Количество 900
Количество 900
GHSA-fxpg-gg9g-76gj
Cross-site scripting in django
GHSA-fwr5-q9rx-294f
Improper query string handling in Django
GHSA-frmv-pr5f-9mcr
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
GHSA-fp6p-5xvw-m74f
Django User Enumeration Vulnerability
GHSA-f7cm-ccfp-3q4r
Django Incorrectly Validates URLs
GHSA-f6f8-9mx6-9mx2
Django vulnerable to Denial of Service
GHSA-crhm-qpjc-cm64
Django CSRF Protection Bypass
GHSA-crhf-3pfg-w68w
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.
GHSA-cqf7-ff9h-7967
Django ReDoS in validators.URLValidator
GHSA-c8c8-9472-w52h
Django Cross-site scripting Vulnerability
GHSA-c4qh-4vgv-qc6g
Django Denial-of-service in django.utils.text.Truncator
GHSA-9xg7-gg9m-rmq9
Django Admin Media Handler Vulnerable to Directory Traversal
GHSA-9v8h-57gv-qch6
Django vulnerable to Denial of Service via i18n middleware component
GHSA-9r8w-6x8c-6jr9
Django vulnerable to XSS on 500 pages
GHSA-9jmf-237g-qf46
Django Path Traversal vulnerability
GHSA-9cwg-mhxf-hh59
Django cross-site scripting (XSS) vulnerability via is_safe_url function
GHSA-95rw-fx8r-36v6
Cross-site Scripting in Django
GHSA-933h-hp56-hf7m
Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
GHSA-923m-gv2p-w5qp
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Navid Rezazadeh for reporting this issue.
GHSA-8x94-hmjh-97hq
Django vulnerable to Reflected File Download attack
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-fxpg-gg9g-76gj Cross-site scripting in django | CVSS3: 6.1 | 2% Низкий | около 8 лет назад | |
GHSA-fwr5-q9rx-294f Improper query string handling in Django | CVSS3: 6.5 | 2% Низкий | около 8 лет назад | |
GHSA-frmv-pr5f-9mcr Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects. | CVSS3: 9.1 | 19% Средний | 9 месяцев назад | |
GHSA-fp6p-5xvw-m74f Django User Enumeration Vulnerability | CVSS3: 3.1 | 3% Низкий | около 4 лет назад | |
GHSA-f7cm-ccfp-3q4r Django Incorrectly Validates URLs | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-f6f8-9mx6-9mx2 Django vulnerable to Denial of Service | CVSS3: 7.5 | 29% Средний | около 2 лет назад | |
GHSA-crhm-qpjc-cm64 Django CSRF Protection Bypass | CVSS3: 7.5 | 6% Низкий | около 4 лет назад | |
GHSA-crhf-3pfg-w68w An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue. | CVSS3: 4.8 | 0% Низкий | 24 дня назад | |
GHSA-cqf7-ff9h-7967 Django ReDoS in validators.URLValidator | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-c8c8-9472-w52h Django Cross-site scripting Vulnerability | CVSS3: 6.1 | 6% Низкий | около 4 лет назад | |
GHSA-c4qh-4vgv-qc6g Django Denial-of-service in django.utils.text.Truncator | CVSS3: 7.5 | 4% Низкий | почти 7 лет назад | |
GHSA-9xg7-gg9m-rmq9 Django Admin Media Handler Vulnerable to Directory Traversal | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-9v8h-57gv-qch6 Django vulnerable to Denial of Service via i18n middleware component | CVSS3: 5.9 | 2% Низкий | около 4 лет назад | |
GHSA-9r8w-6x8c-6jr9 Django vulnerable to XSS on 500 pages | CVSS3: 6.1 | 24% Средний | больше 7 лет назад | |
GHSA-9jmf-237g-qf46 Django Path Traversal vulnerability | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
GHSA-9cwg-mhxf-hh59 Django cross-site scripting (XSS) vulnerability via is_safe_url function | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-95rw-fx8r-36v6 Cross-site Scripting in Django | CVSS3: 6.1 | 3% Низкий | больше 4 лет назад | |
GHSA-933h-hp56-hf7m Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
GHSA-923m-gv2p-w5qp An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Navid Rezazadeh for reporting this issue. | CVSS3: 3.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-8x94-hmjh-97hq Django vulnerable to Reflected File Download attack | CVSS3: 8.8 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу