Vulnerability index

Browse CVEs

129 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Django HIGH 7.5
CVE-2018-6188

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensiti…

Patch available
Fix from $1,950 2018-02-05
Django MEDIUM 6.1
CVE-2017-12794EPSS 24%

In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page…

Patch available
Fix from $1,600 2017-09-07
Django MEDIUM 6.1
CVE-2017-7233

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. T…

Mitigation only
Fix from $1,600 2017-04-04
Django MEDIUM 6.1
CVE-2017-7234

A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` v…

Mitigation only
Fix from $1,600 2017-04-04
Django CRITICAL 9.8
CVE-2016-9013EPSS 5%

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running…

Mitigation only
Fix from $2,300 2016-12-09
Django HIGH 7.4
CVE-2016-2512

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites a…

Patch available
Fix from $1,950 2016-04-08
Django MEDIUM 5.5
CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and creat…

Mitigation only
Fix from $1,600 2016-02-08
Django MEDIUM 5.0
CVE-2015-8213

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote atta…

Fix: after 1.7.10
Fix from $1,600 2015-12-07
Django MEDIUM 5.0
CVE-2015-5964

The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.…

Patch available
Fix from $1,600 2015-08-24
Django MEDIUM 5.0
CVE-2015-5963EPSS 5%

contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions all…

Patch available
Fix from $1,600 2015-08-24
Django HIGH 7.8
CVE-2015-5145

validators.URLValidator in Django 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

Mitigation only
Fix from $1,950 2015-07-14
Django HIGH 7.8
CVE-2015-5143EPSS 7%

The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a deni…

Patch available
Fix from $1,950 2015-07-14
Django MEDIUM 5.0
CVE-2015-3982

The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers t…

Patch available
Fix from $1,600 2015-06-02
Django MEDIUM 5.0
CVE-2015-2316

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, …

Patch available
Fix from $1,600 2015-03-25
Django MEDIUM 5.0
CVE-2015-0221

The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which a…

Fix: after 1.4.17
Fix from $1,600 2015-01-16
Django MEDIUM 5.0
CVE-2015-0219EPSS 7%

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character …

Fix: after 1.4.17
Fix from $1,600 2015-01-16
Piston HIGH 7.5
CVE-2011-4103

emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute …

Fix: after 0.2.2.0
Fix from $1,950 2014-10-27
Tastypie HIGH 7.5
CVE-2011-4104

The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to exe…

Fix: after 0.9.9
Fix from $1,950 2014-10-27
Django MEDIUM 6.0
CVE-2014-0482

The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release c…

Fix: after 1.4.13
Fix from $1,600 2014-08-26
Django MEDIUM 5.8
CVE-2014-0480

The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not p…

Patch available
Fix from $1,600 2014-08-26
Django MEDIUM 6.4
CVE-2014-1418

Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Contro…

Patch available
Fix from $1,600 2014-05-16
Django MEDIUM 5.0
CVE-2014-0473

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all…

Fix: after 1.4.10
Fix from $1,600 2014-04-23
Django MEDIUM 5.1
CVE-2014-0472EPSS 6%

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows rem…

Fix: after 1.4.10
Fix from $1,600 2014-04-23
Django MEDIUM 5.0
CVE-2013-1443

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attack…

Patch available
Fix from $1,600 2013-09-23
Django MEDIUM 5.0
CVE-2013-4315

Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbit…

Patch available
Fix from $1,600 2013-09-16
Django MEDIUM 5.0
CVE-2013-0306

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended reso…

Mitigation only
Fix from $1,600 2013-05-02
Django MEDIUM 6.4
CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arb…

Patch available
Fix from $1,600 2012-11-18
Django MEDIUM 5.0
CVE-2012-3443

The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image va…

Fix: after 1.3
Fix from $1,600 2012-07-31
Django MEDIUM 5.0
CVE-2012-3444

The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all…

Fix: after 1.3
Fix from $1,600 2012-07-31
Django MEDIUM 6.8
CVE-2011-4140

The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary…

Fix: after 1.2.6
Fix from $1,600 2011-10-19