Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.37% | — | Python | 7/6/2023 | 17/6/2026 | CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c. | |
| Modificada | Media (6.1) | 3.0% | — | Python RequestsFedoraproject Fedora | 26/5/2023 | 17/6/2026 | Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rebuild_proxies` to reattach the `Proxy-Authorization` header to requests. For HTTP connections sent through the tunnel,… | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.3) | 2.5% | — | Fedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityPython | 19/4/2023 | 17/6/2026 | The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after… | |
| Modificada | Crítica (9.8) | 0.78% | — | Wechat SDK Python Project Wechat SDK Python | 21/3/2023 | 17/6/2026 | A vulnerability was found in zwczou WeChat SDK Python 0.3.0 and classified as critical. This issue affects the function validate/to_xml. The manipulation leads to xml external entity reference. The attack may be initiated remotely. Upgrading to version 0.5.5 is able to address this issue. The patch is named… | |
| Modificada | Crítica (9.8) | 1.2% | — | Hour OF Code Python 2015 Project Hour OF Code Python 2015 | 22/2/2023 | 17/6/2026 | hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code. | |
| Modificada | Alta (7.5) | 20% | — | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+2 | 17/2/2023 | 17/6/2026 | An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters. | |
| Modificada | Alta (7.3) | 0.18% | — | Intel Distribution FOR Python | 16/2/2023 | 17/6/2026 | Uncontrolled search path element in the Intel(R) Distribution for Python programming language before version 2022.1 for Intel(R) oneAPI Toolkits may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7) | 1.3% | — | Ipython | 10/2/2023 | 17/6/2026 | IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Versions prior to 8.1.0 are subject to a command injection vulnerability with very specific prerequisites. This vulnerability requires that the function… | |
| Modificada | Media (5.3) | 0.56% | — | Includesecurity Safeurl-python | 30/1/2023 | 17/6/2026 | isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF. | |
| Modificada | Alta (7.5) | 1.9% | — | Pythoncharmers Python-future | 23/12/2022 | 17/6/2026 | An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server. | |
| Modificada | Media (5.9) | 2.5% | — | Python Setuptools | 23/12/2022 | 17/6/2026 | Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py. | |
| Modificada | Crítica (9.8) | 1.5% | — | Python3-restfulapi Project Python3-restfulapi | 14/12/2022 | 17/6/2026 | Python3-RESTfulAPI commit d9907f14e9e25dcdb54f5b22252b0e9452e3970e and e772e0beee284c50946e94c54a1d43071ca78b74 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 5.7% | — | Gitpython Project GitpythonFedoraproject FedoraDebian Linux | 6/12/2022 | 17/6/2026 | All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient… | |
| Modificada | Media (6.3) | 3.1% | — | Snyk CLISnyk Cocoapods CLISnyk Docker CLISnyk Gradle CLI+4 | 30/11/2022 | 17/6/2026 | The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin before 1.24.2; the package snyk-docker-plugin before 5.6.5; the… | |
| Modificada | Media (4.3) | 0.38% | — | Chocolatey Python3 | 29/11/2022 | 17/6/2026 | Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\Python311 and all files located in that folder. | |
| Modificada | Alta (7.5) | 1.2% | — | Python Pillow | 14/11/2022 | 17/6/2026 | Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL. | |
| Modificada | Alta (7.5) | 1.3% | — | Python Pillow | 14/11/2022 | 17/6/2026 | Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification). | |
| Analizada | Alta (7.5) | 0.95% | — | Python-poetry Cleo | 9/11/2022 | 17/6/2026 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method | |
| Modificada | Alta (7.5) | 2.7% | — | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+5 | 9/11/2022 | 17/6/2026 | An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote… | |
| Modificada | Crítica (9.8) | 1.1% | — | Democritus D8s-python | 7/11/2022 | 17/6/2026 | The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-grammars package. The affected version of d8s-htm is 0.1.0. | |
| Modificada | Crítica (9.8) | 1.1% | — | Democritus D8s-python | 7/11/2022 | 17/6/2026 | The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-algorithms package. The affected version of d8s-htm is 0.1.0. | |
| Modificada | Alta (7.8) | 0.75% | — | PythonFedoraproject Fedora | 7/11/2022 | 17/6/2026 | Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized from any user in the same machine local network namespace, which in… | |
| Modificada | Crítica (9.8) | 5.8% | — | Extended Keccak Code Package Project Extended Keccak Code PackageDebian LinuxFedoraproject FedoraPHP+4 | 21/10/2022 | 17/6/2026 | The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface. | |
| Modificada | Crítica (9.1) | 5.3% | — | Python-jwt Project Python-jwt | 23/9/2022 | 17/6/2026 | python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key.… |