Skip to content
Noroxi

OWASP records

49 published records for vendor owasp.

All records

49 records
  • The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

    CriticalCVSS 9.8No exploitEPSS 3%

    owasp · java html sanitizerOct 18, 2021

  • Path Traversal in ESAPI

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    owasp · enterprise security apiApr 25, 2022

  • OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a tr

    CriticalCVSS 9.8No exploitEPSS 3%

    owasp · owasp modsecurity core rule setNov 5, 2021

  • OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input.

    CriticalCVSS 9.8No exploitEPSS 2%

    owasp · json-sanitizerJan 13, 2021

  • Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header

    CriticalCVSS 9.8No exploitEPSS 1%

    owasp · owasp modsecurity core rule setSep 20, 2022

  • Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability.

    CriticalCVSS 9.8No exploitEPSS 1%

    owasp · owasp modsecurity core rule setSep 2, 2022

  • Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encodi

    CriticalCVSS 9.8No exploitEPSS 1%

    owasp · owasp modsecurity core rule setSep 20, 2022

  • coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms.

    CriticalCVSS 9.8No exploitEPSS 1%

    owasp · corerulesetJul 12, 2023

  • FACTION Unauthenticated Custom Extension Upload leads to RCE

    CriticalCVSS 9.8No exploitEPSS 1%

    owasp · factionNov 25, 2025

  • An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

    HighCVSS 8.8No exploitEPSS 1%

    owasp · defectdojoAug 12, 2024

  • OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow

    HighCVSS 8.8No exploitEPSS 1%

    owasp · owasp bltApr 15, 2026

  • In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.

    HighCVSS 8.8No exploitEPSS 1%

    owasp · csrfguardAug 19, 2021

  • CVE-2024-1019
    34Monitor

    WAF bypass of the ModSecurity v3 release line

    HighCVSS 8.6No exploitEPSS 1%

    owasp · modsecurityJan 30, 2024

  • ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass

    HighCVSS 8.6No exploitEPSS 0%

    owasp · modsecurityJul 10, 2026

  • OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization

    HighCVSS 8.6No exploitEPSS 0%

    owasp · java html sanitizerNov 25, 2025

  • OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filena

    HighCVSS 7.8Proof of conceptEPSS 2%

    owasp · dependency-checkJun 7, 2018

  • libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query strings

    HighCVSS 8.2No exploitEPSS 1%

    owasp · modsecurityMay 5, 2026

  • ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators

    HighCVSS 8.2No exploitEPSS 0%

    owasp · modsecurityMay 12, 2026

  • ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.

    HighCVSS 7.5Proof of conceptEPSS 3%

    owasp · modsecurityDec 7, 2021

  • Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request.

    HighCVSS 7.5No exploitEPSS 3%

    owasp · modsecurityOct 6, 2020

  • Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to

    HighCVSS 7.5No exploitEPSS 3%

    owasp · modsecurityJan 21, 2020

  • OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input.

    HighCVSS 7.5No exploitEPSS 2%

    owasp · json-sanitizerJan 13, 2021

  • A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} wher

    HighCVSS 7.5No exploitEPSS 2%

    owasp · owasp modsecurity core rule setSep 2, 2018

  • OWASP CRS: Whitespace padding in filenames bypasses file upload extension checks

    HighCVSS 7.5Proof of conceptEPSS 2%

    owasp · owasp modsecurity core rule setApr 2, 2026

  • Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte range

    HighCVSS 7.5No exploitEPSS 1%

    owasp · owasp modsecurity core rule setSep 20, 2022