Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.47%—Usebottles BottlesFedoraproject Fedora26/5/202317/6/2026
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
ModificadaCrítica (9.8)0.67%—Bottle-auth Project Bottle-auth7/1/202317/6/2026
A vulnerability, which was classified as critical, was found in john5223 bottle-auth. Affected is an unknown function. The manipulation leads to sql injection. The name of the patch is 99cfbcc0c1429096e3479744223ffb4fda276875. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability…
ModificadaCrítica (9.8)2.1%—Bottlepy BottleDebian LinuxFedoraproject Fedora2/6/202217/6/2026
Bottle before 0.12.20 mishandles errors during early request binding.
ModificadaAlta (7.5)1.3%—Obottle Project Obottle3/6/202117/6/2026
OBottle 2.0 in \c\g.php contains an arbitrary file download vulnerability.
ModificadaAlta (8.1)1.1%—Obottle Project Obottle3/6/202117/6/2026
OBottle 2.0 in \c\t.php contains an arbitrary file write vulnerability.
ModificadaMedia (6.8)1.8%—Bottlepy BottleDebian Linux18/1/202117/6/2026
The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration)…
ModificadaMedia (6.5)1.8%—Bottlepy BottleDebian Linux16/12/201617/6/2026
redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.
ModificadaMedia (6.8)3.1%—Bottlepy Bottle25/10/201417/6/2026
Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in…