Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 900

Количество 900

debian логотип

CVE-2023-24580

больше 3 лет назад

An issue was discovered in the Multipart Request Parser in Django 3.2 ...

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2023-23969

больше 3 лет назад

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2023-23969

больше 3 лет назад

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2023-23969

больше 3 лет назад

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2023-23969

больше 3 лет назад

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, t ...

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2022-41323

почти 4 года назад

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-41323

почти 4 года назад

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-41323

почти 4 года назад

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-41323

почти 4 года назад

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, i ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-36359

почти 4 года назад

An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-36359

почти 4 года назад

An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-36359

почти 4 года назад

An issue was discovered in the HTTP FileResponse class in Django 3.2 b ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2022-34265

около 4 лет назад

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.

CVSS3: 9.8
EPSS: Высокий
redhat логотип

CVE-2022-34265

около 4 лет назад

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.

CVSS3: 9.8
EPSS: Высокий
nvd логотип

CVE-2022-34265

около 4 лет назад

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.

CVSS3: 9.8
EPSS: Высокий
debian логотип

CVE-2022-34265

около 4 лет назад

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0 ...

CVSS3: 9.8
EPSS: Высокий
ubuntu логотип

CVE-2022-28347

больше 4 лет назад

A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-28347

больше 4 лет назад

A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.

CVSS3: 9.4
EPSS: Низкий
nvd логотип

CVE-2022-28347

больше 4 лет назад

A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-28347

больше 4 лет назад

A SQL injection issue was discovered in QuerySet.explain() in Django 2 ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2023-24580

An issue was discovered in the Multipart Request Parser in Django 3.2 ...

CVSS3: 7.5
63%
Средний
больше 3 лет назад
ubuntu логотип
CVE-2023-23969

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.

CVSS3: 7.5
47%
Средний
больше 3 лет назад
redhat логотип
CVE-2023-23969

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.

CVSS3: 7.5
47%
Средний
больше 3 лет назад
nvd логотип
CVE-2023-23969

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.

CVSS3: 7.5
47%
Средний
больше 3 лет назад
debian логотип
CVE-2023-23969

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, t ...

CVSS3: 7.5
47%
Средний
больше 3 лет назад
ubuntu логотип
CVE-2022-41323

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

CVSS3: 7.5
3%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-41323

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

CVSS3: 7.5
3%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-41323

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

CVSS3: 7.5
3%
Низкий
почти 4 года назад
debian логотип
CVE-2022-41323

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, i ...

CVSS3: 7.5
3%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-36359

An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-36359

An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-36359

An issue was discovered in the HTTP FileResponse class in Django 3.2 b ...

CVSS3: 8.8
1%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-34265

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.

CVSS3: 9.8
73%
Высокий
около 4 лет назад
redhat логотип
CVE-2022-34265

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.

CVSS3: 9.8
73%
Высокий
около 4 лет назад
nvd логотип
CVE-2022-34265

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.

CVSS3: 9.8
73%
Высокий
около 4 лет назад
debian логотип
CVE-2022-34265

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0 ...

CVSS3: 9.8
73%
Высокий
около 4 лет назад
ubuntu логотип
CVE-2022-28347

A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28347

A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.

CVSS3: 9.4
3%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-28347

A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-28347

A SQL injection issue was discovered in QuerySet.explain() in Django 2 ...

CVSS3: 9.8
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу