OWASP kayıtları
owasp üreticisine ait 49 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %81,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-404 Improper Resource Shutdown or Release3
- CWE-863 Incorrect Authorization3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-310 Cryptographic Issues2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
49 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-42575İstismar yok | The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.owasp · java html sanitizer | Kritik9,8 | — | %3,0 | 18 Eki 2021 |
40Planlayın | CVE-2022-23457Kavram kanıtı | Path Traversal in ESAPIowasp · enterprise security api · CWE-22 | Kritik9,8 | — | %2,8 | 25 Nis 2022 |
40Planlayın | CVE-2021-35368İstismar yok | OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trowasp · owasp modsecurity core rule set | Kritik9,8 | — | %2,7 | 5 Kas 2021 |
40Planlayın | CVE-2021-23899İstismar yok | OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input.owasp · json-sanitizer · CWE-611 | Kritik9,8 | — | %2,1 | 13 Oca 2021 |
39İzleyin | CVE-2022-39955İstismar yok | Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type headerowasp · owasp modsecurity core rule set · CWE-863 | Kritik9,8 | — | %1,4 | 20 Eyl 2022 |
39İzleyin | CVE-2020-22669İstismar yok | Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability.owasp · owasp modsecurity core rule set · CWE-89 | Kritik9,8 | — | %1,3 | 2 Eyl 2022 |
39İzleyin | CVE-2022-39956İstismar yok | Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encodiowasp · owasp modsecurity core rule set · CWE-863 | Kritik9,8 | — | %1,2 | 20 Eyl 2022 |
39İzleyin | CVE-2023-38199İstismar yok | coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms.owasp · coreruleset · CWE-843 | Kritik9,8 | — | %0,7 | 12 Tem 2023 |
39İzleyin | CVE-2025-66022İstismar yok | FACTION Unauthenticated Custom Extension Upload leads to RCEowasp · faction · CWE-287 | Kritik9,8 | — | %0,7 | 25 Kas 2025 |
35İzleyin | CVE-2023-48171İstismar yok | An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.owasp · defectdojo · CWE-269 | Yüksek8,8 | — | %0,6 | 12 Ağu 2024 |
35İzleyin | CVE-2026-40316İstismar yok | OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflowowasp · owasp blt · CWE-94 | Yüksek8,8 | — | %0,6 | 15 Nis 2026 |
35İzleyin | CVE-2021-28490İstismar yok | In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.owasp · csrfguard · CWE-352 | Yüksek8,8 | — | %0,5 | 19 Ağu 2021 |
34İzleyin | CVE-2024-1019İstismar yok | WAF bypass of the ModSecurity v3 release lineowasp · modsecurity · CWE-20 | Yüksek8,6 | — | %0,7 | 30 Oca 2024 |
34İzleyin | CVE-2026-52747İstismar yok | ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypassowasp · modsecurity · CWE-180 | Yüksek8,6 | — | %0,5 | 10 Tem 2026 |
34İzleyin | CVE-2025-66021İstismar yok | OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitizationowasp · java html sanitizer · CWE-79 | Yüksek8,6 | — | %0,2 | 25 Kas 2025 |
32İzleyin | CVE-2018-12036Kavram kanıtı | OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenaowasp · dependency-check · CWE-22 | Yüksek7,8 | — | %1,7 | 7 Haz 2018 |
32İzleyin | CVE-2026-30923İstismar yok | libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query stringsowasp · modsecurity · CWE-125 | Yüksek8,2 | — | %0,5 | 5 May 2026 |
32İzleyin | CVE-2026-42268İstismar yok | ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operatorsowasp · modsecurity · CWE-191 | Yüksek8,2 | — | %0,5 | 12 May 2026 |
31İzleyin | CVE-2021-42717Kavram kanıtı | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.owasp · modsecurity · CWE-674 | Yüksek7,5 | — | %3,1 | 7 Ara 2021 |
31İzleyin | CVE-2020-15598İstismar yok | Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request.owasp · modsecurity · CWE-835 | Yüksek7,5 | — | %2,9 | 6 Eki 2020 |
31İzleyin | CVE-2019-19886İstismar yok | Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to owasp · modsecurity · CWE-404 | Yüksek7,5 | — | %2,5 | 21 Oca 2020 |
31İzleyin | CVE-2021-23900İstismar yok | OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input.owasp · json-sanitizer | Yüksek7,5 | — | %2,1 | 13 Oca 2021 |
31İzleyin | CVE-2018-16384İstismar yok | A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} wherowasp · owasp modsecurity core rule set · CWE-89 | Yüksek7,5 | — | %1,7 | 2 Eyl 2018 |
30İzleyin | CVE-2026-33691Kavram kanıtı | OWASP CRS: Whitespace padding in filenames bypasses file upload extension checksowasp · owasp modsecurity core rule set · CWE-178 | Yüksek7,5 | — | %1,6 | 2 Nis 2026 |
30İzleyin | CVE-2022-39958İstismar yok | Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte rangeowasp · owasp modsecurity core rule set · CWE-863 | Yüksek7,5 | — | %1,2 | 20 Eyl 2022 |
- CVE-2021-4257540Planlayın
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
KritikCVSS 9,8İstismar yokEPSS %3owasp · java html sanitizer18 Eki 2021
- CVE-2022-2345740Planlayın
Path Traversal in ESAPI
KritikCVSS 9,8Kavram kanıtıEPSS %3owasp · enterprise security api25 Nis 2022
- CVE-2021-3536840Planlayın
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a tr
KritikCVSS 9,8İstismar yokEPSS %3owasp · owasp modsecurity core rule set5 Kas 2021
- CVE-2021-2389940Planlayın
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input.
KritikCVSS 9,8İstismar yokEPSS %2owasp · json-sanitizer13 Oca 2021
- CVE-2022-3995539İzleyin
Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header
KritikCVSS 9,8İstismar yokEPSS %1owasp · owasp modsecurity core rule set20 Eyl 2022
- CVE-2020-2266939İzleyin
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1owasp · owasp modsecurity core rule set2 Eyl 2022
- CVE-2022-3995639İzleyin
Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encodi
KritikCVSS 9,8İstismar yokEPSS %1owasp · owasp modsecurity core rule set20 Eyl 2022
- CVE-2023-3819939İzleyin
coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms.
KritikCVSS 9,8İstismar yokEPSS %1owasp · coreruleset12 Tem 2023
- CVE-2025-6602239İzleyin
FACTION Unauthenticated Custom Extension Upload leads to RCE
KritikCVSS 9,8İstismar yokEPSS %1owasp · faction25 Kas 2025
- CVE-2023-4817135İzleyin
An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.
YüksekCVSS 8,8İstismar yokEPSS %1owasp · defectdojo12 Ağu 2024
- CVE-2026-4031635İzleyin
OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow
YüksekCVSS 8,8İstismar yokEPSS %1owasp · owasp blt15 Nis 2026
- CVE-2021-2849035İzleyin
In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.
YüksekCVSS 8,8İstismar yokEPSS %1owasp · csrfguard19 Ağu 2021
- CVE-2024-101934İzleyin
WAF bypass of the ModSecurity v3 release line
YüksekCVSS 8,6İstismar yokEPSS %1owasp · modsecurity30 Oca 2024
- CVE-2026-5274734İzleyin
ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass
YüksekCVSS 8,6İstismar yokEPSS %0owasp · modsecurity10 Tem 2026
- CVE-2025-6602134İzleyin
OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
YüksekCVSS 8,6İstismar yokEPSS %0owasp · java html sanitizer25 Kas 2025
- CVE-2018-1203632İzleyin
OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filena
YüksekCVSS 7,8Kavram kanıtıEPSS %2owasp · dependency-check7 Haz 2018
- CVE-2026-3092332İzleyin
libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query strings
YüksekCVSS 8,2İstismar yokEPSS %1owasp · modsecurity5 May 2026
- CVE-2026-4226832İzleyin
ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators
YüksekCVSS 8,2İstismar yokEPSS %0owasp · modsecurity12 May 2026
- CVE-2021-4271731İzleyin
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.
YüksekCVSS 7,5Kavram kanıtıEPSS %3owasp · modsecurity7 Ara 2021
- CVE-2020-1559831İzleyin
Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request.
YüksekCVSS 7,5İstismar yokEPSS %3owasp · modsecurity6 Eki 2020
- CVE-2019-1988631İzleyin
Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to
YüksekCVSS 7,5İstismar yokEPSS %3owasp · modsecurity21 Oca 2020
- CVE-2021-2390031İzleyin
OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input.
YüksekCVSS 7,5İstismar yokEPSS %2owasp · json-sanitizer13 Oca 2021
- CVE-2018-1638431İzleyin
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} wher
YüksekCVSS 7,5İstismar yokEPSS %2owasp · owasp modsecurity core rule set2 Eyl 2018
- CVE-2026-3369130İzleyin
OWASP CRS: Whitespace padding in filenames bypasses file upload extension checks
YüksekCVSS 7,5Kavram kanıtıEPSS %2owasp · owasp modsecurity core rule set2 Nis 2026
- CVE-2022-3995830İzleyin
Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte range
YüksekCVSS 7,5İstismar yokEPSS %1owasp · owasp modsecurity core rule set20 Eyl 2022