Количество 921
Количество 921
GHSA-54qj-48vx-cr9f
Django Cross-site scripting (XSS) vulnerability
GHSA-53qw-q765-4fww
Denial-of-service in Django
GHSA-4rrr-2h4v-f3j9
Django has Inefficient Algorithmic Complexity
GHSA-4mq2-gc4j-cmw6
Django Template Engine Vulnerable to XSS
GHSA-4c42-4rxm-x6qf
Django Denial of Service Vulnerability in the authentication framework
GHSA-4894-5vqc-6r2r
Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget
GHSA-46x4-9jmv-jc8p
Django Access Restrictions Bypass
GHSA-3jqw-crqj-w8qw
Denial of service in django
GHSA-3h9f-r86x-qvjx
Django: cache middleware may expose private responses when unrelated request cookies are present
GHSA-3f2c-jm6v-cr35
Django DNS Rebinding Vulnerability
GHSA-37hp-765x-j95x
Django open redirect and possible XSS attack via user-supplied numeric redirect URLs
GHSA-33mw-q7rj-mjwj
Django has Inefficient Algorithmic Complexity
GHSA-337x-4q8g-prc5
Improper Input Validation in Django
GHSA-2mcm-79hx-8fxw
Django has Observable Timing Discrepancy
GHSA-2hrw-hx67-34x6
Resource exhaustion in Django
GHSA-2gwj-7jmv-h26r
SQL Injection in Django
GHSA-2f9x-5v75-3qv4
Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters
GHSA-2f9m-qhxg-w5v5
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since request data is limited by the `DATA_UPLOAD_MAX_MEMORY_SIZE` setting (default 2.5 MB) and the cache holds a fixed maximum number of entries. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Jaeyoung Jang for reporting this issue.
GHSA-296w-6qhq-gf92
Django denial of service via file upload naming
GHSA-2655-q453-22f9
Django Allows Arbitrary URL Generation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-54qj-48vx-cr9f Django Cross-site scripting (XSS) vulnerability | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-53qw-q765-4fww Denial-of-service in Django | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-4rrr-2h4v-f3j9 Django has Inefficient Algorithmic Complexity | 1% Низкий | 7 месяцев назад | ||
GHSA-4mq2-gc4j-cmw6 Django Template Engine Vulnerable to XSS | CVSS3: 9.3 | 0% Низкий | больше 2 лет назад | |
GHSA-4c42-4rxm-x6qf Django Denial of Service Vulnerability in the authentication framework | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-4894-5vqc-6r2r Django cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget | CVSS3: 6.1 | 3% Низкий | больше 4 лет назад | |
GHSA-46x4-9jmv-jc8p Django Access Restrictions Bypass | CVSS3: 5.5 | 2% Низкий | больше 4 лет назад | |
GHSA-3jqw-crqj-w8qw Denial of service in django | CVSS3: 7.5 | 3% Низкий | около 8 лет назад | |
GHSA-3h9f-r86x-qvjx Django: cache middleware may expose private responses when unrelated request cookies are present | CVSS3: 3.1 | 0% Низкий | 2 месяца назад | |
GHSA-3f2c-jm6v-cr35 Django DNS Rebinding Vulnerability | CVSS3: 8.1 | 6% Низкий | больше 4 лет назад | |
GHSA-37hp-765x-j95x Django open redirect and possible XSS attack via user-supplied numeric redirect URLs | CVSS3: 6.1 | 2% Низкий | больше 7 лет назад | |
GHSA-33mw-q7rj-mjwj Django has Inefficient Algorithmic Complexity | 1% Низкий | 7 месяцев назад | ||
GHSA-337x-4q8g-prc5 Improper Input Validation in Django | CVSS3: 6.5 | 3% Низкий | больше 7 лет назад | |
GHSA-2mcm-79hx-8fxw Django has Observable Timing Discrepancy | 1% Низкий | 7 месяцев назад | ||
GHSA-2hrw-hx67-34x6 Resource exhaustion in Django | CVSS3: 7.5 | 63% Средний | больше 3 лет назад | |
GHSA-2gwj-7jmv-h26r SQL Injection in Django | CVSS3: 9.8 | 19% Средний | больше 4 лет назад | |
GHSA-2f9x-5v75-3qv4 Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters | CVSS3: 5.3 | 4% Низкий | больше 7 лет назад | |
GHSA-2f9m-qhxg-w5v5 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since request data is limited by the `DATA_UPLOAD_MAX_MEMORY_SIZE` setting (default 2.5 MB) and the cache holds a fixed maximum number of entries. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Jaeyoung Jang for reporting this issue. | CVSS3: 5.3 | 1% Низкий | около 1 месяца назад | |
GHSA-296w-6qhq-gf92 Django denial of service via file upload naming | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-2655-q453-22f9 Django Allows Arbitrary URL Generation | CVSS3: 7.5 | 4% Низкий | больше 4 лет назад |
Уязвимостей на страницу