Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2541▼ 354 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)6.9%—PythonOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Slice Selection Function+26/5/202117/6/2026
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
ModificadaAlta (7.5)1.6%—Python Pillow19/3/202117/6/2026
An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.
ModificadaMedia (6.5)1.6%—Python Pillow19/3/202117/6/2026
An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.
ModificadaAlta (7.5)1.4%—Python Pillow19/3/202117/6/2026
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.
ModificadaAlta (7.5)2.4%—Python PillowDebian Linux19/3/202117/6/2026
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
ModificadaCrítica (9.8)2.3%—Python Pillow19/3/202117/6/2026
An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.
ModificadaMedia (6.5)2.1%—Python Urllib3Fedoraproject FedoraOracle Peoplesoft Enterprise Peopletools15/3/202117/6/2026
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers…
ModificadaAlta (7.5)3.0%—Python PillowFedoraproject Fedora3/3/202117/6/2026
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
ModificadaAlta (7.5)4.9%—Python PillowFedoraproject Fedora3/3/202117/6/2026
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
ModificadaAlta (7.5)3.2%—Python PillowFedoraproject Fedora3/3/202117/6/2026
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
ModificadaMedia (5.9)41%—PythonFedoraproject FedoraDebian LinuxNetapp Cloud Backup+815/2/202117/6/2026
The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query…
ModificadaCrítica (9.8)23%—PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+619/1/202117/6/2026
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.
ModificadaMedia (5.4)1.6%—Python PillowFedoraproject Fedora12/1/202117/6/2026
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.
ModificadaAlta (8.8)1.8%—Python PillowFedoraproject Fedora12/1/202117/6/2026
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
ModificadaAlta (7.1)1.6%—Python PillowFedoraproject FedoraDebian Linux12/1/202117/6/2026
In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.
ModificadaMedia (6.8)0.83%—Python Openid Connect Project Python Openid Connect2/12/202017/6/2026
Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The issues are: 1) The IdToken signature algorithm was not checked automatically, but only if the expected algorithm was passed…
ModificadaMedia (5.9)1.7%—Python-rsa Project Python-rsaRedhat Openstack PlatformFedoraproject Fedora12/11/202017/6/2026
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.
ModificadaAlta (7.5)1.1%—Synopsys Hub-rest-api-python6/11/202017/6/2026
Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.
ModificadaCrítica (9.8)8.3%—PythonFedoraproject FedoraOracle Communications Cloud Native Core Network Function Cloud Native Environment22/10/202017/6/2026
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
ModificadaMedia (6.5)2.3%—Python Urllib3Canonical Ubuntu LinuxDebian LinuxOracle Communications Cloud Native Core Network Function Cloud Native Environment+130/9/202017/6/2026
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
ModificadaAlta (7.2)6.4%—PythonFedoraproject FedoraCanonical Ubuntu LinuxNetapp Solidfire+427/9/202017/6/2026
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
ModificadaCrítica (9.8)2.5%—Sqreen Python Mini Racer17/9/202017/6/2026
A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploit heap corruption.
ModificadaCrítica (9)1.8%—Openapi-python-client Project Openapi-python-client14/8/202017/6/2026
In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution.
ModificadaMedia (4.1)1.1%—Openapi-python-client Project Openapi-python-client14/8/202017/6/2026
In openapi-python-client before version 0.5.3, there is a path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.
ModificadaCrítica (9.8)3.5%—PythonNetapp MAX Data17/7/202017/6/2026
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected.