Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
651 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.5% | — | Ipython NotebookJupyter Notebook | 29/9/2015 | 17/6/2026 | The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types. | |
| Modificada | Media (4.3) | 2.8% | — | Jupyter NotebookFedoraproject FedoraOpensuseIpython Notebook | 21/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF)… | |
| Modificada | Media (6.8) | 18% | — | Google ChromeLibexpat Project LibexpatPythonDebian Linux+9 | 23/7/2015 | 17/6/2026 | Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to… | |
| Modificada | Media (5) | 2.0% | — | OpensusePython Pillow | 1/5/2015 | 17/6/2026 | The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image. | |
| Modificada | Media (4.3) | 2.6% | — | Openstack KeystonemiddlewareOpenstack Python-keystoneclientCanonical Ubuntu Linux | 17/4/2015 | 17/6/2026 | The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a… | |
| Modificada | Media (6.8) | 3.4% | — | Mageia Project MageiaPython RequestsCanonical Ubuntu Linux | 18/3/2015 | 17/6/2026 | The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect. | |
| Modificada | Media (5) | 4.6% | — | Python PillowOracle SolarisFedoraproject FedoraOpensuse | 16/1/2015 | 17/6/2026 | Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed. | |
| Modificada | Media (5.8) | 3.0% | — | PythonApple MAC OS X | 12/12/2014 | 17/6/2026 | The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b)… | |
| Modificada | Baja (3.3) | 0.36% | — | Python | 16/11/2014 | 17/6/2026 | Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value. | |
| Modificada | Media (4.4) | 0.39% | — | Python-gnupg Project Python-gnupg | 25/10/2014 | 17/6/2026 | python-gnupg 0.3.5 and 0.3.6 allows context-dependent attackers to have an unspecified impact via vectors related to "option injection through positional arguments." NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323. | |
| Modificada | Media (4.6) | 0.61% | — | Python-gnupg Project Python-gnupg | 25/10/2014 | 17/6/2026 | The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulnerability than… | |
| Modificada | Alta (7.5) | 3.4% | — | Python-gnupg Project Python-gnupg | 25/10/2014 | 17/6/2026 | The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928. NOTE: this… | |
| Modificada | Media (5) | 2.0% | — | OpensusePython Requests | 15/10/2014 | 17/6/2026 | Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request. | |
| Modificada | Media (5) | 2.2% | — | Debian LinuxPython RequestsCanonical Ubuntu LinuxMageia | 15/10/2014 | 17/6/2026 | Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request. | |
| Modificada | Media (6.4) | 5.1% | — | PythonApple MAC OS X | 8/10/2014 | 17/6/2026 | Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function. | |
| Modificada | Media (4.3) | 2.0% | — | Openstack KeystonemiddlewareOpenstack Python-keystoneclient | 2/10/2014 | 17/6/2026 | OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted… | |
| Modificada | Media (5) | 3.4% | — | Debian Python-imagingPython PillowOpensuse | 25/8/2014 | 17/6/2026 | PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size. | |
| Modificada | Media (6.8) | 4.7% | — | OpensuseIpython NotebookMageia | 7/8/2014 | 17/6/2026 | IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page. | |
| Modificada | Alta (7.5) | 2.9% | — | Vinay Sajip Python-gnupg | 9/6/2014 | 17/6/2026 | python-gnupg before 0.3.5 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in unspecified vectors. | |
| Modificada | Alta (7.4) | 95% | — | OpensslRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise WEB Server+12 | 5/6/2014 | 17/6/2026 | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive… | |
| Modificada | Media (5.8) | 2.5% | — | Urbanairship Python-oauth2 | 20/5/2014 | 16/6/2026 | The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack. | |
| Modificada | Media (4.3) | 2.4% | — | Urbanairship Python-oauth2 | 20/5/2014 | 16/6/2026 | The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL. | |
| Modificada | Media (4.3) | 3.3% | — | Apple MAC OS XPython | 19/5/2014 | 17/6/2026 | Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers to cause a denial of service (CPU consumption) via crafted input… | |
| Modificada | Media (6.4) | 1.8% | — | Xiaowen Huang Yingzhi Python Programming Language | 14/5/2014 | 16/6/2026 | Directory traversal vulnerability in the FTP server in YingZhi Python Programming Language for iOS 1.9 allows remote attackers to read and possibly write arbitrary files via a .. (dot dot) in the default URI. | |
| Modificada | Alta (10) | 11% | — | Python PillowPythonware Python Imaging Library | 27/4/2014 | 17/6/2026 | Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py. |