Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2552▼ 400 respecto a la semana anterior
Críticas / altas1318▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
–

650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)6.6%—Libexpat Project LibexpatPython4/9/201917/6/2026
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
ModificadaAlta (8.8)1.0%—Python Novajoin30/7/201917/6/2026
A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.
ModificadaAlta (8.8)0.85%—Python-engineio Project Python-engineio16/7/201917/6/2026
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.
ModificadaMedia (5.3)3.9%—Python13/7/201917/6/2026
http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has another valid hostname as a suffix (e.g.,…
ModificadaAlta (7.8)1.3%—Python8/7/201917/6/2026
The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position is that it is the user's responsibility to ensure C:\Python27 access control or…
ModificadaCrítica (9.8)8.0%—Bzip2Debian LinuxOpensuse LeapCanonical Ubuntu Linux+219/6/201917/6/2026
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
ModificadaCrítica (9.8)5.2%—PythonRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+107/6/201917/6/2026
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application…
ModificadaAlta (7.5)2.1%—Python Pyxdg6/6/201917/6/2026
A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_CONFIG_DIRS must be set up to trigger xdg.Menu.parse parsing within the directory containing this file. This is due to a lack of sanitization in xdg/Menu.py before an…
RechazadaSin puntuar——PythonAI3/6/20197/11/2023
Rejected reason: Various versions of Python do not properly restrict readline calls, which allows remote attackers to cause a denial of service (memory consumption) via a long string, related to (1) httplib - fixed in 2.7.4, 2.6.9, and 3.3.3; (2) ftplib - fixed in 2.7.6, 2.6.9, 3.3.3; (3) imaplib - not yet fixed in…
ModificadaAlta (8.8)1.8%—Python-dbusmock Project Python-dbusmock22/4/201917/6/2026
python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method could be tricked into executing malicious code if an attacker supplies a .pyc file.
ModificadaAlta (7.5)2.8%—Python Urllib3Canonical Ubuntu Linux18/4/201917/6/2026
The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context,…
ModificadaCrítica (9.8)4.7%—Onelogin Pythonsaml17/4/201917/6/2026
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service…
ModificadaMedia (6.1)2.1%—Python Urllib315/4/201917/6/2026
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
ModificadaCrítica (9.1)12%—PythonOpensuse LeapDebian LinuxFedoraproject Fedora+723/3/201917/6/2026
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.
ModificadaMedia (6.1)5.3%—Python23/3/201917/6/2026
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the path component of a URL that lacks a ? character)…
ModificadaAlta (7.5)8.5%—Python-gnupgDebian LinuxOpensuse LeapSuse Backports+121/3/201917/6/2026
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect…
ModificadaMedia (6.1)5.4%—Python13/3/201917/6/2026
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the query string after a ? character) followed by an…
ModificadaCrítica (9.8)8.8%—PythonFedoraproject FedoraOpensuse LeapDebian Linux+128/3/201917/6/2026
Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit,…
ModificadaCrítica (9.1)1.7%—Yingzhipython Project Yingzhipython15/2/201916/6/2026
Vulnerability in YingZhi Python Programming Language v1.9 allows arbitrary anonymous uploads to the phone's storage
ModificadaMedia (6.1)3.8%—Python Pypiserver25/1/201917/6/2026
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.
ModificadaAlta (7.5)5.8%—PythonDebian LinuxFedoraproject Fedora23/12/201817/6/2026
Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during a "resize to twice the size" attempt. This issue might cause memory exhaustion, but is only relevant if the pickle format is used for serializing tens or hundreds of gigabytes of data. This issue is…
ModificadaCrítica (9.8)4.5%—Python Urllib3Fedoraproject Fedora11/12/201817/6/2026
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
ModificadaAlta (7.5)7.4%—Python RequestsCanonical Ubuntu LinuxOpensuse LeapRedhat Enterprise Linux Desktop+29/10/201817/6/2026
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
ModificadaAlta (7.5)11%—PythonCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+425/9/201817/6/2026
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and…
ModificadaCrítica (9.8)20%—PythonCanonical Ubuntu LinuxDebian LinuxOpensuse Leap18/9/201817/6/2026
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or…