Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

279 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)41%—PythonFedoraproject FedoraDebian LinuxNetapp Cloud Backup+815/2/202117/6/2026
The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query…
ModificadaMedia (5.3)7.6%💥 PoCDjangoproject DjangoFedoraproject FedoraNetapp Snapcenter2/2/202117/6/2026
In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.
ModificadaMedia (6.1)1.3%—Encode Django Rest FrameworkRedhat Ceph StorageDebian Linux30/9/202017/6/2026
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious <script> tags, leading to a…
ModificadaAlta (7.5)3.3%—Djangoproject DjangoCanonical Ubuntu LinuxFedoraproject FedoraOracle ZFS Storage Appliance KIT1/9/202017/6/2026
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
ModificadaAlta (7.5)4.0%—Djangoproject DjangoCanonical Ubuntu LinuxFedoraproject FedoraOracle ZFS Storage Appliance KIT1/9/202017/6/2026
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading files. It was also not applied to intermediate-level collected static…
ModificadaAlta (7.5)0.87%—Django-celery-results Project Django-celery-results11/8/202017/6/2026
django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database.
ModificadaMedia (5.4)0.70%—Django Two-factor Authentication Project Django Two-factor Authentication10/7/202017/6/2026
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authentication code. This means…
ModificadaBaja (2.4)0.36%—Django-basic-auth-ip-whitelist Project Django-basic-auth-ip-whitelist24/6/202017/6/2026
In django-basic-auth-ip-whitelist before 0.3.4, a potential timing attack exists on websites where the basic authentication is used or configured, i.e. BASIC_AUTH_LOGIN and BASIC_AUTH_PASSWORD is set. Currently the string comparison between configured credentials and the ones provided by users is performed through a…
ModificadaMedia (6.1)2.9%—Djangoproject DjangoFedoraproject FedoraCanonical Ubuntu LinuxNetapp SRA Plugin+33/6/202017/6/2026
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
ModificadaMedia (5.9)6.1%💥 PoCDjangoproject DjangoCanonical Ubuntu LinuxFedoraproject FedoraNetapp SRA Plugin+33/6/202017/6/2026
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
ModificadaAlta (7.5)1.2%—Django-nopassword Project Django-nopassword18/3/202017/6/2026
django-nopassword before 5.0.0 stores cleartext secrets in the database.
ModificadaCrítica (9.1)1.6%—Styria Django-rest-framework-json WEB Tokens15/3/202017/6/2026
An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible with the token-refresh feature. NOTE: drf-jwt is a fork of…
ModificadaAlta (8.8)23%—Djangoproject DjangoDebian LinuxFedoraproject FedoraNetapp Steelstore Cloud Integrated Storage+15/3/202017/6/2026
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject…
ModificadaCrítica (9.8)66%💥 PoCDjangoproject Django3/2/202017/6/2026
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a…
ModificadaAlta (8.8)0.53%—Django-user-sessions Project Django-user-sessions24/1/202017/6/2026
In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions. The session key is used to identify sessions, and thus included in the rendered HTML. In itself this is not a problem. However if the website has an XSS vulnerability, the session key could be…
ModificadaCrítica (9.8)54%💥 ExploitDjangoproject DjangoCanonical Ubuntu Linux18/12/201917/6/2026
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One…
ModificadaMedia (6.5)1.7%—Djangoproject DjangoFedoraproject Fedora2/12/201917/6/2026
Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edit permissions to the inline model, would be presented with an editing UI, allowing POST requests, for updating the…
ModificadaAlta (8.8)1.2%—Micropyramid Django CRM27/8/201917/6/2026
Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-admin/, /comment/add/, /documents/1/view/, /documents/create/, /opportunities/create/, and /login/.
ModificadaMedia (6.1)1.0%—Django JS Reverse Project Django JS Reserve23/8/201917/6/2026
django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
ModificadaCrítica (9.8)48%💥 PoCDjangoproject DjangoFedoraproject FedoraDebian Linux9/8/201917/6/2026
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField, were subject to SQL injection. This…
ModificadaAlta (7.5)3.1%—Djangoproject DjangoOpensuse Leap2/8/201917/6/2026
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage due to a recursion when repercent-encoding invalid UTF-8 octet sequences.
ModificadaAlta (7.5)3.2%—Djangoproject DjangoOpensuse Leap2/8/201917/6/2026
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_tags would be extremely slow to evaluate certain inputs containing large sequences of nested incomplete HTML entities.
ModificadaAlta (7.5)3.5%—Djangoproject DjangoOpensuse Leap2/8/201917/6/2026
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular…
ModificadaCrítica (9.8)1.6%—Django-rest-registration Project Django-rest-registration2/7/201917/6/2026
verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the Django Signing API is misused), which allows remote attackers to spoof the verification process. This occurs because incorrect code refactoring led to calling a…
ModificadaMedia (5.3)1.7%—Djangoproject DjangoCanonical Ubuntu LinuxDebian Linux1/7/201917/6/2026
An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect…
Orbitaley — Vulnerabilidades