Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.1%—Python-jose Project Python-jose23/1/201717/6/2026
python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.
ModificadaBaja (3.7)0.75%—Python Urllib311/1/201717/6/2026
Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability…
ModificadaAlta (7.5)1.8%—Python HpackPython Hyper10/1/201717/6/2026
A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could be targeted for a denial of service attack, specifically a so-called "HPACK Bomb" attack. This attack occurs when an attacker inserts a header field that is exactly the size of the HPACK dynamic header table…
ModificadaAlta (7.5)1.8%—Python Priority Library10/1/201717/6/2026
A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having that peer assign priority information for every possible HTTP/2 stream ID. The priority tree would happily continue to store the priority information for each stream,…
ModificadaAlta (8.8)2.4%—Python-openxml Project Python-docx21/12/201617/6/2026
python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.
ModificadaAlta (7.8)1.9%—Python PillowDebian Linux4/11/201617/6/2026
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.
ModificadaMedia (5.5)1.9%—Python PillowDebian Linux4/11/201617/6/2026
Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.
ModificadaMedia (5.6)2.2%—Oracle Mysql Connector/python25/10/201617/6/2026
Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and 2.0.4 and earlier in Oracle MySQL allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Connector/Python.
ModificadaAlta (7.5)1.3%—Python Tgcaptcha225/10/201617/6/2026
TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times.
ModificadaCrítica (9.8)3.2%—Openstack Mitaka-muranoOpenstack MuranoOpenstack Murano-dashboardOpenstack Python-muranoclient26/9/201617/6/2026
OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and python-muranoclient before 0.7.3 (liberty) and 0.8.x before 0.8.5 (mitaka) improperly use loaders inherited from yaml.Loader when parsing MuranoPL and UI files, which allows…
ModificadaMedia (6.1)9.9%—Python2/9/201617/6/2026
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
ModificadaCrítica (9.8)25%—Python2/9/201617/6/2026
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.
ModificadaMedia (6.5)15%—Python2/9/201617/6/2026
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS…
ModificadaAlta (7.5)95%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss WEB ServerRedhat Enterprise Linux+51/9/201617/6/2026
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated…
ModificadaAlta (8.1)12%—Libexpat Project LibexpatCanonical Ubuntu LinuxMcafee Policy AuditorPython30/6/201617/6/2026
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
ModificadaMedia (6.5)16%—Bzip2Python30/6/201617/6/2026
Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.
ModificadaMedia (5.9)1.9%—Python7/6/201617/6/2026
The ssl.match_hostname function in CPython (aka Python) before 2.7.9 and 3.x before 3.3.3 does not properly handle wildcards in hostnames, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
ModificadaCrítica (9.8)13%—Mozilla FirefoxApple MAC OS XSuse Linux Enterprise DebuginfoSuse Studio Onsite+1026/5/201617/6/2026
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
ModificadaCrítica (9.8)7.9%—Python Pillow13/4/201617/6/2026
Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.
ModificadaMedia (6.5)4.0%—Python PillowPython Imaging Project Python ImagingDebian Linux13/4/201617/6/2026
Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.
ModificadaMedia (6.5)2.5%—Python PillowDebian Linux13/4/201617/6/2026
Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
ModificadaMedia (6.5)2.6%—Python PillowDebian Linux13/4/201617/6/2026
Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
ModificadaMedia (5.3)7.1%—Python RSAFedoraproject FedoraOpensuse LeapOpensuse13/1/201617/6/2026
The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.
ModificadaAlta (7.2)0.59%—Python6/10/201517/6/2026
Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a longtime behavior of Python that cannot really be altered at this…
ModificadaMedia (6.8)2.5%—Ipython NotebookJupyter Notebook29/9/201517/6/2026
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.