Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
–

650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.9)0.32%—Biopython Bio.entrezAI18/12/202517/6/2026
Bio.Entrez in Biopython through 186 allows doctype XXE.
AnalizadaMedia (5.3)0.19%—Python-jose Project Python-jose17/12/202517/6/2026
In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation…
AnalizadaAlta (8.9)0.68%—Python Urllib35/12/202525/9/2026
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire…
AnalizadaAlta (8.9)0.68%—Python Urllib35/12/202525/9/2026
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the…
AnalizadaMedia (6.9)0.14%—Ubuntu Python-aptDebian Linux5/12/202525/9/2026
NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.
ModificadaMedia (6.3)0.80%—Python3/12/202517/6/2026
When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.
AnalizadaAlta (7.6)0.51%—Lfprojects MCP Python SDK2/12/202517/6/2026
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.23.0, tThe Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without…
ModificadaBaja (2.1)0.22%—Python1/12/20253/9/2026
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
AnalizadaMedia (6.3)1.6%—Python1/12/20253/9/2026
When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.
AplazadaMedia (5.4)0.12%—Intel Distribution FOR PythonAI11/11/202517/6/2026
Uncontrolled search path for some Intel(R) Distribution for Python software installers before version 2025.2.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege.…
AplazadaAlta (8.6)0.45%—Amazon Aurora PostgresqlAIAmazon Jdbc WrapperAIAmazon GO WrapperAIAmazon Nodejs WrapperAI+210/11/202517/6/2026
An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. We recommend customers upgrade to the…
AnalizadaBaja (1.8)0.15%—Python31/10/202530/9/2026
If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.
AplazadaAlta (8.9)0.63%—KerasAIPythonAI30/10/202517/6/2026
The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python's tarfile.extractall function without the filter="data" feature. A remote attacker can craft a malicious tar archive containing special symlinks, which, when…
AnalizadaMedia (5.5)0.46%—Python-ldap10/10/202517/6/2026
python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x00 incorrectly by emitting a backslash followed by a literal NUL byte instead of the RFC-4514 hex form \00. Any application that uses this helper to construct DNs from…
AnalizadaMedia (5.5)0.32%—Python-ldap10/10/202517/6/2026
python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the sanitization method `ldap.filter.escape_filter_chars` can be tricked to skip escaping of special characters when a crafted `list` or `dict` is supplied as the `assertion_value` parameter, and the…
AplazadaMedia (6.5)0.32%—Python-joseAI10/10/202517/6/2026
python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged token with arbitrary claims (e.g., is_admin=true) and bypass authentication checks, leading to privilege escalation or unauthorized access in…
AplazadaMedia (6.3)0.42%—Python Social AuthAI9/10/202517/6/2026
Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate…
AplazadaMedia (4.3)0.38%—Python ZipfileAI7/10/202531/7/2026
The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are…
AplazadaMedia (6.4)0.48%—Python-socketioAI6/10/202517/6/2026
python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker…
AplazadaMedia (5.9)0.47%—Pypa PIPAIPythonAI24/9/202525/9/2026
When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP…
AplazadaCrítica (9.8)1.4%—Ftp-flask-pythonAI9/9/202517/6/2026
A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute arbitrary OS commands. The /ftp.html endpoint's "Upload File" action constructs a shell command from the ftp_file parameter and executes it using os.system() without sanitization or escaping.
AnalizadaMedia (6.9)0.11%—Heinlein-support Check MK Python API28/8/202525/9/2026
Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.
AplazadaMedia (5.4)0.29%—Pythoncharmers Python-futureAI14/8/202517/6/2026
A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to…
AplazadaMedia (5.4)0.11%—Intel Distribution FOR PythonAI12/8/202517/6/2026
Incorrect default permissions for some Intel(R) Distribution for Python software installers before version 2025.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.5)0.67%—CpythonAI28/7/202531/7/2026
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability…