Vulnerabilities

Summary — last 7 days

New vulnerabilities2,541▼ 407 vs. last week
Critical / high1,311▲ 28 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)59▼ 467 vs. last week
–

1 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedCritical (9.8)4.4%—Python Jw.util5/22/20206/17/2026
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resulting in OS command execution, because safe_load is not used.