Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
–

650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.28%—Intel Distribution FOR Python12/9/201817/6/2026
Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user to escalate privileges via local access.
ModificadaAlta (7.8)0.32%—Intel Distribution FOR Python1/8/201817/6/2026
Insufficient Input Validation in Bleach module in INTEL Distribution for Python versions prior to IDP 2018 Update 2 allows unprivileged user to bypass URI sanitization via local vector.
ModificadaAlta (7.5)3.2%—Python-cryptographyRedhat OpenstackCanonical Ubuntu Linux30/7/201817/6/2026
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they…
ModificadaAlta (7.5)4.9%—PythonDebian LinuxRedhat Ansible TowerRedhat Enterprise Linux Desktop+419/6/201817/6/2026
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.
ModificadaAlta (7.5)5.0%—PythonFedoraproject FedoraCanonical Ubuntu LinuxRedhat Ansible Tower+418/6/201817/6/2026
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
ModificadaCrítica (9.8)5.5%—Mozilla FirefoxDebian LinuxPython11/6/201817/6/2026
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
ModificadaCrítica (9.8)6.2%—Python-eve EVE14/3/201817/6/2026
io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.
ModificadaMedia (6.7)1.0%—Python7/3/201817/6/2026
Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an…
ModificadaMedia (6.5)1.3%—Python1/3/201817/6/2026
The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because Python applications "need to be…
ModificadaBaja (3.6)1.2%—PythonCanonical Ubuntu Linux8/2/201817/6/2026
Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be vulnerable however this has not been confirmed. The vulnerability lies when multiply threads are handling large amounts…
ModificadaMedia (6.1)0.82%—Python-markdown2 Project Python-markdown218/1/201817/6/2026
An issue was discovered in markdown2 (aka python-markdown2) through 2.3.5. The safe_mode feature, which is supposed to sanitize user input against XSS, is flawed and does not escape the input properly. With a crafted payload, XSS can be triggered, as demonstrated by omitting the final '>' character from an IMG tag.
ModificadaAlta (8.8)3.6%—Python14/12/201717/6/2026
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that exploitation is impossible because the…
ModificadaCrítica (9.8)7.9%—PythonDebian Linux17/11/201717/6/2026
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
ModificadaCrítica (9.8)2.6%—Recurly Client Python13/11/201717/6/2026
The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources.
ModificadaMedia (6.1)2.1%—Ipython21/9/201717/6/2026
Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/contents path.
ModificadaMedia (6.1)2.3%—Ipython20/9/201717/6/2026
Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/notebooks path.
ModificadaAlta (8.8)1.2%—IpythonFedoraproject Fedora20/9/201717/6/2026
Cross-site request forgery in the REST API in IPython 2 and 3.
ModificadaMedia (5.5)0.21%—Gentoo Dev-python-flower15/9/201717/6/2026
flower.initd in the Gentoo dev-python/flower package before 0.9.1-r1 for Celery Flower sets PID file ownership to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`"…
ModificadaMedia (6.1)0.99%—Fedoraproject Python-fedora14/9/201717/6/2026
python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection
ModificadaMedia (5.9)8.1%—PythonSimplejson Project SimplejsonOpensuseOpensuse Project Opensuse24/8/201717/6/2026
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.
ModificadaAlta (7.5)8.7%—Libexpat Project LibexpatPythonDebian Linux25/7/201717/6/2026
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD.
ModificadaCrítica (9.8)4.9%—Python Tablib14/6/201717/6/2026
An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.
ModificadaBaja (3.3)0.41%—Oracle Connector/python24/4/201717/6/2026
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions that are affected are 2.1.5 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL…
ModificadaMedia (5.5)2.6%—Python Pillow24/4/201717/6/2026
Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.
ModificadaAlta (8.2)1.2%—Python Openpyxl15/2/201717/6/2026
Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.