Количество 900
Количество 900
GHSA-vjjp-9r83-22rc
Django Directory Traversal via ssi template tag
GHSA-vfq6-hq5r-27r6
Django Potential account hijack via password reset form
GHSA-v9qg-3j8p-r63v
Uncontrolled Recursion in Django
GHSA-v6rh-hp5x-86rv
Potential bypass of an upstream access control based on URL paths in Django
GHSA-rxjp-mfm9-w4wr
Path Traversal in Django
GHSA-rw75-m7gp-92m3
Django data leakage via querystring manipulation in admin
GHSA-rvq6-mrpv-m6rm
Code Injection in Django
GHSA-rrqc-c2jx-6jgv
Django allows enumeration of user e-mail addresses
GHSA-rqw2-ghq9-44m7
Django is vulnerable to SQL injection in column aliases
GHSA-rm2j-x595-q9cj
Django Vulnerable to Cache Poisoning
GHSA-rf4j-j272-fj86
Django vulnerable to information leakage in AuthenticationForm
GHSA-r836-hh6v-rg5g
Django vulnerable to denial-of-service attack
GHSA-r7w6-p47g-vj53
Django Data leakage via admin history log
GHSA-r5cj-wv24-92p5
Django cross-site request forgery (CSRF) vulnerability
GHSA-r3xc-prgr-mg9p
Django bypasses validation when using one form field to upload multiple files
GHSA-qw25-v68c-qjf3
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
GHSA-qrw5-5h28-6cmg
Django denial-of-service vulnerability in internationalized URLs
GHSA-qpc8-7fxc-cm4p
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Shai Berger for reporting this issue.
GHSA-qmf9-6jqf-j8fq
Django potential denial of service vulnerability in UsernameField on Windows
GHSA-qg2p-9jwr-mmqf
Django vulnerable to Denial of Service
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-vjjp-9r83-22rc Django Directory Traversal via ssi template tag | CVSS3: 8.6 | 3% Низкий | около 4 лет назад | |
GHSA-vfq6-hq5r-27r6 Django Potential account hijack via password reset form | CVSS3: 9.8 | 32% Средний | больше 6 лет назад | |
GHSA-v9qg-3j8p-r63v Uncontrolled Recursion in Django | CVSS3: 7.5 | 3% Низкий | почти 7 лет назад | |
GHSA-v6rh-hp5x-86rv Potential bypass of an upstream access control based on URL paths in Django | CVSS3: 7.3 | 2% Низкий | больше 4 лет назад | |
GHSA-rxjp-mfm9-w4wr Path Traversal in Django | CVSS3: 7.5 | 5% Низкий | около 5 лет назад | |
GHSA-rw75-m7gp-92m3 Django data leakage via querystring manipulation in admin | CVSS3: 5.3 | 2% Низкий | около 4 лет назад | |
GHSA-rvq6-mrpv-m6rm Code Injection in Django | CVSS3: 9.8 | 6% Низкий | около 4 лет назад | |
GHSA-rrqc-c2jx-6jgv Django allows enumeration of user e-mail addresses | CVSS3: 3.7 | 1% Низкий | почти 2 года назад | |
GHSA-rqw2-ghq9-44m7 Django is vulnerable to SQL injection in column aliases | CVSS3: 4.3 | 1% Низкий | 8 месяцев назад | |
GHSA-rm2j-x595-q9cj Django Vulnerable to Cache Poisoning | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-rf4j-j272-fj86 Django vulnerable to information leakage in AuthenticationForm | CVSS3: 7.5 | 5% Низкий | почти 8 лет назад | |
GHSA-r836-hh6v-rg5g Django vulnerable to denial-of-service attack | CVSS3: 5.3 | 1% Низкий | почти 2 года назад | |
GHSA-r7w6-p47g-vj53 Django Data leakage via admin history log | CVSS3: 4.3 | 2% Низкий | около 4 лет назад | |
GHSA-r5cj-wv24-92p5 Django cross-site request forgery (CSRF) vulnerability | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-r3xc-prgr-mg9p Django bypasses validation when using one form field to upload multiple files | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-qw25-v68c-qjf3 Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows | CVSS3: 7.5 | 2% Низкий | 9 месяцев назад | |
GHSA-qrw5-5h28-6cmg Django denial-of-service vulnerability in internationalized URLs | CVSS3: 7.5 | 3% Низкий | почти 4 года назад | |
GHSA-qpc8-7fxc-cm4p An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Shai Berger for reporting this issue. | CVSS3: 3.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-qmf9-6jqf-j8fq Django potential denial of service vulnerability in UsernameField on Windows | CVSS3: 7.5 | 50% Средний | больше 2 лет назад | |
GHSA-qg2p-9jwr-mmqf Django vulnerable to Denial of Service | CVSS3: 7.5 | 1% Низкий | около 2 лет назад |
Уязвимостей на страницу