Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Modsecurity HIGH 8.6
CVE-2026-52747

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-da…

Fix: 3.0.16+
Fix from $1,950 2026-07-10
Modsecurity MEDIUM 5.3
CVE-2026-52761

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8t…

Fix: after 3.0.15
Fix from $1,600 2026-07-10
Modsecurity HIGH 7.5
CVE-2026-42268

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is …

Fix: 3.0.15+
Fix from $1,950 2026-05-12
Modsecurity HIGH 7.5
CVE-2026-30923

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the…

Fix: 3.0.15+
Fix from $1,950 2026-05-05
Owasp Blt HIGH 8.8
CVE-2026-40316

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 …

Fix: after 2.1
Fix from $1,950 2026-04-15
Owasp Modsecurity Core Rule Set HIGH 7.5
CVE-2026-33691

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 a…

Fix: 3.3.9 / 4.25.0+
Fix from $1,950 2026-04-02
Defectdojo MEDIUM 6.5
CVE-2026-3816

A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parse…

Fix: 2.56.0+
Fix from $1,600 2026-03-09
Owasp Modsecurity Core Rule Set MEDIUM 5.3
CVE-2026-21876EPSS 13%

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 …

Fix: 3.3.8 / 4.22.0+
Fix from $1,600 2026-01-08
Faction CRITICAL 9.8
CVE-2025-66022

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension fra…

Fix: 1.7.1+
Fix from $2,300 2025-11-26
Java Html Sanitizer MEDIUM 6.1
CVE-2025-66021

OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications…

No fix yet
Fix from $1,600 2025-11-26
Modsecurity MEDIUM 6.1
CVE-2025-54571

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attac…

Fix: 2.9.12+
Fix from $1,600 2025-08-06
Modsecurity HIGH 7.5
CVE-2025-48866

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a den…

Fix: 2.9.10+
Fix from $1,950 2025-06-02
Defectdojo HIGH 8.8
CVE-2023-48171

An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

Fix: 1.5.3.1+
Fix from $1,950 2024-08-12
Modsecurity HIGH 8.6
CVE-2024-1019

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSec…

Fix: 3.0.12+
Fix from $1,950 2024-01-30
Dependency Check MEDIUM 5.3
CVE-2024-23686

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an att…

Fix: 9.0.6+
Fix from $1,600 2024-01-19
Modsecurity HIGH 7.5
CVE-2023-38285

Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.

Fix: 3.0.10+
Fix from $1,950 2023-07-26
Coreruleset CRITICAL 9.8
CVE-2023-38199

coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might a…

Fix: after 3.3.4
Fix from $2,300 2023-07-13
Modsecurity HIGH 7.5
CVE-2023-28882

Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a seg…

Fix: 3.0.9+
Fix from $1,950 2023-04-28
Nodegoat HIGH 7.5
CVE-2021-4247

A vulnerability has been found in OWASP NodeGoat and classified as problematic. This vulnerability affects unknown code of the file app/routes/resear…

Fix: 2021-01-26+
Fix from $1,950 2022-12-18
Dependency Track Frontend MEDIUM 5.4
CVE-2022-39350

@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organiz…

Fix: 4.6.1+
Fix from $1,600 2022-10-25
Java Html Sanitizer CRITICAL 9.8
CVE-2021-42575

The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

Fix: 20211018.2+
Fix from $2,300 2021-10-18
Csrfguard HIGH 8.8
CVE-2021-28490

In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.

Fix: after 3.1.0
Fix from $1,950 2021-08-19
Enterprise Security Api For Java MEDIUM 5.9
CVE-2010-3300

It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.

Fix: 2.0+
Fix from $1,600 2021-06-22
Modsecurity MEDIUM 5.3
CVE-2019-25043

ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a…

Fix: 3.0.4+
Fix from $1,600 2021-05-06
Json Sanitizer CRITICAL 9.8
CVE-2021-23899

OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbi…

Fix: 1.2.2+
Fix from $2,300 2021-01-13
Json Sanitizer HIGH 7.5
CVE-2021-23900

OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if t…

Fix: 1.2.2+
Fix from $1,950 2021-01-13
Json Sanitizer MEDIUM 6.1
CVE-2020-13973

OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring adjacent to a SC…

Fix: 1.2.1+
Fix from $1,600 2020-06-09
Dependency Track MEDIUM 5.4
CVE-2019-1020007

Dependency-Track before 3.5.1 allows XSS.

Fix: 3.5.1+
Fix from $1,600 2019-07-29
Owasp Modsecurity Core Rule Set HIGH 7.5
CVE-2018-16384

A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a …

Fix: after 3.0.2
Fix from $1,950 2018-09-03
Modsecurity MEDIUM 6.1
CVE-2018-13065

ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to enviro…

No fix yet
Fix from $1,600 2018-07-03