Vulnerabilities

Summary — last 7 days

New vulnerabilities3,045▲ 455 vs. last week
Critical / high1,424▲ 188 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)389▲ 174 vs. last week
–

6 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.4)0.62%—Zope RestrictedpythonAI9/16/20269/16/2026
RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the string.Formatter class, a Formatter…
DeferredHigh (8.3)0.40%—Zope RestrictedpythonAI7/8/20267/10/2026
RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted positional-only arguments,…
DeferredHigh (7.9)0.40%—CpythonAIZope RestrictedpythonAI1/23/20256/17/2026
RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Via a type confusion bug in versions of the CPython interpreter starting in 3.11 and prior to 3.13.2 when using `try/except*`, RestrictedPython starting in version 6.0 and…
AnalyzedHigh (8.7)0.72%—Zope Restrictedpython9/30/20246/17/2026
RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will be fixed in version 7.3. As a workaround, If the application does not require…
ModifiedHigh (7.7)0.68%—Zope Restrictedpython8/30/20236/17/2026
RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling the format string to "read" all objects accessible through recursive attribute lookup and subscription from objects he can access. This can lead to critical information…
ModifiedCritical (9.9)0.85%—Zope Restrictedpython7/11/20236/17/2026
RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environment. RestrictedPython does not check access to stack frames and their attributes. Stack frames are accessible within at least generators and generator expressions, which…