Vulnerabilities
Summary — last 7 days
New vulnerabilities3,045▲ 455 vs. last week
Critical / high1,424▲ 188 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)389▲ 174 vs. last week
6 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.4) | 0.62% | — | Zope RestrictedpythonAI | 9/16/2026 | 9/16/2026 | RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the string.Formatter class, a Formatter… | |
| Deferred | High (8.3) | 0.40% | — | Zope RestrictedpythonAI | 7/8/2026 | 7/10/2026 | RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted positional-only arguments,… | |
| Deferred | High (7.9) | 0.40% | — | CpythonAIZope RestrictedpythonAI | 1/23/2025 | 6/17/2026 | RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Via a type confusion bug in versions of the CPython interpreter starting in 3.11 and prior to 3.13.2 when using `try/except*`, RestrictedPython starting in version 6.0 and… | |
| Analyzed | High (8.7) | 0.72% | — | Zope Restrictedpython | 9/30/2024 | 6/17/2026 | RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will be fixed in version 7.3. As a workaround, If the application does not require… | |
| Modified | High (7.7) | 0.68% | — | Zope Restrictedpython | 8/30/2023 | 6/17/2026 | RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling the format string to "read" all objects accessible through recursive attribute lookup and subscription from objects he can access. This can lead to critical information… | |
| Modified | Critical (9.9) | 0.85% | — | Zope Restrictedpython | 7/11/2023 | 6/17/2026 | RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environment. RestrictedPython does not check access to stack frames and their attributes. Stack frames are accessible within at least generators and generator expressions, which… |