Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Python-poetry Poetry | 21/3/2022 | 17/6/2026 | Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS. | |
| Modificada | Alta (7) | 1.4% | — | PythonNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility | 10/3/2022 | 17/6/2026 | In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have installed Python for all users and enabled PATH entries. A… | |
| Modificada | Media (6.5) | 4.7% | — | PythonRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+16 | 10/3/2022 | 17/6/2026 | There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to… | |
| Modificada | Alta (7.5) | 12% | — | PythonRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+13 | 4/3/2022 | 17/6/2026 | A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability. | |
| Modificada | Media (4.7) | 0.22% | — | Backblaze B2 Python Software Development KIT | 23/2/2022 | 17/6/2026 | b2-sdk-python is a python library to access cloud storage provided by backblaze. Linux and Mac releases of the SDK version 1.14.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. SDK users of… | |
| Modificada | Alta (7.5) | 8.3% | — | PythonNetapp Active IQ Unified ManagerNetapp HCINetapp Management Services FOR Element Software+6 | 9/2/2022 | 17/6/2026 | A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a… | |
| Modificada | Alta (8.8) | 0.65% | — | IpythonDebian LinuxFedoraproject Fedora | 19/1/2022 | 17/6/2026 | IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This… | |
| Modificada | Crítica (9.8) | 3.3% | — | Python PillowDebian Linux | 10/1/2022 | 17/6/2026 | PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used. | |
| Modificada | Media (6.5) | 1.9% | — | Python PillowDebian Linux | 10/1/2022 | 17/6/2026 | path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path. | |
| Modificada | Media (6.5) | 2.6% | — | Python PillowDebian Linux | 10/1/2022 | 17/6/2026 | path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path. | |
| Modificada | Crítica (9.8) | 1.2% | — | Starkbank Ecdsa-python | 9/11/2021 | 17/6/2026 | The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. | |
| Modificada | Media (4.3) | 0.76% | — | Pythondiscord BOT | 5/11/2021 | 17/6/2026 | Python discord bot is the community bot for the Python Discord community. In affected versions when a non-blacklisted URL and an otherwise triggering filter token is included in the same message the token filter does not trigger. This means that by including any non-blacklisted URL moderation filters can be bypassed.… | |
| Modificada | Crítica (9.8) | 1.6% | — | Microco BluemondayPython Pybluemonday | 18/10/2021 | 17/6/2026 | The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements. | |
| Modificada | Alta (7.5) | 3.2% | — | Python PillowFedoraproject Fedora | 3/9/2021 | 17/6/2026 | The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function. | |
| Modificada | Crítica (9.8) | 3.2% | — | Python PillowDebian LinuxFedoraproject Fedora | 13/7/2021 | 17/6/2026 | Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c. | |
| Modificada | Alta (7.5) | 3.3% | — | Python Urllib3Fedoraproject FedoraOracle Enterprise Manager OPS CenterOracle Instantis Enterprisetrack+1 | 29/6/2021 | 17/6/2026 | An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect. | |
| Modificada | Alta (7.8) | 0.34% | — | Opensuse Python-postorius | 10/6/2021 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from users postorius or postorius-admin to root. This issue affects: openSUSE Leap 15.2 python-postorius version 1.3.2-lp152.1.2 and prior versions. openSUSE Factory… | |
| Modificada | Alta (7.8) | 0.44% | — | Python-hyperkitty Project Python-hyperkitty | 10/6/2021 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, Factory allows local attackers to escalate privileges from the user hyperkitty or hyperkitty-admin to root. This issue affects: openSUSE Leap 15.2 python-HyperKitty version 1.3.2-lp152.2.3.1 and prior versions. openSUSE… | |
| Modificada | Media (5.5) | 0.73% | — | Python PillowFedoraproject Fedora | 2/6/2021 | 17/6/2026 | An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder could be run a large number of times on empty data. | |
| Modificada | Alta (7.5) | 2.3% | — | Python PillowFedoraproject Fedora | 2/6/2021 | 17/6/2026 | An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a… | |
| Modificada | Alta (7.5) | 2.5% | — | Python PillowFedoraproject Fedora | 2/6/2021 | 17/6/2026 | An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load. | |
| Modificada | Crítica (9.1) | 2.4% | — | Python PillowFedoraproject Fedora | 2/6/2021 | 17/6/2026 | An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i. | |
| Modificada | Crítica (9.1) | 2.9% | — | Python PillowFedoraproject Fedora | 2/6/2021 | 17/6/2026 | An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la. | |
| Modificada | Media (5.5) | 0.96% | — | Python PillowFedoraproject Fedora | 2/6/2021 | 17/6/2026 | An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lacked a sanity check on the number of input layers relative to the size of the data block. This could lead to a DoS on Image.open prior to Image.load. | |
| Modificada | Media (5.7) | 1.9% | — | PythonFedoraproject FedoraDebian LinuxRedhat Software Collections+6 | 20/5/2021 | 17/6/2026 | There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk… |