Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

279 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Djangoproject DjangoFedoraproject Fedora3/11/202317/6/2026
In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, potentially malformed HTML text. The chars() and words() methods are…
ModificadaAlta (7.5)1.5%—Djangoproject DjangoFedoraproject Fedora3/11/202317/6/2026
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
ModificadaAlta (7.5)50%—Djangoproject Django2/11/202317/6/2026
An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
ModificadaMedia (6.1)0.47%—Vonautomatisch Django Grappelli22/10/202317/6/2026
views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does not consider a protocol-relative URL (e.g., //example.com) attack.
ModificadaCrítica (9.8)1.6%—Ehco1996 Django-sspanel4/8/202317/6/2026
django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCreateView._post.
ModificadaAlta (7.5)3.0%—Djangoproject DjangoDebian LinuxFedoraproject Fedora3/7/202317/6/2026
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
ModificadaMedia (5.4)0.41%—Djangoblog Project Djangoblog29/5/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.
ModificadaMedia (5.4)0.23%—Django-ses Project Django-ses26/5/202317/6/2026
Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebhookView class` intended to receive signed requests from AWS to handle email bounces, subscriptions, etc. These requests are signed by AWS and…
ModificadaCrítica (9.8)1.4%—Djangoproject DjangoFedoraproject Fedora7/5/202317/6/2026
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading…
ModificadaMedia (6.1)0.57%—Mobilevikings Django Ajax Utilities10/3/202317/6/2026
A vulnerability was found in Mobile Vikings Django AJAX Utilities up to 1.2.1 and classified as problematic. This issue affects the function Pagination of the file django_ajax/static/ajax-utilities/js/pagination.js of the component Backslash Handler. The manipulation of the argument url leads to cross site scripting.…
ModificadaAlta (7.5)63%—Djangoproject DjangoDebian Linux15/2/202317/6/2026
An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service…
ModificadaAlta (7.5)47%💥 PoCDjangoproject DjangoDebian Linux1/2/202317/6/2026
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
ModificadaMedia (6.1)0.55%—Django-ucamlookup Project Django-ucamlookup5/1/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in University of Cambridge django-ucamlookup up to 1.9.1. Affected by this vulnerability is an unknown functionality of the component Lookup Handler. The manipulation leads to cross site scripting. The attack can be launched remotely.…
ModificadaMedia (6.1)0.53%—Django-openipam Project Django-openipam18/12/202217/6/2026
A vulnerability classified as problematic has been found in django-openipam. This affects an unknown part of the file openipam/report/templates/report/exposed_hosts.html. The manipulation of the argument description leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is…
ModificadaMedia (6.1)0.48%—Django Terms AND Conditions Project Django Terms AND Conditions17/12/202217/6/2026
A vulnerability has been found in cyface Terms and Conditions Module up to 2.0.9 and classified as problematic. Affected by this vulnerability is the function returnTo of the file termsandconditions/views.py. The manipulation leads to open redirect. The attack can be launched remotely. Upgrading to version 2.0.10 is…
ModificadaMedia (6.1)0.54%—Django-photologue Project Django-photologue15/12/202217/6/2026
A vulnerability was found in django-photologue up to 3.15.1 and classified as problematic. Affected by this issue is some unknown functionality of the file photologue/templates/photologue/photo_detail.html of the component Default Template Handler. The manipulation of the argument object.caption leads to cross site…
ModificadaAlta (7.5)3.0%—Djangoproject Django16/10/202217/6/2026
In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.
ModificadaAlta (7.5)1.1%—Django-mfa2 Project Django-mfa211/10/202217/6/2026
mfa/FIDO2.py in django-mfa2 before 2.5.1 and 2.6.x before 2.6.1 allows a replay attack that could be used to register another device for a user. The device registration challenge is not invalidated after usage.
ModificadaAlta (8.8)0.88%—Djangoproject DjangoDebian Linux3/8/202217/6/2026
An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.
ModificadaMedia (6.1)0.76%—Django-rest-framework Django Rest Framework23/7/202217/6/2026
Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping.
ModificadaCrítica (9.8)74%💥 PoCDjangoproject Django4/7/202217/6/2026
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.
ModificadaCrítica (9.8)2.0%—Pypi Django-navbar-client24/6/202217/6/2026
The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaCrítica (9.8)2.0%—Django-s3file Project Django-s3file9/6/202217/6/2026
django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible to traverse the entire AWS S3 bucket and in most cases to access or delete files. If the `AWS_LOCATION` setting was set, traversal was limited to that location only. The issue was discovered by the…
ModificadaAlta (8.8)1.2%—Django-mfa3 Project Django-mfa315/4/202217/6/2026
django-mfa3 is a library that implements multi factor authentication for the django web framework. It achieves this by modifying the regular login view. Django however has a second login view for its admin area. This second login view was not modified, so the multi factor authentication can be bypassed. Users are…
ModificadaCrítica (9.8)2.9%—Djangoproject DjangoDebian Linux12/4/202217/6/2026
A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.
Orbitaley — Vulnerabilidades