Skip to main content

Vendor archive

owasp CVEs

Beta · best-effort

49 CVEs tagged to vendor owasp7 Critical, 23 High, 16 Medium, 3 Low, 0 Unrated.

CVE-2026-52761

Published Jul 10, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src…

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-52747

Published Jul 10, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libm…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-42268

Published May 12, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::o…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30923

Published May 5, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project. A seg…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-40316

Published Apr 15, 2026

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability i…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33691

Published Apr 2, 2026

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identi…

CVSS 6.8 · Medium
evidence mentions
11
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-3816

Published Mar 9, 2026

A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parser.py of the component SonarQub…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
33.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-21876

Published Jan 8, 2026

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 92…

CVSS 9.3 · Critical
evidence mentions
10
Buzz score
40.5
Vendor/product tagsBeta · best-effort

CVE-2025-66022

Published Nov 26, 2025

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension framework permits untrusted exten…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66021

Published Nov 26, 2025

OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against XSS.…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54571

Published Aug 6, 2025

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can override the HTTP resp…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48866

Published Jun 2, 2025

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48171

Published Aug 12, 2024

An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1019

Published Jan 30, 2024

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encod…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23686

Published Jan 19, 2024

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API K…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2023-38199

Published Jul 13, 2023

coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might allow attackers to bypass a WAF…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-28882

Published Apr 28, 2023

Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a segfault in the Transaction class…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-4247

Published Dec 18, 2022

A vulnerability has been found in OWASP NodeGoat and classified as problematic. This vulnerability affects unknown code of the file app/routes/research.js of the component Query P…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39351

Published Oct 25, 2022

Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Prior to version 4.6.0, performing an API req…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39350

Published Oct 25, 2022

@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 49 CVEsPage 1 of 2