Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.34% | — | AptrsAIDjangoAIPalletsprojects JinjaAI | 23/12/2024 | 17/6/2026 | APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. In 1.0, there is a vulnerability in the web application's handling of user-supplied input that is incorporated into a Jinja2 template. Specifically,… | |
| Analizada | Crítica (9.8) | 1.4% | — | Djangoproject Django | 6/12/2024 | 17/6/2026 | An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via… | |
| Analizada | Alta (7.5) | 1.4% | — | Djangoproject Django | 6/12/2024 | 17/6/2026 | An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities. | |
| Aplazada | Media (6.9) | 0.47% | — | Django CMS Association Django CMS Attributes FieldsAI | 20/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django CMS Attributes Fields allows Stored XSS. This issue affects django CMS Attributes Fields: before 4.0. | |
| Aplazada | Media (5.5) | 0.36% | — | Django CMS Association Django FilerAI | 20/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django Filer allows Input Data Manipulation, Stored XSS. This issue affects django Filer: from 3 before 3.3. | |
| Modificada | Media (4.8) | 0.51% | — | Django-cms Django CMS | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS). This issue affects django-cms: 3.11.7, 3.11.8, 4.1.2, 4.1.3. | |
| Modificada | Media (5.3) | 0.79% | — | Djangoproject Django | 8/10/2024 | 17/6/2026 | An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending… | |
| Modificada | Alta (7.5) | 26% | — | Djangoproject Django | 8/10/2024 | 17/6/2026 | An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters. | |
| Modificada | Alta (7.3) | 1.5% | — | Djangoproject Django | 7/8/2024 | 17/6/2026 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg. | |
| Modificada | Alta (7.5) | 0.95% | — | Djangoproject Django | 7/8/2024 | 17/6/2026 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters. | |
| Modificada | Alta (7.5) | 1.3% | — | Djangoproject Django | 7/8/2024 | 17/6/2026 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters. | |
| Modificada | Alta (7.5) | 1.2% | — | Djangoproject Django | 7/8/2024 | 17/6/2026 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in scientific notation with a large exponent. | |
| Modificada | Alta (7.5) | 29% | 💥 PoC | Djangoproject Django | 10/7/2024 | 17/6/2026 | An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters. | |
| Modificada | Media (4.3) | 1.0% | — | Djangoproject Django | 10/7/2024 | 17/6/2026 | An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generate_filename() without replicating the file-path validations from the parent class, potentially allow directory traversal via certain inputs during a… | |
| Modificada | Media (5.3) | 0.89% | — | Djangoproject Django | 10/7/2024 | 17/6/2026 | An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing attack involving login requests for users with an unusable password. | |
| Modificada | Alta (7.5) | 1.2% | — | Djangoproject Django | 10/7/2024 | 17/6/2026 | An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of brackets. | |
| Aplazada | Baja (2.1) | 1.1% | 💥 PoC | DjangorestframeworkAI | 26/6/2024 | 17/6/2026 | Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags. | |
| Aplazada | Media (5.5) | 0.33% | — | DjangoAITorchbox WagtailAI | 30/5/2024 | 17/6/2026 | Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in the `wagtail.contrib.settings` module, a user with access to the Wagtail admin and knowledge of the URL of the edit view for a settings model can access and update that setting, even when they have not… | |
| Aplazada | Baja (2.7) | 0.48% | — | DjangoAITorchbox WagtailAI | 2/5/2024 | 17/6/2026 | Wagtail is an open source content management system built on Django. In affected versions if a model has been made available for editing through the `wagtail.contrib.settings` module or `ModelViewSet`, and the `permission` argument on `FieldPanel` has been used to further restrict access to one or more fields of the… | |
| Analizada | Alta (7.5) | 0.61% | — | Django-wiki Project Django-wiki | 18/3/2024 | 17/6/2026 | django-wiki is a wiki system for Django. Installations of django-wiki prior to version 0.10.1 are vulnerable to maliciously crafted article content that can cause severe use of server CPU through a regular expression loop. Version 0.10.1 fixes this issue. As a workaround, close off access to create and edit articles… | |
| Aplazada | Media (5.5) | 0.80% | 💥 Exploit | Djangorestframework-simplejwtAI | 16/3/2024 | 17/6/2026 | djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method. | |
| Modificada | Media (5.3) | 1.9% | — | Djangoproject Django | 15/3/2024 | 17/6/2026 | In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete… | |
| Analizada | Alta (8.8) | 2.1% | — | Microsoft Django Backend | 12/3/2024 | 17/6/2026 | Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 1.6% | — | Djangoproject Django | 6/2/2024 | 17/6/2026 | An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings. | |
| Modificada | Media (6.1) | 0.48% | — | Gofiber Django | 11/1/2024 | 17/6/2026 | This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications that render user-supplied data through this template engine, potentially leading to the execution of malicious scripts in users'… |