapiexpert Python-multipart | 5/2/2024 | 17/6/2026 | `python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. An attacker could send a custom-made `Content-Type` option that is very difficult for the RegEx to process, consuming CPU… | |
| Modificada | Alta (8.1) | 1.7% | — | Python PillowDebian Linux | 19/1/2024 | 17/6/2026 | Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter). | |
| Modificada | Baja (2.8) | 0.41% | — | Lfprojects Case Python UtilitiesLfprojects CDO Local Uuid Utility | 11/1/2024 | 17/6/2026 | cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present in `cdo-local-uuid` at version `0.4.0`, and in `case-utils` in unpatched versions (matching the pattern `0.x.0`) at and… | |
| Modificada | Alta (7.8) | 0.32% | — | Gitpython Project Gitpython | 11/1/2024 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious… |