Количество 921
Количество 921
GHSA-qg2p-9jwr-mmqf
Django vulnerable to Denial of Service
GHSA-qcgg-j2x8-h9g8
Django has a potential denial-of-service vulnerability in IPv6 validation
GHSA-qc99-g3wm-hgxr
Django Arbitrary Code Execution
GHSA-q95w-c7qg-hrff
Django vulnerable to partial directory traversal via archives
GHSA-q7q2-qf2q-rw3w
Django Vulnerable to Cache Poisoning
GHSA-q5qw-4364-5hhm
Django Vulnerable to HTTP Response Splitting Attack
GHSA-q2jf-h9jm-m7p4
Django contains Uncontrolled Resource Consumption via cached header
GHSA-q238-5cxm-5c9h
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue.
GHSA-pwjp-ccjc-ghwg
Django vulnerable to privilege abuse in GenericInlineModelAdmin
GHSA-pw27-w7w4-9qc7
Django XSS Vulnerability
GHSA-pv4p-cwwg-4rph
Django SQL injection vulnerability
GHSA-pjc8-j97x-hp3p
** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module.
GHSA-pgxh-wfw4-jx2v
Django denial of service via empty session record creation
GHSA-p99v-5w3c-jqq9
Django Access Control Bypass possibly leading to SSRF, RFI, and LFI attacks
GHSA-p6m5-h7pp-v2x5
Django Regex Algorithmic Complexity Causes Denial of Service
GHSA-p64x-8rxx-wf6q
Django `Trunc()` and `Extract()` database functions vulnerable to SQL Injection
GHSA-p3fp-8748-vqfq
Django vulnerable to Allocation of Resources Without Limits or Throttling
GHSA-mwv2-398h-v489
Django Improper Access Control
GHSA-mwm9-4648-f68q
Django has an SQL Injection issue
GHSA-mvfq-ggxm-9mc5
Django vulnerable to ASGI header spoofing via underscore/hyphen conflation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-qg2p-9jwr-mmqf Django vulnerable to Denial of Service | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
GHSA-qcgg-j2x8-h9g8 Django has a potential denial-of-service vulnerability in IPv6 validation | CVSS3: 5.8 | 2% Низкий | больше 1 года назад | |
GHSA-qc99-g3wm-hgxr Django Arbitrary Code Execution | 2% Низкий | больше 4 лет назад | ||
GHSA-q95w-c7qg-hrff Django vulnerable to partial directory traversal via archives | CVSS3: 3.1 | 1% Низкий | 12 месяцев назад | |
GHSA-q7q2-qf2q-rw3w Django Vulnerable to Cache Poisoning | CVSS3: 7.4 | 3% Низкий | больше 4 лет назад | |
GHSA-q5qw-4364-5hhm Django Vulnerable to HTTP Response Splitting Attack | CVSS3: 7.5 | 4% Низкий | больше 4 лет назад | |
GHSA-q2jf-h9jm-m7p4 Django contains Uncontrolled Resource Consumption via cached header | CVSS3: 7.5 | 47% Средний | больше 3 лет назад | |
GHSA-q238-5cxm-5c9h An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue. | CVSS3: 5.3 | 1% Низкий | около 1 месяца назад | |
GHSA-pwjp-ccjc-ghwg Django vulnerable to privilege abuse in GenericInlineModelAdmin | 0% Низкий | 5 месяцев назад | ||
GHSA-pw27-w7w4-9qc7 Django XSS Vulnerability | CVSS3: 7.4 | 4% Низкий | больше 4 лет назад | |
GHSA-pv4p-cwwg-4rph Django SQL injection vulnerability | CVSS3: 9.1 | 2% Низкий | около 2 лет назад | |
GHSA-pjc8-j97x-hp3p ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module. | 1% Низкий | больше 4 лет назад | ||
GHSA-pgxh-wfw4-jx2v Django denial of service via empty session record creation | CVSS3: 7.5 | 5% Низкий | больше 4 лет назад | |
GHSA-p99v-5w3c-jqq9 Django Access Control Bypass possibly leading to SSRF, RFI, and LFI attacks | CVSS3: 7.5 | 5% Низкий | больше 5 лет назад | |
GHSA-p6m5-h7pp-v2x5 Django Regex Algorithmic Complexity Causes Denial of Service | CVSS3: 7.5 | 4% Низкий | больше 4 лет назад | |
GHSA-p64x-8rxx-wf6q Django `Trunc()` and `Extract()` database functions vulnerable to SQL Injection | CVSS3: 9.8 | 73% Высокий | около 4 лет назад | |
GHSA-p3fp-8748-vqfq Django vulnerable to Allocation of Resources Without Limits or Throttling | CVSS3: 5 | 1% Низкий | больше 1 года назад | |
GHSA-mwv2-398h-v489 Django Improper Access Control | 1% Низкий | больше 4 лет назад | ||
GHSA-mwm9-4648-f68q Django has an SQL Injection issue | 13% Средний | 7 месяцев назад | ||
GHSA-mvfq-ggxm-9mc5 Django vulnerable to ASGI header spoofing via underscore/hyphen conflation | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу