İçeriğe atla
Noroxi

OWASP kayıtları

owasp üreticisine ait 49 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%81,6
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

49 kayıt
  • CVE-2021-42575
    40Planlayın

    The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

    KritikCVSS 9,8İstismar yokEPSS %3

    owasp · java html sanitizer18 Eki 2021

  • CVE-2022-23457
    40Planlayın

    Path Traversal in ESAPI

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    owasp · enterprise security api25 Nis 2022

  • CVE-2021-35368
    40Planlayın

    OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a tr

    KritikCVSS 9,8İstismar yokEPSS %3

    owasp · owasp modsecurity core rule set5 Kas 2021

  • CVE-2021-23899
    40Planlayın

    OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input.

    KritikCVSS 9,8İstismar yokEPSS %2

    owasp · json-sanitizer13 Oca 2021

  • CVE-2022-39955
    39İzleyin

    Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header

    KritikCVSS 9,8İstismar yokEPSS %1

    owasp · owasp modsecurity core rule set20 Eyl 2022

  • CVE-2020-22669
    39İzleyin

    Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %1

    owasp · owasp modsecurity core rule set2 Eyl 2022

  • CVE-2022-39956
    39İzleyin

    Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encodi

    KritikCVSS 9,8İstismar yokEPSS %1

    owasp · owasp modsecurity core rule set20 Eyl 2022

  • CVE-2023-38199
    39İzleyin

    coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms.

    KritikCVSS 9,8İstismar yokEPSS %1

    owasp · coreruleset12 Tem 2023

  • CVE-2025-66022
    39İzleyin

    FACTION Unauthenticated Custom Extension Upload leads to RCE

    KritikCVSS 9,8İstismar yokEPSS %1

    owasp · faction25 Kas 2025

  • CVE-2023-48171
    35İzleyin

    An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

    YüksekCVSS 8,8İstismar yokEPSS %1

    owasp · defectdojo12 Ağu 2024

  • CVE-2026-40316
    35İzleyin

    OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow

    YüksekCVSS 8,8İstismar yokEPSS %1

    owasp · owasp blt15 Nis 2026

  • CVE-2021-28490
    35İzleyin

    In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.

    YüksekCVSS 8,8İstismar yokEPSS %1

    owasp · csrfguard19 Ağu 2021

  • CVE-2024-1019
    34İzleyin

    WAF bypass of the ModSecurity v3 release line

    YüksekCVSS 8,6İstismar yokEPSS %1

    owasp · modsecurity30 Oca 2024

  • CVE-2026-52747
    34İzleyin

    ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass

    YüksekCVSS 8,6İstismar yokEPSS %0

    owasp · modsecurity10 Tem 2026

  • CVE-2025-66021
    34İzleyin

    OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization

    YüksekCVSS 8,6İstismar yokEPSS %0

    owasp · java html sanitizer25 Kas 2025

  • CVE-2018-12036
    32İzleyin

    OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filena

    YüksekCVSS 7,8Kavram kanıtıEPSS %2

    owasp · dependency-check7 Haz 2018

  • CVE-2026-30923
    32İzleyin

    libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query strings

    YüksekCVSS 8,2İstismar yokEPSS %1

    owasp · modsecurity5 May 2026

  • CVE-2026-42268
    32İzleyin

    ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators

    YüksekCVSS 8,2İstismar yokEPSS %0

    owasp · modsecurity12 May 2026

  • CVE-2021-42717
    31İzleyin

    ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    owasp · modsecurity7 Ara 2021

  • CVE-2020-15598
    31İzleyin

    Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request.

    YüksekCVSS 7,5İstismar yokEPSS %3

    owasp · modsecurity6 Eki 2020

  • CVE-2019-19886
    31İzleyin

    Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to

    YüksekCVSS 7,5İstismar yokEPSS %3

    owasp · modsecurity21 Oca 2020

  • CVE-2021-23900
    31İzleyin

    OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input.

    YüksekCVSS 7,5İstismar yokEPSS %2

    owasp · json-sanitizer13 Oca 2021

  • CVE-2018-16384
    31İzleyin

    A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} wher

    YüksekCVSS 7,5İstismar yokEPSS %2

    owasp · owasp modsecurity core rule set2 Eyl 2018

  • CVE-2026-33691
    30İzleyin

    OWASP CRS: Whitespace padding in filenames bypasses file upload extension checks

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    owasp · owasp modsecurity core rule set2 Nis 2026

  • CVE-2022-39958
    30İzleyin

    Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte range

    YüksekCVSS 7,5İstismar yokEPSS %1

    owasp · owasp modsecurity core rule set20 Eyl 2022