Количество 900
Количество 900
GHSA-mm6v-q8q9-pgcf
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
GHSA-mjgh-79qc-68w3
Django has a Race Condition vulnerability
GHSA-m9g8-fxxm-xg86
Django SQL injection in HasKey(lhs, rhs) on Oracle
GHSA-jrh2-hc4r-7jwx
Directory-traversal in Django
GHSA-jhjg-w2cp-5j44
Django DoS in django.views.static.serve
GHSA-jh75-99hh-qvx9
Django memory consumption vulnerability
GHSA-jh3w-4vvf-mjgr
Django has regular expression denial of service vulnerability in EmailValidator/URLValidator
GHSA-j3j3-jrfh-cm2w
Django Denial-of-service possibility with strip_tags
GHSA-hvmf-r92r-27hr
Django allows unintended model editing
GHSA-hpr9-3m2g-3j9p
Django vulnerable to SQL injection in column aliases
GHSA-hmr4-m2h5-33qx
SQL injection in Django
GHSA-h95j-h2rv-qrg4
Django Cross-Site Request Forgery vulnerability
GHSA-h8gc-pgj2-vjm3
Django Denial-of-service in django.utils.text.Truncator
GHSA-h7pc-vwp9-298g
An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Peng Zhou for reporting this issue.
GHSA-h5jv-4p7w-64jg
Django Denial-of-service in strip_tags()
GHSA-h582-2pch-3xv3
Django Denial-of-service by filling session store
GHSA-h4hv-m4h4-mhwg
Django open redirect
GHSA-gvg8-93h5-g6qq
Django has an SQL Injection issue
GHSA-gv98-g628-m9x5
Django Cross-site Scripting Vulnerability
GHSA-g8xg-jgj6-49r3
Django is vulnerable to Denial of Service attack in formset
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-mm6v-q8q9-pgcf Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake | CVSS3: 3.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-mjgh-79qc-68w3 Django has a Race Condition vulnerability | CVSS3: 3.7 | 0% Низкий | 5 месяцев назад | |
GHSA-m9g8-fxxm-xg86 Django SQL injection in HasKey(lhs, rhs) on Oracle | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
GHSA-jrh2-hc4r-7jwx Directory-traversal in Django | CVSS3: 5.3 | 2% Низкий | больше 4 лет назад | |
GHSA-jhjg-w2cp-5j44 Django DoS in django.views.static.serve | CVSS3: 7.5 | 4% Низкий | около 4 лет назад | |
GHSA-jh75-99hh-qvx9 Django memory consumption vulnerability | CVSS3: 5.3 | 1% Низкий | почти 2 года назад | |
GHSA-jh3w-4vvf-mjgr Django has regular expression denial of service vulnerability in EmailValidator/URLValidator | CVSS3: 7.5 | 3% Низкий | около 3 лет назад | |
GHSA-j3j3-jrfh-cm2w Django Denial-of-service possibility with strip_tags | CVSS3: 7.5 | 5% Низкий | около 4 лет назад | |
GHSA-hvmf-r92r-27hr Django allows unintended model editing | CVSS3: 6.5 | 2% Низкий | больше 6 лет назад | |
GHSA-hpr9-3m2g-3j9p Django vulnerable to SQL injection in column aliases | CVSS3: 7.1 | 1% Низкий | 10 месяцев назад | |
GHSA-hmr4-m2h5-33qx SQL injection in Django | CVSS3: 9.8 | 65% Средний | больше 6 лет назад | |
GHSA-h95j-h2rv-qrg4 Django Cross-Site Request Forgery vulnerability | CVSS3: 7.5 | 1% Низкий | около 8 лет назад | |
GHSA-h8gc-pgj2-vjm3 Django Denial-of-service in django.utils.text.Truncator | CVSS3: 5.9 | 1% Низкий | больше 2 лет назад | |
GHSA-h7pc-vwp9-298g An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Peng Zhou for reporting this issue. | CVSS3: 3.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-h5jv-4p7w-64jg Django Denial-of-service in strip_tags() | CVSS3: 7.5 | 3% Низкий | почти 7 лет назад | |
GHSA-h582-2pch-3xv3 Django Denial-of-service by filling session store | CVSS3: 7.5 | 7% Низкий | около 7 лет назад | |
GHSA-h4hv-m4h4-mhwg Django open redirect | CVSS3: 6.1 | 2% Низкий | больше 7 лет назад | |
GHSA-gvg8-93h5-g6qq Django has an SQL Injection issue | 1% Низкий | 6 месяцев назад | ||
GHSA-gv98-g628-m9x5 Django Cross-site Scripting Vulnerability | CVSS3: 6.1 | 3% Низкий | около 4 лет назад | |
GHSA-g8xg-jgj6-49r3 Django is vulnerable to Denial of Service attack in formset | CVSS3: 5.3 | 3% Низкий | около 4 лет назад |
Уязвимостей на страницу