Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 392 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.24% | — | Erdogant Pypickle | 26/5/2025 | 17/6/2026 | A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the function Save of the file pypickle/pypickle.py. The manipulation leads to improper authorization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Upgrading… | |
| Analizada | Media (4.8) | 0.32% | — | Erdogant Pypickle | 26/5/2025 | 17/6/2026 | A vulnerability was found in erdogant pypickle up to 1.1.5 and classified as problematic. Affected by this issue is the function load of the file pypickle/pypickle.py. The manipulation leads to deserialization. Local access is required to approach this attack. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (7.5) | 0.41% | — | Bandoche Pypinksign | 16/11/2023 | 9/7/2026 | PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications. | |
| Modificada | Crítica (9.8) | 1.5% | — | Pypi | 22/7/2022 | 17/6/2026 | The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party. | |
| Modificada | Crítica (9.8) | 1.5% | — | Pypi | 22/7/2022 | 17/6/2026 | The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Watertools | 24/6/2022 | 17/6/2026 | The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Drxhello | 24/6/2022 | 17/6/2026 | The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Perdido | 24/6/2022 | 17/6/2026 | The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Dr-web-engine | 24/6/2022 | 17/6/2026 | The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Beginner | 24/6/2022 | 17/6/2026 | The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Watools | 24/6/2022 | 17/6/2026 | The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Explore | 24/6/2022 | 17/6/2026 | The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Aamiles | 24/6/2022 | 17/6/2026 | The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Ml-scanner | 24/6/2022 | 17/6/2026 | The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Cloudlabeling | 24/6/2022 | 17/6/2026 | The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Cryptoasset-data-downloader | 24/6/2022 | 17/6/2026 | The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Rootinteractive | 24/6/2022 | 17/6/2026 | The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Django-navbar-client | 24/6/2022 | 17/6/2026 | The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.3% | — | Python Pypi | 8/5/2022 | 17/6/2026 | marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor. | |
| Modificada | Alta (7.8) | 1.1% | — | Pypi Bsdiff4 | 22/7/2020 | 17/6/2026 | A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file. | |
| Modificada | Media (6.1) | 3.8% | — | Python Pypiserver | 25/1/2019 | 17/6/2026 | CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI. |