Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2538▼ 400 respecto a la semana anterior
Críticas / altas1320▲ 39 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.24%—Erdogant Pypickle26/5/202517/6/2026
A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the function Save of the file pypickle/pypickle.py. The manipulation leads to improper authorization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Upgrading…
AnalizadaMedia (4.8)0.32%—Erdogant Pypickle26/5/202517/6/2026
A vulnerability was found in erdogant pypickle up to 1.1.5 and classified as problematic. Affected by this issue is the function load of the file pypickle/pypickle.py. The manipulation leads to deserialization. Local access is required to approach this attack. The exploit has been disclosed to the public and may be…
ModificadaAlta (7.5)0.41%—Bandoche Pypinksign16/11/20239/7/2026
PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
ModificadaCrítica (9.8)1.5%—Pypi22/7/202217/6/2026
The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
ModificadaCrítica (9.8)1.5%—Pypi22/7/202217/6/2026
The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
ModificadaCrítica (9.8)2.0%—Pypi Watertools24/6/202217/6/2026
The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Pypi Drxhello24/6/202217/6/2026
The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Pypi Perdido24/6/202217/6/2026
The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Pypi Dr-web-engine24/6/202217/6/2026
The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Pypi Beginner24/6/202217/6/2026
The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Pypi Watools24/6/202217/6/2026
The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Pypi Explore24/6/202217/6/2026
The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Pypi Aamiles24/6/202217/6/2026
The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Pypi Ml-scanner24/6/202217/6/2026
The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Pypi Cloudlabeling24/6/202217/6/2026
The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Pypi Cryptoasset-data-downloader24/6/202217/6/2026
The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Pypi Rootinteractive24/6/202217/6/2026
The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Pypi Django-navbar-client24/6/202217/6/2026
The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.3%—Python Pypi8/5/202217/6/2026
marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.
ModificadaAlta (7.8)1.1%—Pypi Bsdiff422/7/202017/6/2026
A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file.
ModificadaMedia (6.1)3.8%—Python Pypiserver25/1/201917/6/2026
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.