Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.37%—Python7/6/202317/6/2026
CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c.
ModificadaMedia (6.1)3.0%—Python RequestsFedoraproject Fedora26/5/202317/6/2026
Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rebuild_proxies` to reattach the `Proxy-Authorization` header to requests. For HTTP connections sent through the tunnel,…
ModificadaAlta (7.8)0.21%—Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+2510/5/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.3)2.5%—Fedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityPython19/4/202317/6/2026
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after…
ModificadaCrítica (9.8)0.78%—Wechat SDK Python Project Wechat SDK Python21/3/202317/6/2026
A vulnerability was found in zwczou WeChat SDK Python 0.3.0 and classified as critical. This issue affects the function validate/to_xml. The manipulation leads to xml external entity reference. The attack may be initiated remotely. Upgrading to version 0.5.5 is able to address this issue. The patch is named…
ModificadaCrítica (9.8)1.2%—Hour OF Code Python 2015 Project Hour OF Code Python 201522/2/202317/6/2026
hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.
ModificadaAlta (7.5)20%—PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+217/2/202317/6/2026
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
ModificadaAlta (7.3)0.18%—Intel Distribution FOR Python16/2/202317/6/2026
Uncontrolled search path element in the Intel(R) Distribution for Python programming language before version 2022.1 for Intel(R) oneAPI Toolkits may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7)1.3%—Ipython10/2/202317/6/2026
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Versions prior to 8.1.0 are subject to a command injection vulnerability with very specific prerequisites. This vulnerability requires that the function…
ModificadaMedia (5.3)0.56%—Includesecurity Safeurl-python30/1/202317/6/2026
isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF.
ModificadaAlta (7.5)1.9%—Pythoncharmers Python-future23/12/202217/6/2026
An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.
ModificadaMedia (5.9)2.5%—Python Setuptools23/12/202217/6/2026
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
ModificadaCrítica (9.8)1.5%—Python3-restfulapi Project Python3-restfulapi14/12/202217/6/2026
Python3-RESTfulAPI commit d9907f14e9e25dcdb54f5b22252b0e9452e3970e and e772e0beee284c50946e94c54a1d43071ca78b74 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)5.7%—Gitpython Project GitpythonFedoraproject FedoraDebian Linux6/12/202217/6/2026
All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient…
ModificadaMedia (6.3)3.1%—Snyk CLISnyk Cocoapods CLISnyk Docker CLISnyk Gradle CLI+430/11/202217/6/2026
The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin before 1.24.2; the package snyk-docker-plugin before 5.6.5; the…
ModificadaMedia (4.3)0.38%—Chocolatey Python329/11/202217/6/2026
Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\Python311 and all files located in that folder.
ModificadaAlta (7.5)1.2%—Python Pillow14/11/202217/6/2026
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
ModificadaAlta (7.5)1.3%—Python Pillow14/11/202217/6/2026
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
AnalizadaAlta (7.5)0.95%—Python-poetry Cleo9/11/202217/6/2026
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method
ModificadaAlta (7.5)2.7%—PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+59/11/202217/6/2026
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote…
ModificadaCrítica (9.8)1.1%—Democritus D8s-python7/11/202217/6/2026
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-grammars package. The affected version of d8s-htm is 0.1.0.
ModificadaCrítica (9.8)1.1%—Democritus D8s-python7/11/202217/6/2026
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-algorithms package. The affected version of d8s-htm is 0.1.0.
ModificadaAlta (7.8)0.75%—PythonFedoraproject Fedora7/11/202217/6/2026
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized from any user in the same machine local network namespace, which in…
ModificadaCrítica (9.8)5.8%—Extended Keccak Code Package Project Extended Keccak Code PackageDebian LinuxFedoraproject FedoraPHP+421/10/202217/6/2026
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
ModificadaCrítica (9.1)5.3%—Python-jwt Project Python-jwt23/9/202217/6/2026
python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key.…