Количество 921
Количество 921
SUSE-SU-2025:01523-1
Security update for python-Django
SUSE-SU-2025:0149-1
Security update for python-Django
SUSE-SU-2024:3187-1
Security update for python-Django
SUSE-SU-2024:2861-1
Security update for python-Django
SUSE-SU-2024:0902-1
Security update for python-Django
GHSA-xxj9-f6rv-m3x4
Django denial-of-service attack in the intcomma template filter
GHSA-xpfp-f569-q3p2
SQL Injection in Django
GHSA-xgxc-v2qg-chmh
Directory Traversal in Django
GHSA-x88j-93vc-wpmp
Session manipulation in Django
GHSA-x7q2-wr7g-xqmf
Django vulnerable to user enumeration attack
GHSA-x38m-486c-2wr9
Denial-of-service possibility in logout() view by filling session store
GHSA-wxg3-mfph-qg9w
Django Might Allow CSRF Requests via URL Verification
GHSA-wvqv-fj8w-qmhm
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter submitted through the Django admin changelist query string by a staff user with view permission. A `dict`, or a `str` holding its JSON representation, is opened in write mode regardless of the constructor's `write=False` default, allowing a file with an attacker-chosen name and contents to be written through a file-backed GDAL driver. Any other `str` is treated as a datasource, allowing an outbound network request through a GDAL virtual filesystem handler. Writing a file to a location later imported by the application can result in remote code execution. Earlier, unsupported Django series (such...
GHSA-wqjj-hx84-v449
Django Vulnerable to MySQL Injection
GHSA-wqfg-m96j-85vm
Django Potential Denial of Service (DoS) on Windows
GHSA-wh4h-v3f2-r2pp
Uncontrolled Memory Consumption in Django
GHSA-w26r-rmm8-9c29
Django has an Improper Handling of Length Parameter Inconsistency
GHSA-w24h-v9qh-8gxj
SQL Injection in Django
GHSA-vrcr-9hj9-jcg6
Django is vulnerable to DoS via XML serializer text extraction
GHSA-vq3h-3q7v-9prw
Django Allows Open Redirects
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
SUSE-SU-2025:01523-1 Security update for python-Django | 14% Средний | больше 1 года назад | ||
SUSE-SU-2025:0149-1 Security update for python-Django | 2% Низкий | больше 1 года назад | ||
SUSE-SU-2024:3187-1 Security update for python-Django | 26% Средний | около 2 лет назад | ||
SUSE-SU-2024:2861-1 Security update for python-Django | 1% Низкий | около 2 лет назад | ||
SUSE-SU-2024:0902-1 Security update for python-Django | 2% Низкий | больше 2 лет назад | ||
GHSA-xxj9-f6rv-m3x4 Django denial-of-service attack in the intcomma template filter | CVSS3: 5.9 | 2% Низкий | больше 2 лет назад | |
GHSA-xpfp-f569-q3p2 SQL Injection in Django | CVSS3: 9.8 | 44% Средний | почти 5 лет назад | |
GHSA-xgxc-v2qg-chmh Directory Traversal in Django | CVSS3: 5.3 | 4% Низкий | больше 5 лет назад | |
GHSA-x88j-93vc-wpmp Session manipulation in Django | CVSS3: 4 | 2% Низкий | около 8 лет назад | |
GHSA-x7q2-wr7g-xqmf Django vulnerable to user enumeration attack | CVSS3: 5.3 | 1% Низкий | около 2 лет назад | |
GHSA-x38m-486c-2wr9 Denial-of-service possibility in logout() view by filling session store | CVSS3: 7.5 | 5% Низкий | больше 4 лет назад | |
GHSA-wxg3-mfph-qg9w Django Might Allow CSRF Requests via URL Verification | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-wvqv-fj8w-qmhm An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter submitted through the Django admin changelist query string by a staff user with view permission. A `dict`, or a `str` holding its JSON representation, is opened in write mode regardless of the constructor's `write=False` default, allowing a file with an attacker-chosen name and contents to be written through a file-backed GDAL driver. Any other `str` is treated as a datasource, allowing an outbound network request through a GDAL virtual filesystem handler. Writing a file to a location later imported by the application can result in remote code execution. Earlier, unsupported Django series (such... | CVSS3: 8.8 | 1% Низкий | около 1 месяца назад | |
GHSA-wqjj-hx84-v449 Django Vulnerable to MySQL Injection | CVSS3: 9.8 | 5% Низкий | больше 4 лет назад | |
GHSA-wqfg-m96j-85vm Django Potential Denial of Service (DoS) on Windows | CVSS3: 5.8 | 1% Низкий | больше 1 года назад | |
GHSA-wh4h-v3f2-r2pp Uncontrolled Memory Consumption in Django | CVSS3: 7.5 | 5% Низкий | больше 7 лет назад | |
GHSA-w26r-rmm8-9c29 Django has an Improper Handling of Length Parameter Inconsistency | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
GHSA-w24h-v9qh-8gxj SQL Injection in Django | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-vrcr-9hj9-jcg6 Django is vulnerable to DoS via XML serializer text extraction | 2% Низкий | 10 месяцев назад | ||
GHSA-vq3h-3q7v-9prw Django Allows Open Redirects | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад |
Уязвимостей на страницу