Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.28% | — | Intel Distribution FOR Python | 12/9/2018 | 17/6/2026 | Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user to escalate privileges via local access. | |
| Modificada | Alta (7.8) | 0.32% | — | Intel Distribution FOR Python | 1/8/2018 | 17/6/2026 | Insufficient Input Validation in Bleach module in INTEL Distribution for Python versions prior to IDP 2018 Update 2 allows unprivileged user to bypass URI sanitization via local vector. | |
| Modificada | Alta (7.5) | 3.2% | — | Python-cryptographyRedhat OpenstackCanonical Ubuntu Linux | 30/7/2018 | 17/6/2026 | A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they… | |
| Modificada | Alta (7.5) | 4.9% | — | PythonDebian LinuxRedhat Ansible TowerRedhat Enterprise Linux Desktop+4 | 19/6/2018 | 17/6/2026 | python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service. | |
| Modificada | Alta (7.5) | 5.0% | — | PythonFedoraproject FedoraCanonical Ubuntu LinuxRedhat Ansible Tower+4 | 18/6/2018 | 17/6/2026 | python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service. | |
| Modificada | Crítica (9.8) | 5.5% | — | Mozilla FirefoxDebian LinuxPython | 11/6/2018 | 17/6/2026 | An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50. | |
| Modificada | Crítica (9.8) | 6.2% | — | Python-eve EVE | 14/3/2018 | 17/6/2026 | io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter. | |
| Modificada | Media (6.7) | 1.0% | — | Python | 7/3/2018 | 17/6/2026 | Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an… | |
| Modificada | Media (6.5) | 1.3% | — | Python | 1/3/2018 | 17/6/2026 | The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because Python applications "need to be… | |
| Modificada | Baja (3.6) | 1.2% | — | PythonCanonical Ubuntu Linux | 8/2/2018 | 17/6/2026 | Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be vulnerable however this has not been confirmed. The vulnerability lies when multiply threads are handling large amounts… | |
| Modificada | Media (6.1) | 0.82% | — | Python-markdown2 Project Python-markdown2 | 18/1/2018 | 17/6/2026 | An issue was discovered in markdown2 (aka python-markdown2) through 2.3.5. The safe_mode feature, which is supposed to sanitize user input against XSS, is flawed and does not escape the input properly. With a crafted payload, XSS can be triggered, as demonstrated by omitting the final '>' character from an IMG tag. | |
| Modificada | Alta (8.8) | 3.6% | — | Python | 14/12/2017 | 17/6/2026 | Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that exploitation is impossible because the… | |
| Modificada | Crítica (9.8) | 7.9% | — | PythonDebian Linux | 17/11/2017 | 17/6/2026 | CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution) | |
| Modificada | Crítica (9.8) | 2.6% | — | Recurly Client Python | 13/11/2017 | 17/6/2026 | The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources. | |
| Modificada | Media (6.1) | 2.1% | — | Ipython | 21/9/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/contents path. | |
| Modificada | Media (6.1) | 2.3% | — | Ipython | 20/9/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/notebooks path. | |
| Modificada | Alta (8.8) | 1.2% | — | IpythonFedoraproject Fedora | 20/9/2017 | 17/6/2026 | Cross-site request forgery in the REST API in IPython 2 and 3. | |
| Modificada | Media (5.5) | 0.21% | — | Gentoo Dev-python-flower | 15/9/2017 | 17/6/2026 | flower.initd in the Gentoo dev-python/flower package before 0.9.1-r1 for Celery Flower sets PID file ownership to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`"… | |
| Modificada | Media (6.1) | 0.99% | — | Fedoraproject Python-fedora | 14/9/2017 | 17/6/2026 | python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection | |
| Modificada | Media (5.9) | 8.1% | — | PythonSimplejson Project SimplejsonOpensuseOpensuse Project Opensuse | 24/8/2017 | 17/6/2026 | Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function. | |
| Modificada | Alta (7.5) | 8.7% | — | Libexpat Project LibexpatPythonDebian Linux | 25/7/2017 | 17/6/2026 | XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD. | |
| Modificada | Crítica (9.8) | 4.9% | — | Python Tablib | 14/6/2017 | 17/6/2026 | An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability. | |
| Modificada | Baja (3.3) | 0.41% | — | Oracle Connector/python | 24/4/2017 | 17/6/2026 | Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions that are affected are 2.1.5 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL… | |
| Modificada | Media (5.5) | 2.6% | — | Python Pillow | 24/4/2017 | 17/6/2026 | Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file. | |
| Modificada | Alta (8.2) | 1.2% | — | Python Openpyxl | 15/2/2017 | 17/6/2026 | Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document. |