Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2573▼ 324 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 435 respecto a la semana anterior
–

650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)6.3%—PythonOpensuse LeapDebian LinuxFedoraproject Fedora+413/7/202017/6/2026
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
ModificadaAlta (7.8)0.92%—PythonNetapp Snapcenter4/7/202017/6/2026
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for python3.dll loading (after Py_SetPath has…
ModificadaAlta (8.1)2.5%—Python PillowFedoraproject FedoraCanonical Ubuntu Linux25/6/202017/6/2026
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
ModificadaMedia (5.5)1.4%—Python PillowFedoraproject FedoraCanonical Ubuntu Linux25/6/202017/6/2026
In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.
ModificadaAlta (7.8)1.1%—Python PillowFedoraproject FedoraCanonical Ubuntu Linux25/6/202017/6/2026
In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.
ModificadaMedia (5.5)1.1%—Python PillowFedoraproject FedoraCanonical Ubuntu Linux25/6/202017/6/2026
In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.
ModificadaMedia (5.5)1.5%—Python PillowDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux25/6/202017/6/2026
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
ModificadaMedia (5.9)13%—PythonOpensuse LeapFedoraproject FedoraOracle Enterprise Manager OPS Center18/6/202017/6/2026
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker…
ModificadaAlta (7.5)1.4%—Python-rsa Project Python-rsaFedoraproject FedoraCanonical Ubuntu Linux1/6/202017/6/2026
Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory…
ModificadaCrítica (9.8)4.4%—Python Jw.util22/5/202017/6/2026
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resulting in OS command execution, because safe_load is not used.
ModificadaAlta (7.8)4.1%—Microsoft Python21/5/202019/8/2026
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings from a notebook file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user…
ModificadaAlta (8.8)5.0%—Microsoft Python21/5/202019/8/2026
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads configuration files after opening a project. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user…
ModificadaMedia (6.1)2.1%—Contentful Python Example21/5/202017/6/2026
Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.py.
ModificadaAlta (7.8)0.54%—Autoswitch Python Virtualenv Project Autoswitch Python Virtualenv13/5/202017/6/2026
In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0
ModificadaMedia (6.1)1.9%—Python-markdown2 Project Python-markdown220/4/202017/6/2026
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
ModificadaMedia (4.7)0.51%—Ubuntu Python-aptDebian Python-apt26/3/202017/6/2026
Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py or in `_fetch_archives()` of apt/cache.py in version 1.9.3ubuntu2 and earlier. This allows downloads from unsigned repositories which shouldn't be allowed and has been fixed in verisions 1.9.5,…
ModificadaMedia (4.7)0.45%—Ubuntu Python-aptDebian Python-apt26/3/202017/6/2026
python-apt only checks the MD5 sums of downloaded files in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py in version 1.9.0ubuntu1 and earlier. This allows a man-in-the-middle attack which could potentially be used to install altered packages and has been fixed in versions 1.9.0ubuntu1.2,…
ModificadaAlta (7.5)3.6%—Python11/3/202016/6/2026
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
ModificadaAlta (7.5)3.4%—Python Urllib36/3/202017/6/2026
The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of…
ModificadaCrítica (9.8)25%—PythonRedhat Software CollectionsRedhat Enterprise Linux20/2/202017/6/2026
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f…
ModificadaAlta (8.8)1.7%—Python-mode Project Python-mode12/2/202016/6/2026
A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.
AnalizadaAlta (7.5)5.5%—PythonCanonical Ubuntu LinuxNetapp Active IQ Unified Manager4/2/202017/6/2026
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
ModificadaMedia (6.5)6.6%—PythonOpensuse LeapCanonical Ubuntu LinuxFedoraproject Fedora+130/1/202017/6/2026
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
ModificadaMedia (5.5)1.5%—Python28/1/202017/6/2026
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's copy. Windows 8 and later are unaffected.
ModificadaAlta (7.5)2.8%—Python Py-bcryptFedoraproject Fedora28/1/202016/6/2026
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.