Known vulnerabilities in Django - page 5

Software: Django
Software CPE: cpe:2.3:a:django_software_foundation:django:*:*:*:*:*:*:*:*
Total vulnerabilities: 137
Public exploits: 12
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Django Django is affected by 137 known vulnerabilities: 19 high, 82 medium, 36 low Critical High Medium Low

Vulnerabilities (137)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU46660 - Incorrect Default Permissions
CVE-2020-24584
CWE-276 Medium
No
No
2.2.16, 3.0.10, 3.1.1 11.09.2020 SB2020091027
SB2020091118
SB2020121611
and 5 more
#VU46659 - Incorrect Default Permissions
CVE-2020-24583
CWE-276 Medium
No
No
2.2.16, 3.0.10, 3.1.1 11.09.2020 SB2020091027
SB2020091118
SB2020121610
and 5 more
#VU28954 - Improper Certificate Validation
CVE-2020-13254
CWE-295 Medium
Available
No
2.2.13, 3.0.7 10.06.2020 SB2020061040
SB2020061041
SB2020121608
and 5 more
#VU28953 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-13596
CWE-79 Low
No
No
2.2.13, 3.0.7 10.06.2020 SB2020061040
SB2020061041
SB2020121609
and 4 more
#VU25812 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2020-9402
CWE-89 High
No
No
1.11.29, 2.2.11, 3.0.4 08.03.2020 SB2020030801
SB2020030802
SB2020050101
and 6 more
#VU24846 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2020-7471
CWE-89 Medium
Available
No
1.11.28, 2.2.10, 3.0.3 03.02.2020 SB2020020315
SB2020020316
SB2020021911
and 6 more
#VU23667 - Improper input validation
CVE-2019-19844
CWE-20 High
Available
No
1.11.27, 2.2.9, 3.0.1 18.12.2019 SB2019121815
SB2019121916
SB2020010811
and 7 more
#VU23453 - Improper Privilege Management
CVE-2019-19118
CWE-269 Medium
No
No
2.1.15, 2.2.8 08.12.2019 SB2019120805
SB2020050101
SB2019121099
#VU19620 - Resource Management Errors
CVE-2019-14235
CWE-399 Medium
No
No
1.11.23, 2.1.11, 2.2.4 01.08.2019 SB2019080105
SB2019080204
SB2019080601
and 9 more
#VU19619 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-14234
CWE-89 High
No
No
1.11.23, 2.1.11, 2.2.4 01.08.2019 SB2019080105
SB2019080204
SB2019080601
and 9 more
#VU19618 - Resource Management Errors
CVE-2019-14233
CWE-399 Medium
No
No
1.11.23, 2.1.11, 2.2.4 01.08.2019 SB2019080105
SB2019080204
SB2019080601
and 12 more
#VU19617 - Resource Management Errors
CVE-2019-14232
CWE-399 Medium
No
No
1.11.23, 2.1.11, 2.2.4 01.08.2019 SB2019080105
SB2019080204
SB2019080601
and 14 more
#VU18967 - Cleartext Transmission of Sensitive Information
CVE-2019-12781
CWE-319 Medium
No
No
1.11.22, 2.1.10, 2.2.3 02.07.2019 SB2019070211
SB2019070601
SB2019070602
and 8 more
#VU18672 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-12308
CWE-79 Low
No
No
1.11.21, 2.1.9, 2.2.2 04.06.2019 SB2019060403
SB2019060404
SB2019060406
and 10 more
#VU18092 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2019-11358
CWE-1321 Low
Available
No
2.1.9, 2.2.2 28.03.2019 SB2019032804
SB2019041026
SB2019041801
and 155 more
#VU17717 - Resource exhaustion
CVE-2019-6975
CWE-400 Low
No
No
1.11.19, 2.0.11, 2.1.6 15.02.2019 SB2019021505
SB2019021814
SB2019070501
and 8 more
#VU16832 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2019-3498
CWE-451 Low
No
No
1.11.18, 2.0.10, 2.1.5 07.01.2019 SB2019010703
SB2019010907
SB2019011001
and 7 more
#VU31195 - Insufficiently Protected Credentials
CVE-2018-16984
CWE-522 Medium
No
No
2.1.2 02.10.2018 SB2018100210
SB2018100114
#VU14175 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2018-14574
CWE-601 Low
No
No
1.11.15, 2.0.8 01.08.2018 SB2018080209
SB2018080301
SB2018080401
and 12 more
#VU10952 - Improper input validation
CVE-2018-7536
CWE-20 Low
No
No
- 13.03.2018 SB2018030605
SB2018030608
SB2018030609
and 12 more


Showing elements 81 - 100 out of 137