Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Google Protobuf-cppGoogle Protobuf-pythonFedoraproject FedoraDebian Linux | 22/9/2022 | 17/6/2026 | A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A… | |
| Modificada | Crítica (9.8) | 1.7% | — | D8s-python Project D8s-python | 19/9/2022 | 17/6/2026 | The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings package. The affected version is 0.1.0. | |
| Modificada | Alta (7.5) | 7.2% | — | PythonRedhat QuayRedhat Software CollectionsFedoraproject Fedora+1 | 9/9/2022 | 17/6/2026 | A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected).… | |
| Modificada | Alta (7.3) | 0.36% | — | Python-poetry Poetry | 7/9/2022 | 17/6/2026 | Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes various commands, e.g. `git config`. These commands are being executed using the executable’s name and not its absolute path. This can lead to the execution of untrusted code due to the way Windows… | |
| Modificada | Alta (7.3) | 1.3% | — | Python-poetry Poetry | 7/9/2022 | 17/6/2026 | Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a registry, Poetry uses various commands, such as `git clone`. These commands are constructed using user input (e.g. the repository URL). When building the commands, Poetry correctly avoids Command… | |
| Modificada | Alta (7.4) | 0.63% | — | Python-scciclient Project Python-scciclientDebian Linux | 1/9/2022 | 17/6/2026 | A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks. | |
| Modificada | Media (5.3) | 3.2% | — | PythonDebian LinuxRedhat Software CollectionsRedhat Enterprise Linux+1 | 24/8/2022 | 17/6/2026 | A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given… | |
| Modificada | Alta (7.4) | 2.5% | — | PythonFedoraproject Fedora | 23/8/2022 | 17/6/2026 | Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is… | |
| Modificada | Alta (7.8) | 0.22% | — | Intel Distribution FOR Python | 18/8/2022 | 17/6/2026 | Uncontrolled search path in the Intel(R) Distribution for Python before version 2022.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 1.2% | — | Codecov-python | 13/7/2022 | 17/6/2026 | This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method. | |
| Modificada | Crítica (9.3) | 1.4% | — | Livro Python Project Livro Python | 11/7/2022 | 17/6/2026 | The duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.3) | 1.3% | — | Python-flask-restful-api Project Python-flask-restful-api | 11/7/2022 | 17/6/2026 | The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.3) | 1.3% | — | Python Athena Stack Project Python Athena Stack | 11/7/2022 | 17/6/2026 | The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.3) | 1.3% | — | Pythonweb Project Pythonweb | 11/7/2022 | 17/6/2026 | The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.3) | 1.3% | — | Python-recipe-database Project Python-recipe-database | 11/7/2022 | 17/6/2026 | The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.3) | 1.3% | — | Harveyzyh Python Project Harveyzyh Python | 11/7/2022 | 17/6/2026 | The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (6.5) | 1.9% | — | Python-ldap | 18/6/2022 | 17/6/2026 | python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a… | |
| Modificada | Alta (7.8) | 1.3% | — | Python | 16/6/2022 | 17/6/2026 | A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the component pgAdmin4. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Crítica (9.8) | 2.3% | — | Python Pillow | 25/5/2022 | 17/6/2026 | libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files. | |
| Modificada | Crítica (9.8) | 2.3% | — | Python Pypi | 8/5/2022 | 17/6/2026 | marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor. | |
| Modificada | Media (4.3) | 0.54% | — | Python Tkvideoplayer | 6/5/2022 | 17/6/2026 | TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideoplayer prior to 2.0.0 can theoretically lead to performance degradation. There are no known workarounds. This issue has been patched and users are advised to upgrade to version 2.0.0 or later. | |
| Modificada | Crítica (9.8) | 5.5% | — | Python-libnmap Project Python-libnmap | 4/5/2022 | 17/6/2026 | In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input data that arrived over an untrusted… | |
| Modificada | Alta (7.6) | 7.1% | — | PythonNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityNetapp Snapcenter+1 | 13/4/2022 | 17/6/2026 | In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or… | |
| Modificada | Crítica (9.1) | 2.7% | — | Python PillowFedoraproject Fedora | 28/3/2022 | 17/6/2026 | Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled. | |
| Modificada | Alta (7.5) | 52% | — | NokogiriPythonZlibDebian Linux+23 | 25/3/2022 | 14/7/2026 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. |