Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Google Protobuf-cppGoogle Protobuf-pythonFedoraproject FedoraDebian Linux22/9/202217/6/2026
A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A…
ModificadaCrítica (9.8)1.7%—D8s-python Project D8s-python19/9/202217/6/2026
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings package. The affected version is 0.1.0.
ModificadaAlta (7.5)7.2%—PythonRedhat QuayRedhat Software CollectionsFedoraproject Fedora+19/9/202217/6/2026
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected).…
ModificadaAlta (7.3)0.36%—Python-poetry Poetry7/9/202217/6/2026
Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes various commands, e.g. `git config`. These commands are being executed using the executable’s name and not its absolute path. This can lead to the execution of untrusted code due to the way Windows…
ModificadaAlta (7.3)1.3%—Python-poetry Poetry7/9/202217/6/2026
Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a registry, Poetry uses various commands, such as `git clone`. These commands are constructed using user input (e.g. the repository URL). When building the commands, Poetry correctly avoids Command…
ModificadaAlta (7.4)0.63%—Python-scciclient Project Python-scciclientDebian Linux1/9/202217/6/2026
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.
ModificadaMedia (5.3)3.2%—PythonDebian LinuxRedhat Software CollectionsRedhat Enterprise Linux+124/8/202217/6/2026
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given…
ModificadaAlta (7.4)2.5%—PythonFedoraproject Fedora23/8/202217/6/2026
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is…
ModificadaAlta (7.8)0.22%—Intel Distribution FOR Python18/8/202217/6/2026
Uncontrolled search path in the Intel(R) Distribution for Python before version 2022.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)1.2%—Codecov-python13/7/202217/6/2026
This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.
ModificadaCrítica (9.3)1.4%—Livro Python Project Livro Python11/7/202217/6/2026
The duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.3)1.3%—Python-flask-restful-api Project Python-flask-restful-api11/7/202217/6/2026
The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.3)1.3%—Python Athena Stack Project Python Athena Stack11/7/202217/6/2026
The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.3)1.3%—Pythonweb Project Pythonweb11/7/202217/6/2026
The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.3)1.3%—Python-recipe-database Project Python-recipe-database11/7/202217/6/2026
The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.3)1.3%—Harveyzyh Python Project Harveyzyh Python11/7/202217/6/2026
The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaMedia (6.5)1.9%—Python-ldap18/6/202217/6/2026
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a…
ModificadaAlta (7.8)1.3%—Python16/6/202217/6/2026
A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the component pgAdmin4. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
ModificadaCrítica (9.8)2.3%—Python Pillow25/5/202217/6/2026
libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
ModificadaCrítica (9.8)2.3%—Python Pypi8/5/202217/6/2026
marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.
ModificadaMedia (4.3)0.54%—Python Tkvideoplayer6/5/202217/6/2026
TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideoplayer prior to 2.0.0 can theoretically lead to performance degradation. There are no known workarounds. This issue has been patched and users are advised to upgrade to version 2.0.0 or later.
ModificadaCrítica (9.8)5.5%—Python-libnmap Project Python-libnmap4/5/202217/6/2026
In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input data that arrived over an untrusted…
ModificadaAlta (7.6)7.1%—PythonNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityNetapp Snapcenter+113/4/202217/6/2026
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or…
ModificadaCrítica (9.1)2.7%—Python PillowFedoraproject Fedora28/3/202217/6/2026
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
ModificadaAlta (7.5)52%—NokogiriPythonZlibDebian Linux+2325/3/202214/7/2026
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.