Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

64 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.5%—Yaml-cpp Project Yaml-cpp14/1/201917/6/2026
The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
ModificadaAlta (7.8)0.40%—Sqla Yaml Fixtures Project Sqla Yaml Fixtures3/1/201917/6/2026
Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.
ModificadaMedia (6.5)2.5%—Yaml-cpp Project Yaml-cpp28/12/201817/6/2026
The SingleDocParser::HandleFlowMap function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
ModificadaMedia (6.5)2.5%—Yaml-cpp Project Yaml-cpp28/12/201817/6/2026
The Scanner::EnsureTokensInQueue function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
ModificadaAlta (7.8)1.5%—Yamldotnet Project Yamldotnet13/7/201817/6/2026
YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior of Deserializer.Deserialize() will deserialize user-controlled types in the line "currentType = Type.GetType(nodeEvent.Tag.Substring(1), throwOnError: false);" and blindly instantiates them. that can…
ModificadaCrítica (9.8)5.7%—PyyamlFedoraproject Fedora27/6/201817/6/2026
In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.
ModificadaAlta (7.5)2.2%—Yaml-cpp Project Yaml-cpp30/7/201717/6/2026
The function "Token& Scanner::peek" in scanner.cpp in yaml-cpp 0.5.3 and earlier allows remote attackers to cause a denial of service (assertion failure and application exit) via a '!2' string.
ModificadaMedia (5.5)2.0%—Yaml-cpp Project Yaml-cpp3/4/201717/6/2026
The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.3 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
ModificadaMedia (5)13%—Pyyaml Libyaml8/12/201417/6/2026
scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.
ModificadaMedia (6.8)8.8%—Pyyaml LibyamlOpensuse LeapOpensuse28/3/201417/6/2026
Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file.
ModificadaMedia (6.8)7.4%—Pyyaml LibyamlCanonical Ubuntu LinuxRedhat OpenstackDebian Linux+26/2/201417/6/2026
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
ModificadaMedia (6.8)17%💥 ExploitNodeca Js-yaml28/6/201316/6/2026
The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation.
ModificadaMedia (5)2.4%—Ingy Yaml\9/9/201216/6/2026
Multiple format string vulnerabilities in the error reporting functionality in the YAML::LibYAML (aka YAML-LibYAML and perl-YAML-LibYAML) module 0.38 for Perl allow remote attackers to cause a denial of service (process crash) via format string specifiers in a (1) YAML stream to the Load function, (2) YAML node to the…
ModificadaMedia (5)2.3%—Yaml-fuer-drupal Linkchecker28/8/201216/6/2026
includes/linkchecker.pages.inc in the Link checker module 6.x-2.x before 6.x-2.5 for Drupal does not properly enforce access permissions on broken links, which allows remote attackers to obtain sensitive information via unspecified vectors.
Orbitaley — Vulnerabilidades