Gregory P. Smith (https://github.com/gpshead)
5 kredili kayıt · son 12 ayda 5 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2026-19445İstismar yok | Use-after-free of a server-side SSLContext when sni_callback switches contextspython software foundation · cpython · CWE-416 | Kritik9,2 | — | — | Bugün |
34İzleyin | CVE-2026-15308İstismar yok | Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarationspython · python · CWE-400 | Yüksek8,7 | — | %0,6 | 9 Tem 2026 |
27İzleyin | CVE-2026-7774İstismar yok | tarfile.data_filter path traversal bypass allows writing outside the extraction directorypython software foundation · cpython · CWE-22 | Orta6,9 | — | %0,8 | 4 Haz 2026 |
16İzleyin | CVE-2026-8643İstismar yok | pip can extract console_scripts and gui_scripts outside installation directorypypa · pip · CWE-22 | Orta4,1 | — | %0,5 | 1 Haz 2026 |
23İzleyin | CVE-2026-8328İstismar yok | FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host addresspython software foundation · cpython · CWE-918 | Orta5,9 | — | %0,7 | 13 May 2026 |
25İzleyin | CVE-2026-7210İstismar yok | The expat and elementtree parsers use insufficient entropy for XML hash-flooding protectionpython · python · CWE-331 | Orta6,3 | — | %1,4 | 11 May 2026 |
- CVE-2026-1944536İzleyin
Use-after-free of a server-side SSLContext when sni_callback switches contexts
KritikCVSS 9,2İstismar yokpython software foundation · cpythonBugün
- CVE-2026-1530834İzleyin
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
YüksekCVSS 8,7İstismar yokEPSS %1python · python9 Tem 2026
- CVE-2026-777427İzleyin
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
OrtaCVSS 6,9İstismar yokEPSS %1python software foundation · cpython4 Haz 2026
- CVE-2026-864316İzleyin
pip can extract console_scripts and gui_scripts outside installation directory
OrtaCVSS 4,1İstismar yokEPSS %0pypa · pip1 Haz 2026
- CVE-2026-832823İzleyin
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
OrtaCVSS 5,9İstismar yokEPSS %1python software foundation · cpython13 May 2026
- CVE-2026-721025İzleyin
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
OrtaCVSS 6,3İstismar yokEPSS %1python · python11 May 2026