Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
django vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2019-14232
An issue exists in Django 1.11.x prior to 1.11.23, 2.1.x prior to 2.1.11, and 2.2.x prior to 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic back...
Djangoproject Django
Opensuse Leap 15.1
5
CVSSv2
CVE-2019-14233
An issue exists in Django 1.11.x prior to 1.11.23, 2.1.x prior to 2.1.11, and 2.2.x prior to 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_tags would be extremely slow to evaluate certain inputs containing large sequences of nested incomplete H...
Djangoproject Django
Opensuse Leap 15.1
5
CVSSv2
CVE-2019-14235
An issue exists in Django 1.11.x prior to 1.11.23, 2.1.x prior to 2.1.11, and 2.2.x prior to 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage due to a recursion when repercent-encoding invalid UTF-8 octet sequences.
Djangoproject Django
Opensuse Leap 15.1
5
CVSSv2
CVE-2019-12781
An issue exists in Django 1.11 prior to 1.11.22, 2.1 prior to 2.1.10, and 2.2 prior to 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django....
Djangoproject Django
Canonical Ubuntu Linux 16.04
Debian Debian Linux 9.0
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 18.10
Canonical Ubuntu Linux 19.04
5
CVSSv2
CVE-2019-6975
Django 1.11.x prior to 1.11.19, 2.0.x prior to 2.0.11, and 2.1.x prior to 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.
Djangoproject Django
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 18.10
Fedoraproject Fedora 28
Fedoraproject Fedora 29
3 Github repositories
5
CVSSv2
CVE-2018-6188
django.contrib.auth.forms.AuthenticationForm in Django 2.0 prior to 2.0.2, and 1.11.8 and 1.11.9, allows remote malicious users to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether ...
Djangoproject Django 2.0.1
Djangoproject Django 1.11.9
Djangoproject Django 2.0
Djangoproject Django 1.11.8
Canonical Ubuntu Linux 17.10
5
CVSSv2
CVE-2015-3982
The session.flush function in the cached_db backend in Django 1.8.x prior to 1.8.2 does not properly flush the session, which allows remote malicious users to hijack user sessions via an empty string in the session key.
Djangoproject Django 1.8.0
Djangoproject Django 1.8.1
5
CVSSv2
CVE-2015-0846
django-markupfield prior to 1.3.2 uses the default docutils RESTRUCTUREDTEXT_FILTER_SETTINGS settings, which allows remote malicious users to include and read arbitrary files via unspecified vectors.
Django-markupfield Project Django-markupfield
5
CVSSv2
CVE-2015-2316
The utils.html.strip_tags function in Django 1.6.x prior to 1.6.11, 1.7.x prior to 1.7.7, and 1.8.x prior to 1.8c1, when using certain versions of Python, allows remote malicious users to cause a denial of service (infinite loop) by increasing the length of the input string.
Oracle Solaris 11.2
Djangoproject Django 1.6.10
Djangoproject Django 1.6.2
Djangoproject Django 1.6.1
Djangoproject Django 1.7
Djangoproject Django 1.7.3
Djangoproject Django 1.7.4
Djangoproject Django 1.6.4
Djangoproject Django 1.6.3
Djangoproject Django 1.6
Djangoproject Django 1.7.1
Djangoproject Django 1.7.2
Djangoproject Django 1.6.7
Djangoproject Django 1.6.6
Djangoproject Django 1.6.5
Djangoproject Django 1.6.9
Djangoproject Django 1.6.8
Djangoproject Django 1.7.5
Djangoproject Django 1.7.6
Djangoproject Django 1.8.0
Canonical Ubuntu Linux 10.04
Canonical Ubuntu Linux 12.04
5
CVSSv2
CVE-2015-0222
ModelMultipleChoiceField in Django 1.6.x prior to 1.6.10 and 1.7.x prior to 1.7.3, when show_hidden_initial is set to True, allows remote malicious users to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 10.04
Canonical Ubuntu Linux 14.10
Djangoproject Django 1.6.4
Djangoproject Django 1.6.5
Djangoproject Django 1.7.2
Djangoproject Django 1.6
Djangoproject Django 1.6.1
Djangoproject Django 1.6.8
Djangoproject Django 1.6.9
Djangoproject Django 1.6.2
Djangoproject Django 1.6.3
Djangoproject Django 1.7
Djangoproject Django 1.7.1
Djangoproject Django
Djangoproject Django 1.6.6
Djangoproject Django 1.6.7
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »