Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
23.894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.66% | — | Httplib2 Project Httplib2 | 8/7/2026 | 20/8/2026 | httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload… | |
| Analizada | Alta (8.7) | 0.62% | — | Pypdf Project Pypdf | 8/7/2026 | 9/7/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inline image, causing an infinite loop during inline image end marker detection such as when extracting page text. This issue is fixed in version 6.14.1. | |
| Analizada | Alta (8.7) | 0.62% | — | Pypdf Project Pypdf | 8/7/2026 | 9/7/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version… | |
| Analizada | Alta (8.8) | 0.64% | — | Yt-dlp Project Yt-dlp | 8/7/2026 | 13/7/2026 | yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious… | |
| Analizada | Media (6.9) | 0.52% | — | Pypdf Project Pypdf | 8/7/2026 | 9/7/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in version 6.14.0. | |
| Analizada | Media (6.9) | 0.62% | — | Pypdf Project Pypdf | 8/7/2026 | 9/7/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recovering broken cross-reference table entries. This issue is fixed in version 6.14.0. | |
| Analizada | Media (4.3) | 0.19% | — | Mistune Project Mistune | 8/7/2026 | 9/7/2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controlled id="toc_N" content to collide with generated anchors and redirect same-page… | |
| Analizada | Media (6.1) | 0.34% | — | Mistune Project Mistune | 8/7/2026 | 9/7/2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only javascript:, vbscript:, file:, and data: schemes, allowing legacy or chained schemes such as feed:, view-source:, jar:, livescript:, mocha:, ms-its:, mk:, and res: to reach… | |
| Analizada | Alta (7.5) | 0.65% | — | Mistune Project Mistune | 8/7/2026 | 9/7/2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service through CPU exhaustion.… | |
| Analizada | Media (5.3) | 0.53% | — | Mistune Project Mistune | 8/7/2026 | 9/7/2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionError, and crash the… | |
| Analizada | Media (5.3) | 0.33% | — | Mistune Project Mistune | 8/7/2026 | 9/7/2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escaping, allowing attribute injection and cross-site scripting even when HTMLRenderer… | |
| Analizada | Alta (7.5) | 0.64% | — | Mistune Project Mistune | 8/7/2026 | 9/7/2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from every potential… | |
| Analizada | Media (5.9) | 0.46% | — | Mistune Project Mistune | 8/7/2026 | 9/7/2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing crafted include paths to access files outside that directory when markdown files… | |
| Analizada | Media (6.1) | 0.35% | — | Mistune Project Mistune | 8/7/2026 | 9/7/2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and execute script in rendered HTML. This issue is fixed in version 3.3.0. | |
| Analizada | Alta (7.5) | 0.64% | — | Mistune Project Mistune | 8/7/2026 | 9/7/2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each possible start… | |
| Analizada | Alta (7.5) | 0.67% | — | Protobufjs Project Protobufjs | 8/7/2026 | 10/7/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause… | |
| Analizada | Media (4.8) | 0.35% | — | Protobufjs Project Protobufjs | 8/7/2026 | 13/7/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed string-keyed map entries using ordinary property assignment, allowing a map entry with key __proto__ to change the prototype of the returned map object instead of creating an own… | |
| Aplazada | Media (5.3) | 0.37% | — | Misp-project MispAI | 8/7/2026 | 9/7/2026 | An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_standard format, the write path did not verify event modification… | |
| Analizada | Media (5.3) | 0.33% | — | Djangoproject Django | 7/7/2026 | 9/7/2026 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is… | |
| Analizada | Media (6.3) | 0.44% | — | Djangoproject Django | 7/7/2026 | 9/7/2026 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is… | |
| Analizada | Baja (2.3) | 0.43% | — | Djangoproject Django | 7/7/2026 | 9/7/2026 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported… | |
| Modificada | Media (4.7) | 0.13% | — | Zephyrproject Zephyr | 7/7/2026 | 1/9/2026 | The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that, on a flash error, the error code was written unconditionally through the caller-supplied dhara_error_t err pointer (e.g. *err = DHARA_E_ECC in dhara_nand_read, and similar in… | |
| Pendiente de análisis | Alta (8.8) | 0.49% | — | 389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI | 7/7/2026 | 8/7/2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds… | |
| Aplazada | Media (6.5) | 0.53% | — | Mojo JsonAI | 6/7/2026 | 6/7/2026 | Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. The pure-Perl decode path (`_decode_value` dispatching to `_decode_array` and `_decode_object`) recurses with no depth limit, so a small deeply nested JSON document can consume excessive memory. This path… | |
| Modificada | Media (5.3) | 0.40% | — | Zephyrproject Zephyr | 5/7/2026 | 14/7/2026 | Zephyr's DNS resolver detects mDNS (.local) queries in dns_resolve_name_internal() (subsys/net/lib/dns/resolve.c) with memcmp(strrchr(query, '.'), ".local", 7), which always reads a fixed 7 bytes from the suffix pointer. When the resolved hostname's final label is shorter than 7 bytes (e.g. names ending in .org, .com,… |