Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"
Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

4.25.05.15.22023202420252026202720282029

Недавние уязвимости Django

Количество 679

github логотип

GHSA-2m34-jcjv-45xf

около 5 лет назад

XSS in Django

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-wpjr-j57x-wxfw

около 5 лет назад

Data leakage via cache key collision in Django

CVSS3: 5.9
EPSS: Средний
github логотип

GHSA-3gh2-xw74-jmcw

около 5 лет назад

SQL injection in Django

CVSS3: 8.8
EPSS: Средний
nvd логотип

CVE-2020-13596

около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-13596

около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0 ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-13254

около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.

CVSS3: 5.9
EPSS: Средний
debian логотип

CVE-2020-13254

около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0 ...

CVSS3: 5.9
EPSS: Средний
ubuntu логотип

CVE-2020-13254

около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.

CVSS3: 5.9
EPSS: Средний
ubuntu логотип

CVE-2020-13596

около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2020-13596

около 5 лет назад

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-2m34-jcjv-45xf

XSS in Django

CVSS3: 6.1
1%
Низкий
около 5 лет назад
github логотип
GHSA-wpjr-j57x-wxfw

Data leakage via cache key collision in Django

CVSS3: 5.9
11%
Средний
около 5 лет назад
github логотип
GHSA-3gh2-xw74-jmcw

SQL injection in Django

CVSS3: 8.8
59%
Средний
около 5 лет назад
nvd логотип
CVE-2020-13596

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.1
1%
Низкий
около 5 лет назад
debian логотип
CVE-2020-13596

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0 ...

CVSS3: 6.1
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-13254

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.

CVSS3: 5.9
11%
Средний
около 5 лет назад
debian логотип
CVE-2020-13254

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0 ...

CVSS3: 5.9
11%
Средний
около 5 лет назад
ubuntu логотип
CVE-2020-13254

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.

CVSS3: 5.9
11%
Средний
около 5 лет назад
ubuntu логотип
CVE-2020-13596

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.1
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-13596

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

CVSS3: 6.5
1%
Низкий
около 5 лет назад

Уязвимостей на страницу


Поделиться