Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.9) | 0.46% | — | Vyperlang VyperAI | 15/5/2025 | 17/6/2026 | Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, the `slice()` builtin can elide side effects when the output length is 0, and the source bytestring is a builtin (`msg.data` or `<address>.code`). The reason is that for these source locations, the… | |
| Aplazada | Baja (2.9) | 0.45% | — | Vyperlang VyperAI | 15/5/2025 | 17/6/2026 | Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `concat()` may skip evaluation of side effects when the length of an argument is zero. This is due to a fastpath in the implementation which skips evaluation of argument expressions when their length… | |
| Analizada | Baja (2.3) | 0.57% | — | Vyperlang Vyper | 21/2/2025 | 17/6/2026 | vyper is a Pythonic Smart Contract Language for the EVM. Vyper handles AugAssign statements by first caching the target location to avoid double evaluation. However, in the case when target is an access to a DynArray and the rhs modifies the array, the cached target will evaluate first, and the bounds check will not… | |
| Analizada | Baja (2.3) | 0.45% | — | Vyperlang Vyper | 21/2/2025 | 17/6/2026 | vyper is a Pythonic Smart Contract Language for the EVM. Multiple evaluation of a single expression is possible in the iterator target of a for loop. While the iterator expression cannot produce multiple writes, it can consume side effects produced in the loop body (e.g. read a storage variable updated in the loop… | |
| Analizada | Baja (2.3) | 0.33% | — | Vyperlang Vyper | 21/2/2025 | 17/6/2026 | vyper is a Pythonic Smart Contract Language for the EVM. Vyper `sqrt()` builtin uses the babylonian method to calculate square roots of decimals. Unfortunately, improper handling of the oscillating final states may lead to sqrt incorrectly returning rounded up results. This issue is being addressed and a fix is… | |
| Modificada | Baja (2.3) | 0.65% | — | Vyperlang Vyper | 14/1/2025 | 17/6/2026 | Vyper is a Pythonic Smart Contract Language for the EVM. When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), the success flag of the call is not checked. As a consequence an attacker can provide a specific amount of gas to make these calls fail but let the overall execution continue. Then… | |
| Analizada | Crítica (9.1) | 0.51% | — | Matter-labs Zkvyper | 15/8/2024 | 17/6/2026 | zkvyper is a Vyper compiler. Starting in version 1.3.12 and prior to version 1.5.3, since LLL IR has no Turing-incompletness restrictions, it is compiled to a loop with a much more late exit condition. It leads to a loss of funds or other unwanted behavior if the loop body contains it. However, more real-life use… | |
| Analizada | Media (5.3) | 0.46% | — | Vyperlang Vyper | 25/4/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `sqrt` builtin can result in double eval vulnerability when the argument has side-effects. It can be seen that the `build_IR` function of the `sqrt` builtin doesn't cache the argument to the stack. As… | |
| Analizada | Media (5.3) | 0.41% | — | Vyperlang Vyper | 25/4/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Prior to version 0.3.0, default functions don't respect nonreentrancy keys and the lock isn't emitted. No vulnerable production contracts were found. Additionally, using a lock on a `default` function is a very sparsely used pattern. As… | |
| Analizada | Media (5.3) | 0.46% | — | Vyperlang Vyper | 25/4/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `create_from_blueprint` builtin can result in a double eval vulnerability when `raw_args=True` and the `args` argument has side-effects. It can be seen that the `_build_create_IR` function of the… | |
| Analizada | Media (5.3) | 0.46% | — | Vyperlang Vyper | 25/4/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `slice` builtin can result in a double eval vulnerability when the buffer argument is either `msg.data`, `self.code` or `<address>.code` and either the `start` or `length` arguments have side-effects.… | |
| Analizada | Media (5.3) | 0.46% | — | Vyperlang Vyper | 25/4/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect values can be logged when `raw_log` builtin is called with memory or storage arguments to be used as topics. A contract search was performed and no vulnerable contracts were found in production. The… | |
| Analizada | Media (5.3) | 0.80% | — | Vyperlang Vyper | 25/4/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to version 0.4.0b1, when looping over a `range` of the form `range(start, start + N)`, if `start` is negative, the execution will always revert. This issue is caused by an incorrect assertion inserted by… | |
| Analizada | Media (5.3) | 0.55% | — | Vyperlang Vyper | 26/2/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified as the starting index for an array in `_abi_decode`, it can cause the read position to overflow. This results in the decoding of values outside the intended array bounds, potentially leading to… | |
| Analizada | Media (5.3) | 0.56% | — | Vyperlang Vyper | 26/2/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, start)`, if the `start` index provided has for side effect to update `b`, the byte array to extract `32` bytes from, it could be that some dirty memory is read and returned by `extract32`. This… | |
| Modificada | Crítica (9.8) | 1.5% | — | Vyperlang Vyper | 7/2/2024 | 17/6/2026 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, while they are defined for unsigned integers only. The typechecker doesn't throw when spotting the usage of an `int` as an index for an array. The typechecker allows the usage of signed integers to be… | |
| Modificada | Media (5.3) | 0.26% | — | Vyperlang Vyper | 5/2/2024 | 17/6/2026 | Vyper is a Pythonic Smart Contract Language for the EVM. There is an error in the stack management when compiling the `IR` for `sha3_64`. Concretely, the `height` variable is miscalculated. The vulnerability can't be triggered without writing the `IR` by hand (that is, it cannot be triggered from regular vyper code).… | |
| Modificada | Media (5.3) | 0.53% | — | Vyperlang Vyper | 2/2/2024 | 17/6/2026 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. When calls to external contracts are made, we write the input buffer starting at byte 28, and allocate the return buffer to start at byte 0 (overlapping with the input buffer). When checking RETURNDATASIZE for dynamic types, the size is… | |
| Modificada | Crítica (9.8) | 0.90% | — | Vyperlang Vyper | 1/2/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account for the ability for start + length to overflow when the values aren't literals. If a slice() function uses a non-literal argument for the start or length variable,… | |
| Modificada | Media (5.3) | 0.48% | — | Vyperlang Vyper | 30/1/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Vyper compiler allows passing a value in builtin raw_call even if the call is a delegatecall or a staticcall. But in the context of delegatecall and staticcall the handling of value is not possible due to the semantics of the respective… | |
| Modificada | Crítica (9.8) | 0.77% | — | Vyperlang Vyper | 18/1/2024 | 17/6/2026 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. The `concat` built-in can write over the bounds of the memory buffer that was allocated for it and thus overwrite existing valid data. The root cause is that the `build_IR` for `concat` doesn't properly adhere to the API of copy functions… | |
| Modificada | Alta (7.5) | 0.70% | — | Vyperlang Vyper | 13/12/2023 | 17/6/2026 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Contracts containing large arrays might underallocate the number of slots they need by 1. Prior to v0.3.8, the calculation to determine how many slots a storage variable needed used `math.ceil(type_.size_in_bytes / 32)`. The… | |
| Modificada | Media (5.3) | 0.56% | — | Matter-labs Zkvyper | 25/10/2023 | 17/6/2026 | era-compiler-vyper is the EraVM Vyper compiler for zkSync Era, a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to era-compiler-vype version 1.3.10, a bug prevented the initialization of the first immutable variable for Vyper contracts meeting certain criteria. The problem arises when there is… | |
| Modificada | Alta (7.5) | 0.67% | — | Vyperlang Vyper | 27/9/2023 | 17/6/2026 | Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is nested in an expression. Uses of `_abi_decode()` can be constructed which allow for bounds checking to be bypassed resulting in incorrect results. This issue has not yet been fixed, but a fix is… | |
| Modificada | Alta (8.1) | 0.83% | — | Vyperlang Vyper | 18/9/2023 | 17/6/2026 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In version 0.3.9 and prior, under certain conditions, the memory used by the builtins `raw_call`, `create_from_blueprint` and `create_copy_of` can be corrupted. For `raw_call`, the argument buffer of the call can be corrupted, leading… |