Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | — | — | DjangoAI | 6/10/2026 | 6/10/2026 | An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.forms.models.BaseModelFormSet.save_existing_objects()` used the presence of a primary key on a submitted form's instance as evidence that the instance belonged to the formset's limiting queryset. An object outside that… | |
| Aplazada | Media (6.9) | — | — | DjangoAI | 6/10/2026 | 6/10/2026 | An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to make network requests via a crafted VRT document referencing an external raster… | |
| Aplazada | Media (6.9) | — | — | DjangoAI | 6/10/2026 | 6/10/2026 | An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request… | |
| Aplazada | Media (6.9) | — | — | DjangoAI | 6/10/2026 | 6/10/2026 | An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service attack when processing many distinct, very long language codes, which are retained as keys in an in-memory cache and… | |
| Aplazada | Media (5.5) | 0.29% | — | Lybbn Django VUE LyadminAI | 5/10/2026 | 6/10/2026 | A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is… | |
| Aplazada | Baja (2) | 0.25% | — | Django HaystackAI | 5/10/2026 | 6/10/2026 | A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag Handler. Such manipulation of the argument result_class leads to improper neutralization of directives in dynamically… | |
| Aplazada | Baja (3.7) | 0.23% | — | Django-allauthAI | 25/9/2026 | 30/9/2026 | django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit. | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | DjangoAIPostgresqlAI | 23/9/2026 | 26/9/2026 | — | |
| Aplazada | Alta (8.4) | 0.20% | — | Django-page-cmsAI | 18/9/2026 | 22/9/2026 | django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing unescaped content that renders to all visitors, enabling stored… | |
| Aplazada | Alta (7.1) | 0.45% | — | Django-page-cmsAI | 18/9/2026 | 22/9/2026 | django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. Attackers with low-privilege staff credentials can enumerate content identifiers and access unpublished drafts, page listings, and file… | |
| Aplazada | Crítica (9.1) | 0.48% | — | DjustAIDjangoAI | 16/9/2026 | 30/9/2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization — `LoginRequiredMixin`,… | |
| Aplazada | Media (5.3) | 0.37% | — | Djangocrm Django-crmAI | 14/9/2026 | 14/9/2026 | A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing authorization. The attack is possible to be carried out remotely. Upgrading to… | |
| Aplazada | Baja (2.1) | 0.38% | — | Caoqianming Django-vue-adminAI | 31/8/2026 | 1/9/2026 | A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of the file /api/file/. Executing a manipulation of the argument file_id can lead to improper access controls. The attack can be executed remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (4.3) | 0.34% | — | DjangoAITorchbox WagtailAI | 24/8/2026 | 9/9/2026 | Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve… | |
| Pendiente de análisis | Media (4.4) | 0.26% | — | Django CMSAI | 20/8/2026 | 9/9/2026 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled values to ContentRenderer.render_exception when plugin rendering fails in edit mode.… | |
| Pendiente de análisis | Media (4.3) | 0.34% | — | Django CMSAI | 20/8/2026 | 9/9/2026 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, render_object_structure fails to authorize non-PageContent objects that use PlaceholderRelationField. An active staff user without cms.use_structure or model-level view or change permission can… | |
| Pendiente de análisis | Media (6.5) | 0.41% | — | Django CMSAI | 20/8/2026 | 9/9/2026 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, render_object_structure in cms/views.py renders cms/toolbar/structure.html for a PageContent object without calling user_can_view_page(). Any staff account can request a restricted page’s… | |
| Pendiente de análisis | Media (6.5) | 0.41% | — | Django-cms Django CMSAI | 20/8/2026 | 9/9/2026 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the copy_plugins endpoint in cms/admin/placeholderadmin.py authorizes only the destination clipboard. The _copy_plugin_to_clipboard and _copy_placeholder_to_clipboard paths accept… | |
| Aplazada | Media (6.5) | 0.41% | — | Django CMSAI | 20/8/2026 | 18/9/2026 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on the source page. In cms/admin/forms.py, DuplicatePageForm.source accepts any Page, the AddPageForm constructor does not narrow a… | |
| Aplazada | Media (4.8) | 0.18% | — | Django CMSAI | 20/8/2026 | 18/9/2026 | django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site, language, path, and timezone but not the… | |
| Aplazada | Alta (7.1) | 0.49% | — | Django CMSAI | 20/8/2026 | 18/9/2026 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value without rejecting a plugin’s own identifier or a descendant identifier. A staff user… | |
| Aplazada | Media (5.3) | 0.29% | — | Django-helpdeskAI | 13/8/2026 | 9/9/2026 | django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by submitting HTML-formatted email messages or uploading .html/.htm file attachments through public ticket submission channels. Attackers can exploit the lack of… | |
| Pendiente de análisis | Media (4.3) | 0.37% | — | Django Rest FrameworkAI | 11/8/2026 | 11/9/2026 | Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.get() without view.check_permissions() while rendering an invalid write request,… | |
| Pendiente de análisis | Media (5.3) | 0.56% | — | Django-rest-framework Django Rest FrameworkAI | 11/8/2026 | 11/9/2026 | Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing… | |
| Aplazada | Media (4.3) | 0.33% | — | DjangocrmAI | 5/8/2026 | 26/8/2026 | DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely verifies the target host matches the current site's domain… |