Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Djangoproject DjangoFedoraproject Fedora | 3/11/2023 | 17/6/2026 | In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, potentially malformed HTML text. The chars() and words() methods are… | |
| Modificada | Alta (7.5) | 1.5% | — | Djangoproject DjangoFedoraproject Fedora | 3/11/2023 | 17/6/2026 | In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters. | |
| Modificada | Alta (7.5) | 50% | — | Djangoproject Django | 2/11/2023 | 17/6/2026 | An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.forms.UsernameField is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters. | |
| Modificada | Media (6.1) | 0.47% | — | Vonautomatisch Django Grappelli | 22/10/2023 | 17/6/2026 | views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does not consider a protocol-relative URL (e.g., //example.com) attack. | |
| Modificada | Crítica (9.8) | 1.6% | — | Ehco1996 Django-sspanel | 4/8/2023 | 17/6/2026 | django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCreateView._post. | |
| Modificada | Alta (7.5) | 3.0% | — | Djangoproject DjangoDebian LinuxFedoraproject Fedora | 3/7/2023 | 17/6/2026 | In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs. | |
| Modificada | Media (5.4) | 0.41% | — | Djangoblog Project Djangoblog | 29/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master. | |
| Modificada | Media (5.4) | 0.23% | — | Django-ses Project Django-ses | 26/5/2023 | 17/6/2026 | Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebhookView class` intended to receive signed requests from AWS to handle email bounces, subscriptions, etc. These requests are signed by AWS and… | |
| Modificada | Crítica (9.8) | 1.4% | — | Djangoproject DjangoFedoraproject Fedora | 7/5/2023 | 17/6/2026 | In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading… | |
| Modificada | Media (6.1) | 0.57% | — | Mobilevikings Django Ajax Utilities | 10/3/2023 | 17/6/2026 | A vulnerability was found in Mobile Vikings Django AJAX Utilities up to 1.2.1 and classified as problematic. This issue affects the function Pagination of the file django_ajax/static/ajax-utilities/js/pagination.js of the component Backslash Handler. The manipulation of the argument url leads to cross site scripting.… | |
| Modificada | Alta (7.5) | 63% | — | Djangoproject DjangoDebian Linux | 15/2/2023 | 17/6/2026 | An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service… | |
| Modificada | Alta (7.5) | 47% | 💥 PoC | Djangoproject DjangoDebian Linux | 1/2/2023 | 17/6/2026 | In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large. | |
| Modificada | Media (6.1) | 0.55% | — | Django-ucamlookup Project Django-ucamlookup | 5/1/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in University of Cambridge django-ucamlookup up to 1.9.1. Affected by this vulnerability is an unknown functionality of the component Lookup Handler. The manipulation leads to cross site scripting. The attack can be launched remotely.… | |
| Modificada | Media (6.1) | 0.53% | — | Django-openipam Project Django-openipam | 18/12/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in django-openipam. This affects an unknown part of the file openipam/report/templates/report/exposed_hosts.html. The manipulation of the argument description leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is… | |
| Modificada | Media (6.1) | 0.48% | — | Django Terms AND Conditions Project Django Terms AND Conditions | 17/12/2022 | 17/6/2026 | A vulnerability has been found in cyface Terms and Conditions Module up to 2.0.9 and classified as problematic. Affected by this vulnerability is the function returnTo of the file termsandconditions/views.py. The manipulation leads to open redirect. The attack can be launched remotely. Upgrading to version 2.0.10 is… | |
| Modificada | Media (6.1) | 0.54% | — | Django-photologue Project Django-photologue | 15/12/2022 | 17/6/2026 | A vulnerability was found in django-photologue up to 3.15.1 and classified as problematic. Affected by this issue is some unknown functionality of the file photologue/templates/photologue/photo_detail.html of the component Default Template Handler. The manipulation of the argument object.caption leads to cross site… | |
| Modificada | Alta (7.5) | 3.0% | — | Djangoproject Django | 16/10/2022 | 17/6/2026 | In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression. | |
| Modificada | Alta (7.5) | 1.1% | — | Django-mfa2 Project Django-mfa2 | 11/10/2022 | 17/6/2026 | mfa/FIDO2.py in django-mfa2 before 2.5.1 and 2.6.x before 2.6.1 allows a replay attack that could be used to register another device for a user. The device registration challenge is not invalidated after usage. | |
| Modificada | Alta (8.8) | 0.88% | — | Djangoproject DjangoDebian Linux | 3/8/2022 | 17/6/2026 | An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input. | |
| Modificada | Media (6.1) | 0.76% | — | Django-rest-framework Django Rest Framework | 23/7/2022 | 17/6/2026 | Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping. | |
| Modificada | Crítica (9.8) | 74% | 💥 PoC | Djangoproject Django | 4/7/2022 | 17/6/2026 | An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Django-navbar-client | 24/6/2022 | 17/6/2026 | The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Django-s3file Project Django-s3file | 9/6/2022 | 17/6/2026 | django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible to traverse the entire AWS S3 bucket and in most cases to access or delete files. If the `AWS_LOCATION` setting was set, traversal was limited to that location only. The issue was discovered by the… | |
| Modificada | Alta (8.8) | 1.2% | — | Django-mfa3 Project Django-mfa3 | 15/4/2022 | 17/6/2026 | django-mfa3 is a library that implements multi factor authentication for the django web framework. It achieves this by modifying the regular login view. Django however has a second login view for its admin area. This second login view was not modified, so the multi factor authentication can be bypassed. Users are… | |
| Modificada | Crítica (9.8) | 2.9% | — | Djangoproject DjangoDebian Linux | 12/4/2022 | 17/6/2026 | A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name. |