Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2026-52747 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-da… Modsecurity 3.0.16+ Fix from $1,9502026-07-10 MEDIUM 5.3 CVE-2026-52761 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8t… Modsecurity after 3.0.15 Fix from $1,6002026-07-10 HIGH 7.5 CVE-2026-42268 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is … Modsecurity 3.0.15+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-30923 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the… Modsecurity 3.0.15+ Fix from $1,9502026-05-05 HIGH 8.8 CVE-2026-40316 OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 … Owasp Blt after 2.1 Fix from $1,9502026-04-15 HIGH 7.5 CVE-2026-33691 The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 a… Owasp Modsecurity Core Rule Set 3.3.9 / 4.25.0+ Fix from $1,9502026-04-02 MEDIUM 6.5 CVE-2026-3816 A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parse… Defectdojo 2.56.0+ Fix from $1,6002026-03-09 MEDIUM 5.3 CVE-2026-21876EPSS 13% The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 … Owasp Modsecurity Core Rule Set 3.3.8 / 4.22.0+ Fix from $1,6002026-01-08 CRITICAL 9.8 CVE-2025-66022 FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension fra… Faction 1.7.1+ Fix from $2,3002025-11-26 MEDIUM 6.1 CVE-2025-66021 OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications… Java Html Sanitizer No fix yet Fix from $1,6002025-11-26 MEDIUM 6.1 CVE-2025-54571 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attac… Modsecurity 2.9.12+ Fix from $1,6002025-08-06 HIGH 7.5 CVE-2025-48866 ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a den… Modsecurity 2.9.10+ Fix from $1,9502025-06-02 HIGH 8.8 CVE-2023-48171 An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component. Defectdojo 1.5.3.1+ Fix from $1,9502024-08-12 HIGH 8.6 CVE-2024-1019 ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSec… Modsecurity 3.0.12+ Fix from $1,9502024-01-30 MEDIUM 5.3 CVE-2024-23686 DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an att… Dependency Check 9.0.6+ Fix from $1,6002024-01-19 HIGH 7.5 CVE-2023-38285 Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity. Modsecurity 3.0.10+ Fix from $1,9502023-07-26 CRITICAL 9.8 CVE-2023-38199 coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might a… Coreruleset after 3.3.4 Fix from $2,3002023-07-13 HIGH 7.5 CVE-2023-28882 Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a seg… Modsecurity 3.0.9+ Fix from $1,9502023-04-28 HIGH 7.5 CVE-2021-4247 A vulnerability has been found in OWASP NodeGoat and classified as problematic. This vulnerability affects unknown code of the file app/routes/resear… Nodegoat 2021-01-26+ Fix from $1,9502022-12-18 MEDIUM 5.4 CVE-2022-39350 @dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organiz… Dependency Track Frontend 4.6.1+ Fix from $1,6002022-10-25 CRITICAL 9.8 CVE-2021-42575 The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements. Java Html Sanitizer 20211018.2+ Fix from $2,3002021-10-18 HIGH 8.8 CVE-2021-28490 In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token. Csrfguard after 3.1.0 Fix from $1,9502021-08-19 MEDIUM 5.9 CVE-2010-3300 It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks. Enterprise Security Api For Java 2.0+ Fix from $1,6002021-06-22 MEDIUM 5.3 CVE-2019-25043 ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a… Modsecurity 3.0.4+ Fix from $1,6002021-05-06 CRITICAL 9.8 CVE-2021-23899 OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbi… Json Sanitizer 1.2.2+ Fix from $2,3002021-01-13 HIGH 7.5 CVE-2021-23900 OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if t… Json Sanitizer 1.2.2+ Fix from $1,9502021-01-13 MEDIUM 6.1 CVE-2020-13973 OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring adjacent to a SC… Json Sanitizer 1.2.1+ Fix from $1,6002020-06-09 MEDIUM 5.4 CVE-2019-1020007 Dependency-Track before 3.5.1 allows XSS. Dependency Track 3.5.1+ Fix from $1,6002019-07-29 HIGH 7.5 CVE-2018-16384 A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a … Owasp Modsecurity Core Rule Set after 3.0.2 Fix from $1,9502018-09-03 MEDIUM 6.1 CVE-2018-13065 ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to enviro… Modsecurity No fix yet Fix from $1,6002018-07-03