Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

279 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)19%💥 PoCDjangoproject DjangoDebian Linux12/4/202217/6/2026
An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.
ModificadaAlta (7.5)50%—Djangoproject DjangoFedoraproject FedoraDebian Linux3/2/202217/6/2026
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.
ModificadaMedia (6.1)3.4%💥 PoCDjangoproject DjangoFedoraproject FedoraDebian Linux3/2/202217/6/2026
The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.
ModificadaMedia (5.4)0.62%—Django-cms Django CMS12/1/202217/6/2026
Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user.
ModificadaMedia (5.3)2.4%—Djangoproject DjangoFedoraproject Fedora5/1/202217/6/2026
Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.
ModificadaAlta (7.5)1.8%—Djangoproject DjangoFedoraproject Fedora5/1/202217/6/2026
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosure, or an unintended method call, if passed a suitably crafted key.
ModificadaAlta (7.5)2.4%—Djangoproject DjangoFedoraproject Fedora5/1/202217/6/2026
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityValidator incurred significant overhead in evaluating a submitted password that was artificially large in relation to the comparison values. In a situation where access to user registration was…
ModificadaMedia (5.3)2.5%—Apache Airavata Django Portal9/12/202117/6/2026
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-django-portal [1]…
ModificadaAlta (7.3)2.5%—Djangoproject DjangoRedhat SatelliteDebian LinuxCanonical Ubuntu Linux+18/12/202117/6/2026
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
ModificadaCrítica (9.6)1.4%—Django-helpdesk Project Django-helpdesk1/12/202117/6/2026
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (5.4)0.60%—Django-wiki Project Django-wiki23/11/202117/6/2026
In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. An attacker who has access to edit pages can inject JavaScript payload in the title field. When a victim gets a notification regarding the changes made in the application, the payload in the…
ModificadaMedia (5.4)0.80%—Django-helpdesk Project Django-helpdesk19/11/202117/6/2026
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (6.1)1.0%—Django-helpdesk Project Django-helpdesk13/11/202117/6/2026
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (6.1)0.70%—Django-unicorn Unicorn11/10/202117/6/2026
The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.
ModificadaMedia (5.4)2.5%💥 ExploitDjango-unicorn Unicorn7/10/202117/6/2026
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
ModificadaCrítica (9.8)44%💥 PoCDjangoproject DjangoFedoraproject Fedora2/7/202117/6/2026
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
ModificadaAlta (7.5)5.3%—Djangoproject DjangoFedoraproject Fedora8/6/202117/6/2026
In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses. (validate_ipv4_address and validate_ipv46_address are…
ModificadaMedia (4.9)2.7%—Djangoproject DjangoFedoraproject Fedora8/6/202117/6/2026
Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files. Additionally, if (and only if) the default admindocs templates have been customized by…
ModificadaMedia (6.1)3.2%—Djangoproject DjangoFedoraproject Fedora6/5/202117/6/2026
In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because…
ModificadaAlta (7.5)5.3%—Djangoproject DjangoDebian LinuxFedoraproject Fedora5/5/202117/6/2026
In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
ModificadaMedia (6.5)1.8%—Django-filter Project Django-filterFedoraproject Fedora29/4/202117/6/2026
django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before version 2.4.0, automatically generated `NumberFilter` instances, whose value was later converted to an integer, were subject to potential DoS from maliciously input using exponential format with…
ModificadaCrítica (9.8)1.9%—Jazzband Django Debug Toolbar14/4/202117/6/2026
A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form.
ModificadaMedia (5.3)3.9%—Djangoproject DjangoDebian LinuxFedoraproject Fedora6/4/202117/6/2026
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.
ModificadaBaja (2.6)0.41%—Django-registration Project Django-registration1/4/202117/6/2026
django-registration is a user registration package for Django. The django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data,…
ModificadaAlta (7.4)2.7%—Djangoproject Channels22/2/202117/6/2026
Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type requests in an ASGI environment prior to Django 3.0, did not correctly separate request scopes in Channels 3.0. In many cases…
Orbitaley — Vulnerabilidades