Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2835▲ 33 respecto a la semana anterior
Críticas / altas1495▲ 276 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 451 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.37% | — | Django Rest FrameworkAI | 11/8/2026 | 11/9/2026 | Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.get() without view.check_permissions() while rendering an invalid write request,… | |
| Pendiente de análisis | Media (5.3) | 0.56% | — | Django-rest-framework Django Rest FrameworkAI | 11/8/2026 | 11/9/2026 | Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing… | |
| Modificada | Media (6.1) | 0.76% | — | Django-rest-framework Django Rest Framework | 23/7/2022 | 17/6/2026 | Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping. | |
| Modificada | Media (6.1) | 1.3% | — | Encode Django Rest FrameworkRedhat Ceph StorageDebian Linux | 30/9/2020 | 17/6/2026 | A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious <script> tags, leading to a… | |
| Modificada | Crítica (9.1) | 1.6% | — | Styria Django-rest-framework-json WEB Tokens | 15/3/2020 | 17/6/2026 | An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible with the token-refresh feature. NOTE: drf-jwt is a fork of… |