Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2022-23833EPSS 49%
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart …
Django
2.2.27 / 3.2.12+
MEDIUM 6.1
CVE-2022-22818
The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This …
Django
2.2.27 / 3.2.12+
HIGH 7.5
CVE-2021-45115
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityValidator incurred significant o…
Django
2.2.26 / 3.2.11+
HIGH 7.5
CVE-2021-45116
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variab…
Django
2.2.26 / 3.2.11+
MEDIUM 5.3
CVE-2021-45452
Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed…
Django
2.2.26 / 3.2.11+
HIGH 7.3
CVE-2021-44420
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access con…
Django
2.2.25 / 3.1.14+
CRITICAL 9.8
CVE-2021-35042EPSS 44%
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web applic…
Django
3.1.13 / 3.2.5+
HIGH 7.5
CVE-2021-33571EPSS 5%
In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit…
Django
2.2.24 / 3.1.12+
MEDIUM 6.1
CVE-2021-32052
In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless t…
Django
2.2.22 / 3.1.10+
HIGH 7.5
CVE-2021-31542EPSS 5%
In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via upl…
Django
2.2.21 / 3.1.9+
MEDIUM 5.3
CVE-2021-28658
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably cr…
Django
2.2.20 / 3.0.14+
HIGH 7.4
CVE-2020-35681
Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.Asg…
Channels
3.0.3+
MEDIUM 5.3
CVE-2021-3281EPSS 8%
In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "sta…
Django
2.2.18 / 3.0.12+
HIGH 7.5
CVE-2020-24583
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMIS…
Django
2.2.16 / 3.0.10+
HIGH 7.5
CVE-2020-24584
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level direc…
Django
2.2.16 / 3.0.10+
MEDIUM 6.1
CVE-2020-13596
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were n…
Django
2.2.13 / 3.0.7+
MEDIUM 5.9
CVE-2020-13254EPSS 6%
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing…
Django
2.2.13 / 3.0.7+
HIGH 8.8
CVE-2020-9402EPSS 23%
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS fu…
Django
1.11.29 / 2.2.11+
CRITICAL 9.8
CVE-2020-7471EPSS 65%
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in…
Django
1.11.28 / 2.2.10+
CRITICAL 9.8
CVE-2019-19844EPSS 35%
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing…
Django
1.11.27 / 2.2.9+
MEDIUM 6.5
CVE-2019-19118
Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user …
Django
2.1.15 / 2.2.8+
CRITICAL 9.8
CVE-2019-14234EPSS 48%
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, …
Django
1.11.23 / 2.1.11+
HIGH 7.5
CVE-2019-14235
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding…
Django
1.11.23 / 2.1.11+
HIGH 7.5
CVE-2019-14232
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and wo…
Django
1.11.23 / 2.1.11+
HIGH 7.5
CVE-2019-14233
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLPars…
Django
1.11.23 / 2.1.11+
MEDIUM 5.3
CVE-2019-12781
An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the S…
Django
1.11.22 / 2.1.10+
MEDIUM 6.1
CVE-2019-12308
An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the Admin…
Django
1.11.21 / 2.1.9+
HIGH 7.5
CVE-2019-6975EPSS 5%
Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied va…
Django
1.11.19 / 2.0.11+
MEDIUM 6.5
CVE-2019-3498
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Down…
Django
1.11.18 / 2.0.10+
MEDIUM 6.1
CVE-2018-14574EPSS 25%
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
Django
1.11.15 / 2.0.8+