Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.8) | 0.14% | — | VirtualenvAI | 29/9/2026 | 30/9/2026 | virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with str.splitlines() and accepts the last value for duplicate keys. An attacker who influences… | |
| Pendiente de análisis | Alta (7.3) | 0.14% | — | VirtualenvAI | 29/9/2026 | 2/10/2026 | virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=value" statement. An attacker who influences --prompt, VIRTUALENV_PROMPT, or the corresponding configuration value can… | |
| Pendiente de análisis | Alta (7.7) | 0.16% | — | VirtualenvAI | 29/9/2026 | 30/9/2026 | virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes against an authoritative digest equivalent to the embedded wheels' BUNDLE_SHA256… | |
| Pendiente de análisis | Alta (7.8) | 0.15% | — | VirtualenvAI | 29/9/2026 | 30/9/2026 | virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh script, a crafted virtual environment path reaches… | |
| Analizada | Media (4.5) | 0.10% | — | Virtualenv | 10/1/2026 | 17/6/2026 | virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory creation operations. An attacker with local access can exploit a race condition between… | |
| Analizada | Alta (7.8) | 1.6% | — | Virtualenv | 24/11/2024 | 17/6/2026 | virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287. | |
| Modificada | Alta (7.8) | 0.54% | — | Autoswitch Python Virtualenv Project Autoswitch Python Virtualenv | 13/5/2020 | 17/6/2026 | In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0 | |
| Modificada | Media (5.9) | 8.0% | 💥 Exploit | Pypa PIPVirtualenvFedoraproject FedoraRedhat Openshift+2 | 5/11/2019 | 16/6/2026 | The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks. | |
| Modificada | Baja (1.2) | 0.31% | — | Python Virtualenv | 31/12/2011 | 16/6/2026 | virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary files via a symlink attack on a certain file in /tmp/. |