Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Modsecurity HIGH 7.5
CVE-2025-47947

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are…

Fix: 2.9.9+
Fix from $1,950 2025-05-21
Modsecurity HIGH 7.5
CVE-2025-27110

Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web tr…

No fix yet
Fix from $1,950 2025-02-25
Modsecurity HIGH 7.5
CVE-2024-46292

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NO…

Mitigation only
Fix from $1,950 2024-10-09
Mailmarshal CRITICAL 9.8
CVE-2014-2727

The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.

Fix: 7.2+
Fix from $2,300 2020-02-19
Secure Web Gateway CRITICAL 9.8
CVE-2017-18001EPSS 14%

Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys da…

Fix: after 11.8.0.27
Fix from $2,300 2017-12-31
Modsecurity MEDIUM 5.0
CVE-2013-2765EPSS 14%

The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, proces…

Fix: 2.7.4+
Fix from $1,600 2013-07-15
Webdefend MEDIUM 5.0
CVE-2011-1906

Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier for remote…

Fix: after 5.0
Fix from $1,600 2011-05-05
Webdefend MEDIUM 5.0
CVE-2011-0756

The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to…

Fix: after 3.0
Fix from $1,600 2011-05-05