Known vulnerabilities in python-django (Debian package) - page 2

Vendor: Debian
Software CPE: cpe:2.3:o:debian:python-django_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 52
Public exploits: 9
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting python-django (Debian package) python-django (Debian package) is affected by 52 known vulnerabilities: 14 high, 32 medium, 6 low Critical High Medium Low

Vulnerabilities (52)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU119043 - Resource Management Errors
CVE-2025-64460
CWE-399 Medium
No
No
3:3.2.25-0+deb12u1, 3:4.2.27-0+deb13u1 02.12.2025 SB2025120234
SB2025120237
SB2025120561
and 13 more
#VU119042 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-13372
CWE-89 Medium
No
No
3:3.2.25-0+deb12u1, 3:4.2.27-0+deb13u1 02.12.2025 SB2025120234
SB2025120237
SB2025121224
and 8 more
#VU118131 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-64459
CWE-89 Medium
Available
No
3:3.2.25-0+deb12u1, 3:4.2.27-0+deb13u1 05.11.2025 SB2025110551
SB2025110552
SB2025111466
and 14 more
#VU116427 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-59682
CWE-22 Medium
No
No
3:3.2.25-0+deb12u1, 3:4.2.27-0+deb13u1 03.10.2025 SB2025100337
SB2025100340
SB2025100647
and 14 more
#VU116426 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-59681
CWE-89 High
No
No
3:3.2.25-0+deb12u1, 3:4.2.27-0+deb13u1 03.10.2025 SB2025100337
SB2025100340
SB2025100647
and 12 more
#VU114764 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-57833
CWE-89 High
Available
No
3:3.2.25-0+deb12u1, 3:4.2.27-0+deb13u1 03.09.2025 SB2025090342
SB2025090433
SB2025090469
and 19 more
#VU110203 - Improper input validation
CVE-2025-48432
CWE-20 Medium
No
No
3:3.2.25-0+deb12u1 04.06.2025 SB2025060452
SB2025060831
SB2025060832
and 18 more
#VU108774 - Resource exhaustion
CVE-2025-32873
CWE-400 Medium
No
No
3:3.2.25-0+deb12u1 07.05.2025 SB2025050779
SB2025050787
SB2025050789
and 14 more
#VU77880 - Inefficient Regular Expression Complexity
CVE-2023-36053
CWE-1333 Medium
No
No
2:2.2.28-1~deb11u2, 3:3.2.19-1+deb12u1 03.07.2023 SB2023070325
SB2023070532
SB2023071502
and 16 more
#VU75707 - Unrestricted Upload of File with Dangerous Type
CVE-2023-31047
CWE-434 High
No
No
2:2.2.28-1~deb11u2, 3:3.2.19-1+deb12u1 03.05.2023 SB2023050350
SB2023050351
SB2023052531
and 11 more
#VU72330 - Resource exhaustion
CVE-2023-24580
CWE-400 Medium
No
No
2:2.2.28-1~deb11u2, 3:3.2.19-1+deb12u1 16.02.2023 SB2023021645
SB2023021648
SB2023031032
and 15 more
#VU71737 - Improper input validation
CVE-2023-23969
CWE-20 Medium
No
No
2:2.2.28-1~deb11u2, 3:3.2.19-1+deb12u1 01.02.2023 SB2023020139
SB2023020143
SB2023020151
and 13 more
#VU67893 - Improper input validation
CVE-2022-41323
CWE-20 Medium
No
No
2:2.2.28-1~deb11u1 04.10.2022 SB2022100415
SB2022100429
SB2022101602
and 9 more
#VU66019 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2022-36359
CWE-451 Low
No
No
2:2.2.28-1~deb11u1 03.08.2022 SB2022080309
SB2022080435
SB2022101602
and 4 more
#VU64905 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-34265
CWE-89 High
Available
No
2:2.2.28-1~deb11u1 04.07.2022 SB2022070425
SB2022070438
SB2022080147
and 8 more
#VU62051 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-28347
CWE-89 High
No
No
2:2.2.28-1~deb11u1 11.04.2022 SB2022041110
SB2022041125
SB2022041267
and 8 more
#VU62050 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-28346
CWE-89 High
Available
No
2:2.2.28-1~deb11u1 11.04.2022 SB2022041110
SB2022041125
SB2022041126
and 14 more
#VU60198 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-23833
CWE-835 Medium
No
No
2:2.2.28-1~deb11u1 01.02.2022 SB2022020110
SB2022041954
SB2022020334
and 11 more
#VU60197 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-22818
CWE-79 Medium
Available
No
2:2.2.28-1~deb11u1 01.02.2022 SB2022020110
SB2022041954
SB2022020334
and 12 more
#VU28953 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-13596
CWE-79 Low
No
No
1:1.10.7-2+deb9u9, 1:1.11.29-1~deb10u1 10.06.2020 SB2020061040
SB2020061041
SB2020121609
and 4 more


Showing elements 21 - 40 out of 52