Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 19% | 💥 PoC | Djangoproject DjangoDebian Linux | 12/4/2022 | 17/6/2026 | An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs. | |
| Modificada | Alta (7.5) | 50% | — | Djangoproject DjangoFedoraproject FedoraDebian Linux | 3/2/2022 | 17/6/2026 | An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files. | |
| Modificada | Media (6.1) | 3.4% | 💥 PoC | Djangoproject DjangoFedoraproject FedoraDebian Linux | 3/2/2022 | 17/6/2026 | The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS. | |
| Modificada | Media (5.4) | 0.62% | — | Django-cms Django CMS | 12/1/2022 | 17/6/2026 | Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user. | |
| Modificada | Media (5.3) | 2.4% | — | Djangoproject DjangoFedoraproject Fedora | 5/1/2022 | 17/6/2026 | Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it. | |
| Modificada | Alta (7.5) | 1.8% | — | Djangoproject DjangoFedoraproject Fedora | 5/1/2022 | 17/6/2026 | An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosure, or an unintended method call, if passed a suitably crafted key. | |
| Modificada | Alta (7.5) | 2.4% | — | Djangoproject DjangoFedoraproject Fedora | 5/1/2022 | 17/6/2026 | An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityValidator incurred significant overhead in evaluating a submitted password that was artificially large in relation to the comparison values. In a situation where access to user registration was… | |
| Modificada | Media (5.3) | 2.5% | — | Apache Airavata Django Portal | 9/12/2021 | 17/6/2026 | Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-django-portal [1]… | |
| Modificada | Alta (7.3) | 2.5% | — | Djangoproject DjangoRedhat SatelliteDebian LinuxCanonical Ubuntu Linux+1 | 8/12/2021 | 17/6/2026 | In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths. | |
| Modificada | Crítica (9.6) | 1.4% | — | Django-helpdesk Project Django-helpdesk | 1/12/2021 | 17/6/2026 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (5.4) | 0.60% | — | Django-wiki Project Django-wiki | 23/11/2021 | 17/6/2026 | In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages can inject JavaScript payload in the title field. When a victim gets a notification regarding the changes made in the application, the payload in the… | |
| Modificada | Media (5.4) | 0.80% | — | Django-helpdesk Project Django-helpdesk | 19/11/2021 | 17/6/2026 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (6.1) | 1.0% | — | Django-helpdesk Project Django-helpdesk | 13/11/2021 | 17/6/2026 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (6.1) | 0.70% | — | Django-unicorn Unicorn | 11/10/2021 | 17/6/2026 | The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053. | |
| Modificada | Media (5.4) | 2.5% | 💥 Exploit | Django-unicorn Unicorn | 7/10/2021 | 17/6/2026 | The Unicorn framework through 0.35.3 for Django allows XSS via component.name. | |
| Modificada | Crítica (9.8) | 44% | 💥 PoC | Djangoproject DjangoFedoraproject Fedora | 2/7/2021 | 17/6/2026 | Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application. | |
| Modificada | Alta (7.5) | 5.3% | — | Djangoproject DjangoFedoraproject Fedora | 8/6/2021 | 17/6/2026 | In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses. (validate_ipv4_address and validate_ipv46_address are… | |
| Modificada | Media (4.9) | 2.7% | — | Djangoproject DjangoFedoraproject Fedora | 8/6/2021 | 17/6/2026 | Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files. Additionally, if (and only if) the default admindocs templates have been customized by… | |
| Modificada | Media (6.1) | 3.2% | — | Djangoproject DjangoFedoraproject Fedora | 6/5/2021 | 17/6/2026 | In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because… | |
| Modificada | Alta (7.5) | 5.3% | — | Djangoproject DjangoDebian LinuxFedoraproject Fedora | 5/5/2021 | 17/6/2026 | In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names. | |
| Modificada | Media (6.5) | 1.8% | — | Django-filter Project Django-filterFedoraproject Fedora | 29/4/2021 | 17/6/2026 | django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before version 2.4.0, automatically generated `NumberFilter` instances, whose value was later converted to an integer, were subject to potential DoS from maliciously input using exponential format with… | |
| Modificada | Crítica (9.8) | 1.9% | — | Jazzband Django Debug Toolbar | 14/4/2021 | 17/6/2026 | A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form. | |
| Modificada | Media (5.3) | 3.9% | — | Djangoproject DjangoDebian LinuxFedoraproject Fedora | 6/4/2021 | 17/6/2026 | In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability. | |
| Modificada | Baja (2.6) | 0.41% | — | Django-registration Project Django-registration | 1/4/2021 | 17/6/2026 | django-registration is a user registration package for Django. The django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data,… | |
| Modificada | Alta (7.4) | 2.7% | — | Djangoproject Channels | 22/2/2021 | 17/6/2026 | Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type requests in an ASGI environment prior to Django 3.0, did not correctly separate request scopes in Channels 3.0. In many cases… |