Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 113

Количество 1 113

oracle-oval логотип

ELSA-2020-3911

почти 6 лет назад

ELSA-2020-3911: python security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-4884

почти 7 лет назад

ELSA-2019-4884: python security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-4877

почти 7 лет назад

ELSA-2019-4877: python security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-4876

почти 7 лет назад

ELSA-2019-4876: python security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2017-1868

около 9 лет назад

ELSA-2017-1868: python security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2016-2586

почти 10 лет назад

ELSA-2016-2586: python security, bug fix, and enhancement update (LOW)

EPSS: Средний
oracle-oval логотип

ELSA-2013-1582

почти 13 лет назад

ELSA-2013-1582: python security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2026-7210

5 месяцев назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-7210

5 месяцев назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-7210

5 месяцев назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-7210

5 месяцев назад

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entro ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-6019

5 месяцев назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2026-6019

5 месяцев назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2026-6019

5 месяцев назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2026-6019

5 месяцев назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2026-4519

6 месяцев назад

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2026-4519

6 месяцев назад

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-4519

6 месяцев назад

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

CVSS3: 3.3
EPSS: Низкий
debian логотип

CVE-2026-4519

6 месяцев назад

The webbrowser.open() API would accept leading dashes in the URL which ...

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2026-4360

3 месяца назад

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2020-3911

ELSA-2020-3911: python security update (MODERATE)

5%
Низкий
почти 6 лет назад
oracle-oval логотип
ELSA-2019-4884

ELSA-2019-4884: python security update (IMPORTANT)

4%
Низкий
почти 7 лет назад
oracle-oval логотип
ELSA-2019-4877

ELSA-2019-4877: python security update (IMPORTANT)

4%
Низкий
почти 7 лет назад
oracle-oval логотип
ELSA-2019-4876

ELSA-2019-4876: python security update (IMPORTANT)

4%
Низкий
почти 7 лет назад
oracle-oval логотип
ELSA-2017-1868

ELSA-2017-1868: python security and bug fix update (MODERATE)

3%
Низкий
около 9 лет назад
oracle-oval логотип
ELSA-2016-2586

ELSA-2016-2586: python security, bug fix, and enhancement update (LOW)

25%
Средний
почти 10 лет назад
oracle-oval логотип
ELSA-2013-1582

ELSA-2013-1582: python security, bug fix, and enhancement update (MODERATE)

5%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2026-7210

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-7210

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

CVSS3: 5.3
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-7210

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
debian логотип
CVE-2026-7210

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entro ...

CVSS3: 7.5
1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-6019

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

CVSS3: 6.1
1%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-6019

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

CVSS3: 6.8
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-6019

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

CVSS3: 6.1
1%
Низкий
5 месяцев назад
debian логотип
CVE-2026-6019

http.cookies.Morsel.js_output() returns an inline <script> snippet and ...

CVSS3: 6.1
1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-4519

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

CVSS3: 3.3
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-4519

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

CVSS3: 7.1
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-4519

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

CVSS3: 3.3
0%
Низкий
6 месяцев назад
debian логотип
CVE-2026-4519

The webbrowser.open() API would accept leading dashes in the URL which ...

CVSS3: 3.3
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-4360

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5.3
0%
Низкий
3 месяца назад

Уязвимостей на страницу