Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.5% | — | Yaml-cpp Project Yaml-cpp | 14/1/2019 | 17/6/2026 | The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file. | |
| Modificada | Alta (7.8) | 0.40% | — | Sqla Yaml Fixtures Project Sqla Yaml Fixtures | 3/1/2019 | 17/6/2026 | Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load. | |
| Modificada | Media (6.5) | 2.5% | — | Yaml-cpp Project Yaml-cpp | 28/12/2018 | 17/6/2026 | The SingleDocParser::HandleFlowMap function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file. | |
| Modificada | Media (6.5) | 2.5% | — | Yaml-cpp Project Yaml-cpp | 28/12/2018 | 17/6/2026 | The Scanner::EnsureTokensInQueue function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file. | |
| Modificada | Alta (7.8) | 1.5% | — | Yamldotnet Project Yamldotnet | 13/7/2018 | 17/6/2026 | YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior of Deserializer.Deserialize() will deserialize user-controlled types in the line "currentType = Type.GetType(nodeEvent.Tag.Substring(1), throwOnError: false);" and blindly instantiates them. that can… | |
| Modificada | Crítica (9.8) | 5.7% | — | PyyamlFedoraproject Fedora | 27/6/2018 | 17/6/2026 | In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function. | |
| Modificada | Alta (7.5) | 2.2% | — | Yaml-cpp Project Yaml-cpp | 30/7/2017 | 17/6/2026 | The function "Token& Scanner::peek" in scanner.cpp in yaml-cpp 0.5.3 and earlier allows remote attackers to cause a denial of service (assertion failure and application exit) via a '!2' string. | |
| Modificada | Media (5.5) | 2.0% | — | Yaml-cpp Project Yaml-cpp | 3/4/2017 | 17/6/2026 | The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.3 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file. | |
| Modificada | Media (5) | 13% | — | Pyyaml Libyaml | 8/12/2014 | 17/6/2026 | scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping. | |
| Modificada | Media (6.8) | 8.8% | — | Pyyaml LibyamlOpensuse LeapOpensuse | 28/3/2014 | 17/6/2026 | Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file. | |
| Modificada | Media (6.8) | 7.4% | — | Pyyaml LibyamlCanonical Ubuntu LinuxRedhat OpenstackDebian Linux+2 | 6/2/2014 | 17/6/2026 | The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 17% | 💥 Exploit | Nodeca Js-yaml | 28/6/2013 | 16/6/2026 | The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation. | |
| Modificada | Media (5) | 2.4% | — | Ingy Yaml\ | 9/9/2012 | 16/6/2026 | Multiple format string vulnerabilities in the error reporting functionality in the YAML::LibYAML (aka YAML-LibYAML and perl-YAML-LibYAML) module 0.38 for Perl allow remote attackers to cause a denial of service (process crash) via format string specifiers in a (1) YAML stream to the Load function, (2) YAML node to the… | |
| Modificada | Media (5) | 2.3% | — | Yaml-fuer-drupal Linkchecker | 28/8/2012 | 16/6/2026 | includes/linkchecker.pages.inc in the Link checker module 6.x-2.x before 6.x-2.5 for Drupal does not properly enforce access permissions on broken links, which allows remote attackers to obtain sensitive information via unspecified vectors. |