Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.33% | — | DulwichAIParamikoAI | 15/7/2026 | 16/7/2026 | Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py. | |
| Pendiente de análisis | Baja (3.4) | 0.13% | — | ParamikoAI | 6/5/2026 | 24/7/2026 | In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm. | |
| Modificada | Media (5.9) | 94% | — | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Media (5.9) | 2.1% | — | ParamikoDebian LinuxFedoraproject Fedora | 17/3/2022 | 17/6/2026 | In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure. | |
| Modificada | Alta (8.8) | 4.4% | — | ParamikoRedhat Ansible TowerRedhat Virtualization HostRedhat Enterprise Linux Desktop+7 | 8/10/2018 | 17/6/2026 | Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity. | |
| Modificada | Crítica (9.8) | 27% | — | ParamikoRedhat Ansible EngineRedhat CloudformsRedhat Virtualization+7 | 13/3/2018 | 17/6/2026 | transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by… | |
| Modificada | Media (4.3) | 1.6% | — | Python Software Foundation Paramiko | 16/1/2008 | 16/6/2026 | common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool. |