Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.5) | 0.72% | — | Webpy Web.pyAI | 23/9/2026 | 24/9/2026 | webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlled template code that built-in security checks are designed to reject. When an application precompiles templates from a directory the attacker can write to and later renders them… | |
| Aplazada | Media (6.8) | 0.29% | — | Webpy Web.pyAI | 22/9/2026 | 22/9/2026 | webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, and _save() writes back under the same session_id; no rotation after authentication, so a fixed session_id keeps the authenticated state. | |
| Aplazada | Sin puntuar | 0.15% | — | Webpy Web.pyAI | 22/9/2026 | 22/9/2026 | webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__(). | |
| Aplazada | Crítica (9.8) | 0.38% | — | Webpy Web.pyAI | 22/9/2026 | 22/9/2026 | webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an expired session whose record has not yet been cleaned up can still be replayed and… | |
| Aplazada | Media (5.3) | 0.33% | — | Webpy Web.pyAI | 19/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seqname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… |