Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.19% | — | Anaconda DaskAI | 22/9/2026 | 23/9/2026 | A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loader. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was… | |
| Aplazada | Baja (2.3) | 0.29% | — | Anaconda DaskAI | 3/6/2026 | 22/7/2026 | A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack.… | |
| Analizada | Media (5.3) | 0.24% | — | Anaconda Dask | 16/1/2026 | 17/6/2026 | Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, and Dask distributed are all run together, it is possible to craft a URL which will result in code being executed by Jupyter due to a cross-side-scripting (XSS) bug in the Dask dashboard. It is… | |
| Analizada | Alta (7.8) | 0.20% | — | Anaconda3 | 17/12/2025 | 26/9/2026 | Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary commands, leading to code… | |
| Analizada | Alta (7.2) | 0.65% | — | Anaconda Conda-build | 16/6/2025 | 17/6/2026 | Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the package, and then exploit pip install… | |
| Analizada | Media (5.6) | 1.3% | — | Anaconda Conda-build | 16/6/2025 | 17/6/2026 | Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build processing logic is vulnerable to path traversal (Tarslip) attacks due to improper sanitization of tar entry paths. Attackers can craft tar archives containing entries with directory traversal sequences to write… | |
| Analizada | Alta (8.2) | 0.83% | — | Anaconda Conda-build | 16/6/2025 | 17/6/2026 | Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build recipe processing logic has been found to be vulnerable to arbitrary code execution due to unsafe evaluation of recipe selectors. Currently, conda-build uses the eval function to process embedded selectors in… | |
| Analizada | Media (6) | 0.17% | — | Anaconda Conda-build | 16/6/2025 | 17/6/2026 | Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, the write_build_scripts function in conda-build creates the temporary build script conda_build.sh with overly permissive file permissions (0o766), allowing write access to all users. Attackers with filesystem access can exploit a… | |
| Aplazada | Crítica (9.3) | 0.41% | — | Conda-forge InfrastructureAIMicrosoft AzureAIAnaconda.orgAI | 2/4/2025 | 17/6/2026 | conda-forge infrastructure holds common configurations and settings for key pieces of the conda-forge infrastructure. Between 2025-02-10 and 2025-04-01, conda-forge infrastructure used the wrong token for Azure's cf-staging access. This bug meant that any feedstock maintainer could upload a package to the conda-forge… | |
| Modificada | Media (4.7) | 0.12% | — | Anaconda3 | 11/9/2023 | 17/6/2026 | Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many files are installed as world-writable on Linux, ignoring umask, even when these files are installed as root. Miniconda is also affected. | |
| Modificada | Alta (8.8) | 1.9% | — | Anaconda3 | 13/5/2022 | 17/6/2026 | Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed. | |
| Modificada | Alta (7.8) | 0.33% | — | Anaconda3Miniconda3 | 17/3/2022 | 17/6/2026 | Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory into the system PATH environment variable. Thus, for example, local users can gain privileges by placing a Trojan horse file into that… | |
| Modificada | Crítica (9.8) | 3.0% | — | Anaconda Dask | 26/10/2021 | 17/6/2026 | An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters started with dask.distributed.LocalCluster or dask.distributed.Client (which defaults to using LocalCluster) would mistakenly configure their respective Dask workers to listen on external interfaces… | |
| Modificada | Baja (2.1) | 0.40% | — | Fedoraproject Anaconda | 3/7/2012 | 16/6/2026 | The bootloader configuration module (pyanaconda/bootloader.py) in Anaconda uses 755 permissions for /etc/grub.d, which allows local users to obtain password hashes and conduct brute force password guessing attacks. | |
| Modificada | Media (5) | 1.5% | — | Anaconda Partners Foundation Directory | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in apexec.pl for Anaconda Foundation Directory allows remote attackers to read arbitrary files via hex-encoded null characters (%00) in the middle of ".." sequences in the template parameter. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Anaconda Partners Clipper | 22/8/2001 | 16/6/2026 | Anaconda Partners Clipper 3.3 and earlier allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the template parameter. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Anaconda Partners Foundation Directory | 19/12/2000 | 23/9/2026 | Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack. |