Known vulnerabilities in Django 2.2.1 - page 2

Software: Django
Version: 2.2.1
Software CPE: cpe:2.3:a:django_software_foundation:django:*:*:*:*:*:*:*:*
Total vulnerabilities: 30
Public exploits: 7
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Django version 2.2.1 Django 2.2.1 is affected by 30 vulnerabilities: 7 high, 18 medium, 5 low Critical High Medium Low

Vulnerabilities (30)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU24846 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2020-7471
CWE-89 Medium
Public exploit available
No
1.11.28, 2.2.10, 3.0.3 03.02.2020 SB2020020315
SB2020020316
SB2020021911
and 6 more
#VU23667 - Improper input validation
CVE-2019-19844
CWE-20 High
Public exploit available
No
1.11.27, 2.2.9, 3.0.1 18.12.2019 SB2019121815
SB2019121916
SB2020010811
and 7 more
#VU23453 - Improper Privilege Management
CVE-2019-19118
CWE-269 Medium
No
No
2.1.15, 2.2.8 08.12.2019 SB2019120805
SB2020050101
SB2019121099
#VU19620 - Resource Management Errors
CVE-2019-14235
CWE-399 Medium
No
No
1.11.23, 2.1.11, 2.2.4 01.08.2019 SB2019080105
SB2019080204
SB2019080601
and 9 more
#VU19619 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-14234
CWE-89 High
No
No
1.11.23, 2.1.11, 2.2.4 01.08.2019 SB2019080105
SB2019080204
SB2019080601
and 9 more
#VU19618 - Resource Management Errors
CVE-2019-14233
CWE-399 Medium
No
No
1.11.23, 2.1.11, 2.2.4 01.08.2019 SB2019080105
SB2019080204
SB2019080601
and 12 more
#VU19617 - Resource Management Errors
CVE-2019-14232
CWE-399 Medium
No
No
1.11.23, 2.1.11, 2.2.4 01.08.2019 SB2019080105
SB2019080204
SB2019080601
and 14 more
#VU18967 - Cleartext Transmission of Sensitive Information
CVE-2019-12781
CWE-319 Medium
No
No
1.11.22, 2.1.10, 2.2.3 02.07.2019 SB2019070211
SB2019070601
SB2019070602
and 8 more
#VU18672 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-12308
CWE-79 Low
No
No
1.11.21, 2.1.9, 2.2.2 04.06.2019 SB2019060403
SB2019060404
SB2019060406
and 10 more
#VU18092 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2019-11358
CWE-1321 Low
Public exploit available
No
2.1.9, 2.2.2 28.03.2019 SB2019032804
SB2019041026
SB2019041801
and 155 more


Showing elements 21 - 40 out of 30