Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3222▲ 222 respecto a la semana anterior
Críticas / altas1465▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)511▼ 31 respecto a la semana anterior
647 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6) | 0.45% | — | Python UrllibAI | 18/8/2026 | 1/10/2026 | The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the… | |
| Pendiente de análisis | Media (6) | 0.72% | — | Python StringprepAIPython IdnaAI | 18/8/2026 | 1/10/2026 | The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of… | |
| Analizada | Alta (8.7) | 0.92% | — | Gitpython Project Gitpython | 13/8/2026 | 3/9/2026 | GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or… | |
| Analizada | Alta (7.2) | 0.55% | — | Gitpython Project Gitpython | 13/8/2026 | 28/9/2026 | GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process… | |
| Analizada | Alta (7.7) | 0.83% | — | Gitpython Project Gitpython | 13/8/2026 | 3/9/2026 | GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the… | |
| Analizada | Alta (8.7) | 0.51% | — | Gitpython Project Gitpython | 13/8/2026 | 3/9/2026 | GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that are expanded into .git/config and… | |
| Analizada | Media (5.3) | 0.36% | — | Gitpython Project Gitpython | 13/8/2026 | 3/9/2026 | GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application… | |
| Analizada | Alta (7.2) | 0.57% | — | Gitpython Project Gitpython | 13/8/2026 | 3/9/2026 | GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band. | |
| Analizada | Alta (7.1) | 0.41% | — | Gitpython Project Gitpython | 13/8/2026 | 3/9/2026 | GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive. | |
| Pendiente de análisis | Alta (8.1) | 0.50% | — | Snowflake Python APIAI | 12/8/2026 | 8/9/2026 | Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `&`/`#`/`=`… | |
| Pendiente de análisis | Media (4.8) | 0.30% | — | Python TablibAI | 12/8/2026 | 24/9/2026 | tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated unsanitized into HTML output via the export_book method in the _html.py format… | |
| Pendiente de análisis | Alta (7.5) | 0.49% | — | Python-socketioAI | 11/8/2026 | 10/9/2026 | python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to version 5.16.4, an… | |
| Aplazada | Alta (7.5) | 0.49% | — | Python-engineioAI | 11/8/2026 | 18/9/2026 | python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advantage of these to… | |
| Aplazada | Alta (7.5) | 0.57% | — | Python-engineioAI | 11/8/2026 | 18/9/2026 | python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is received, and when… | |
| Pendiente de análisis | Alta (7.7) | 0.43% | — | Microsoft PythonAIAnysphere CursorAI | 11/8/2026 | 9/9/2026 | Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper that the Microsoft Python extension invokes outside the sandbox, allowing arbitrary host commands… | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Python | 11/8/2026 | 22/8/2026 | Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally. | |
| Pendiente de análisis | Baja (2.4) | 0.12% | — | Python CSVAI | 10/8/2026 | 18/8/2026 | Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff(). | |
| Pendiente de análisis | Alta (8.7) | 0.25% | — | Python-cryptographyAI | 3/8/2026 | 10/9/2026 | python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an… | |
| Pendiente de análisis | Media (6.9) | 0.31% | — | Python-cryptographyAI | 3/8/2026 | 10/9/2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier… | |
| Analizada | Alta (7.3) | 0.27% | — | Gitpython Project Gitpython | 3/8/2026 | 16/9/2026 | GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from… | |
| Analizada | Alta (7.3) | 0.25% | — | Gitpython Project Gitpython | 1/8/2026 | 16/9/2026 | GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote… | |
| Analizada | Alta (8.7) | 2.2% | — | Gitpython Project Gitpython | 1/8/2026 | 3/9/2026 | GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes… | |
| Analizada | Crítica (9.3) | 0.64% | — | Gitpython Project Gitpython | 1/8/2026 | 3/9/2026 | GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can… | |
| Analizada | Alta (8.6) | 1.3% | — | Gitpython Project Gitpython | 1/8/2026 | 3/9/2026 | GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for… | |
| Analizada | Alta (8.7) | 0.33% | — | Gitpython Project Gitpython | 1/8/2026 | 3/9/2026 | GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who controls the clone URL can embed $NAME or… |