Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"

Количество 673

Количество 673

github логотип

GHSA-46x4-9jmv-jc8p

около 3 лет назад

Django Access Restrictions Bypass

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3jqw-crqj-w8qw

почти 7 лет назад

Denial of service in django

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3f2c-jm6v-cr35

около 3 лет назад

Django DNS Rebinding Vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-37hp-765x-j95x

больше 6 лет назад

Django open redirect and possible XSS attack via user-supplied numeric redirect URLs

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-337x-4q8g-prc5

больше 6 лет назад

Improper Input Validation in Django

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hrw-hx67-34x6

больше 2 лет назад

Resource exhaustion in Django

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2gwj-7jmv-h26r

около 3 лет назад

SQL Injection in Django

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2f9x-5v75-3qv4

больше 6 лет назад

Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-296w-6qhq-gf92

около 3 лет назад

Django denial of service via file upload naming

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2655-q453-22f9

около 3 лет назад

Django Allows Arbitrary URL Generation

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-32873

около 1 месяца назад

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-32873

около 1 месяца назад

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-32873

около 1 месяца назад

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-32873

около 1 месяца назад

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-53908

7 месяцев назад

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2024-53908

7 месяцев назад

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2024-53908

7 месяцев назад

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-53908

7 месяцев назад

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2024-45231

8 месяцев назад

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2024-45231

10 месяцев назад

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).

CVSS3: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-46x4-9jmv-jc8p

Django Access Restrictions Bypass

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3jqw-crqj-w8qw

Denial of service in django

CVSS3: 7.5
2%
Низкий
почти 7 лет назад
github логотип
GHSA-3f2c-jm6v-cr35

Django DNS Rebinding Vulnerability

CVSS3: 8.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-37hp-765x-j95x

Django open redirect and possible XSS attack via user-supplied numeric redirect URLs

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
github логотип
GHSA-337x-4q8g-prc5

Improper Input Validation in Django

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
github логотип
GHSA-2hrw-hx67-34x6

Resource exhaustion in Django

CVSS3: 7.5
16%
Средний
больше 2 лет назад
github логотип
GHSA-2gwj-7jmv-h26r

SQL Injection in Django

CVSS3: 9.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-2f9x-5v75-3qv4

Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters

CVSS3: 5.3
2%
Низкий
больше 6 лет назад
github логотип
GHSA-296w-6qhq-gf92

Django denial of service via file upload naming

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2655-q453-22f9

Django Allows Arbitrary URL Generation

CVSS3: 7.5
4%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2025-32873

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2025-32873

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-32873

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-32873

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, ...

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2024-53908

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)

CVSS3: 9.8
0%
Низкий
7 месяцев назад
redhat логотип
CVE-2024-53908

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)

CVSS3: 9.1
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2024-53908

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)

CVSS3: 9.8
0%
Низкий
7 месяцев назад
debian логотип
CVE-2024-53908

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, ...

CVSS3: 9.8
0%
Низкий
7 месяцев назад
ubuntu логотип
CVE-2024-45231

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).

CVSS3: 5.3
0%
Низкий
8 месяцев назад
redhat логотип
CVE-2024-45231

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).

CVSS3: 3.7
0%
Низкий
10 месяцев назад

Уязвимостей на страницу