Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"
Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

4.25.05.15.22023202420252026202720282029

Недавние уязвимости Django

Количество 673

github логотип

GHSA-9v8h-57gv-qch6

около 3 лет назад

Django vulnerable to Denial of Service via i18n middleware component

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-mwv2-398h-v489

около 3 лет назад

Django Improper Access Control

EPSS: Низкий
github логотип

GHSA-qc99-g3wm-hgxr

около 3 лет назад

Django Arbitrary Code Execution

EPSS: Низкий
github логотип

GHSA-w24h-v9qh-8gxj

около 3 лет назад

SQL Injection in Django

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2gwj-7jmv-h26r

около 3 лет назад

SQL Injection in Django

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-28347

около 3 лет назад

A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-28347

около 3 лет назад

A SQL injection issue was discovered in QuerySet.explain() in Django 2 ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-28346

около 3 лет назад

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-28346

около 3 лет назад

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13 ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2022-28346

около 3 лет назад

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-9v8h-57gv-qch6

Django vulnerable to Denial of Service via i18n middleware component

CVSS3: 5.9
2%
Низкий
около 3 лет назад
github логотип
GHSA-mwv2-398h-v489

Django Improper Access Control

1%
Низкий
около 3 лет назад
github логотип
GHSA-qc99-g3wm-hgxr

Django Arbitrary Code Execution

1%
Низкий
около 3 лет назад
github логотип
GHSA-w24h-v9qh-8gxj

SQL Injection in Django

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2gwj-7jmv-h26r

SQL Injection in Django

CVSS3: 9.8
2%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-28347

A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2022-28347

A SQL injection issue was discovered in QuerySet.explain() in Django 2 ...

CVSS3: 9.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-28346

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVSS3: 9.8
2%
Низкий
около 3 лет назад
debian логотип
CVE-2022-28346

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13 ...

CVSS3: 9.8
2%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-28346

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVSS3: 9.8
2%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться