Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.6
CVE-2026-52747
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-da…
Modsecurity
3.0.16+
MEDIUM 5.3
CVE-2026-52761
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8t…
Modsecurity
after 3.0.15
HIGH 7.5
CVE-2026-42268
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is …
Modsecurity
3.0.15+
HIGH 7.5
CVE-2026-30923
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the…
Modsecurity
3.0.15+
HIGH 8.8
CVE-2026-40316
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 …
Owasp Blt
after 2.1
HIGH 7.5
CVE-2026-33691
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 a…
Owasp Modsecurity Core Rule Set
3.3.9 / 4.25.0+
MEDIUM 6.5
CVE-2026-3816
A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parse…
Defectdojo
2.56.0+
MEDIUM 5.3
CVE-2026-21876EPSS 13%
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 …
Owasp Modsecurity Core Rule Set
3.3.8 / 4.22.0+
CRITICAL 9.8
CVE-2025-66022
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension fra…
Faction
1.7.1+
MEDIUM 6.1
CVE-2025-66021
OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications…
Java Html Sanitizer
No fix yet
MEDIUM 6.1
CVE-2025-54571
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11
and below, an attac…
Modsecurity
2.9.12+
HIGH 7.5
CVE-2025-48866
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a den…
Modsecurity
2.9.10+
HIGH 8.8
CVE-2023-48171
An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.
Defectdojo
1.5.3.1+
HIGH 8.6
CVE-2024-1019
ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSec…
Modsecurity
3.0.12+
MEDIUM 5.3
CVE-2024-23686
DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an att…
Dependency Check
9.0.6+
HIGH 7.5
CVE-2023-38285
Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.
Modsecurity
3.0.10+
CRITICAL 9.8
CVE-2023-38199
coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might a…
Coreruleset
after 3.3.4
HIGH 7.5
CVE-2023-28882
Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a seg…
Modsecurity
3.0.9+
HIGH 7.5
CVE-2021-4247
A vulnerability has been found in OWASP NodeGoat and classified as problematic. This vulnerability affects unknown code of the file app/routes/resear…
Nodegoat
2021-01-26+
MEDIUM 5.4
CVE-2022-39350
@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organiz…
Dependency Track Frontend
4.6.1+
CRITICAL 9.8
CVE-2021-42575
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
Java Html Sanitizer
20211018.2+
HIGH 8.8
CVE-2021-28490
In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.
Csrfguard
after 3.1.0
MEDIUM 5.9
CVE-2010-3300
It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.
Enterprise Security Api For Java
2.0+
MEDIUM 5.3
CVE-2019-25043
ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a…
Modsecurity
3.0.4+
CRITICAL 9.8
CVE-2021-23899
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbi…
Json Sanitizer
1.2.2+
HIGH 7.5
CVE-2021-23900
OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if t…
Json Sanitizer
1.2.2+
MEDIUM 6.1
CVE-2020-13973
OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring adjacent to a SC…
Json Sanitizer
1.2.1+
MEDIUM 5.4
CVE-2019-1020007
Dependency-Track before 3.5.1 allows XSS.
Dependency Track
3.5.1+
HIGH 7.5
CVE-2018-16384
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a …
Owasp Modsecurity Core Rule Set
after 3.0.2
MEDIUM 6.1
CVE-2018-13065
ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to enviro…
Modsecurity
No fix yet