Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 354 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 6.9% | — | PythonOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Slice Selection Function+2 | 6/5/2021 | 17/6/2026 | In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses. | |
| Modificada | Alta (7.5) | 1.6% | — | Python Pillow | 19/3/2021 | 17/6/2026 | An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c. | |
| Modificada | Media (6.5) | 1.6% | — | Python Pillow | 19/3/2021 | 17/6/2026 | An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex. | |
| Modificada | Alta (7.5) | 1.4% | — | Python Pillow | 19/3/2021 | 17/6/2026 | An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries. | |
| Modificada | Alta (7.5) | 2.4% | — | Python PillowDebian Linux | 19/3/2021 | 17/6/2026 | An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size. | |
| Modificada | Crítica (9.8) | 2.3% | — | Python Pillow | 19/3/2021 | 17/6/2026 | An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654. | |
| Modificada | Media (6.5) | 2.1% | — | Python Urllib3Fedoraproject FedoraOracle Peoplesoft Enterprise Peopletools | 15/3/2021 | 17/6/2026 | The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers… | |
| Modificada | Alta (7.5) | 3.0% | — | Python PillowFedoraproject Fedora | 3/3/2021 | 17/6/2026 | Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large. | |
| Modificada | Alta (7.5) | 4.9% | — | Python PillowFedoraproject Fedora | 3/3/2021 | 17/6/2026 | Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large. | |
| Modificada | Alta (7.5) | 3.2% | — | Python PillowFedoraproject Fedora | 3/3/2021 | 17/6/2026 | Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large. | |
| Modificada | Media (5.9) | 41% | — | PythonFedoraproject FedoraDebian LinuxNetapp Cloud Backup+8 | 15/2/2021 | 17/6/2026 | The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query… | |
| Modificada | Crítica (9.8) | 23% | — | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+6 | 19/1/2021 | 17/6/2026 | Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely. | |
| Modificada | Media (5.4) | 1.6% | — | Python PillowFedoraproject Fedora | 12/1/2021 | 17/6/2026 | In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled. | |
| Modificada | Alta (8.8) | 1.8% | — | Python PillowFedoraproject Fedora | 12/1/2021 | 17/6/2026 | In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. | |
| Modificada | Alta (7.1) | 1.6% | — | Python PillowFedoraproject FedoraDebian Linux | 12/1/2021 | 17/6/2026 | In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations. | |
| Modificada | Media (6.8) | 0.83% | — | Python Openid Connect Project Python Openid Connect | 2/12/2020 | 17/6/2026 | Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The issues are: 1) The IdToken signature algorithm was not checked automatically, but only if the expected algorithm was passed… | |
| Modificada | Media (5.9) | 1.7% | — | Python-rsa Project Python-rsaRedhat Openstack PlatformFedoraproject Fedora | 12/11/2020 | 17/6/2026 | It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. | |
| Modificada | Alta (7.5) | 1.1% | — | Synopsys Hub-rest-api-python | 6/11/2020 | 17/6/2026 | Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases. | |
| Modificada | Crítica (9.8) | 8.3% | — | PythonFedoraproject FedoraOracle Communications Cloud Native Core Network Function Cloud Native Environment | 22/10/2020 | 17/6/2026 | In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP. | |
| Modificada | Media (6.5) | 2.3% | — | Python Urllib3Canonical Ubuntu LinuxDebian LinuxOracle Communications Cloud Native Core Network Function Cloud Native Environment+1 | 30/9/2020 | 17/6/2026 | urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116. | |
| Modificada | Alta (7.2) | 6.4% | — | PythonFedoraproject FedoraCanonical Ubuntu LinuxNetapp Solidfire+4 | 27/9/2020 | 17/6/2026 | http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request. | |
| Modificada | Crítica (9.8) | 2.5% | — | Sqreen Python Mini Racer | 17/9/2020 | 17/6/2026 | A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploit heap corruption. | |
| Modificada | Crítica (9) | 1.8% | — | Openapi-python-client Project Openapi-python-client | 14/8/2020 | 17/6/2026 | In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution. | |
| Modificada | Media (4.1) | 1.1% | — | Openapi-python-client Project Openapi-python-client | 14/8/2020 | 17/6/2026 | In openapi-python-client before version 0.5.3, there is a path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk. | |
| Modificada | Crítica (9.8) | 3.5% | — | PythonNetapp MAX Data | 17/7/2020 | 17/6/2026 | In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected. |