Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
Openresty
HIGH 7.5
CVE-2026-55233
OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exists in the upstream PROXY pro…
Fix: 1.29.2.5+
Fix from $1,950
2026-07-10
Lua Nginx Module
HIGH 7.7
CVE-2024-33452
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
Fix: after 0.10.26
Fix from $1,950
2025-04-22
Openresty
MEDIUM 5.9
CVE-2024-39702
In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Se…
Fix: 1.19.9.2 / 1.21.4.4+
Fix from $1,600
2024-07-23
Lua Nginx Module
MEDIUM 5.3
CVE-2020-36309
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or…
Fix: 0.10.16+
Fix from $1,600
2021-04-06
Openresty
CRITICAL 9.8
CVE-2018-9230EPSS 13%
In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters …
Fix: 1.13.6.1+
Fix from $2,300
2018-04-02