trustwave records
18 published records for vendor trustwave.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 61.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-255 Credentials Management Errors2
- CWE-476 NULL Pointer Dereference2
- CWE-170 Improper Null Termination1
- CWE-172 Encoding Error1
- CWE-306 Missing Authentication for Critical Function1
- CWE-436 Interpretation Conflict1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2017-18001Proof of concept | Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorizetrustwave · secure web gateway · CWE-306 | Critical9.8 | — | 13.8% | Dec 31, 2017 |
40Plan | CVE-2014-2727No exploit | The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.trustwave · mailmarshal · CWE-78 | Critical9.8 | — | 1.9% | Feb 19, 2020 |
31Monitor | CVE-2013-1915No exploit | ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of servitrustwave · modsecurity · CWE-611 | High7.5 | — | 4.2% | Apr 25, 2013 |
31Monitor | CVE-2021-42717Proof of concept | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.owasp · modsecurity · CWE-674 | High7.5 | — | 3.1% | Dec 7, 2021 |
31Monitor | CVE-2025-27110No exploit | Libmodsecurity3 has possible bypass of encoded HTML entitiestrustwave · modsecurity · CWE-172 | High7.9 | — | 0.5% | Feb 25, 2025 |
30Monitor | CVE-2022-48279No exploit | In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewowasp · modsecurity · CWE-436 | High7.5 | — | 1.2% | Jan 20, 2023 |
30Monitor | CVE-2023-24021No exploit | Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer overtrustwave · modsecurity · CWE-170 | High7.5 | — | 0.9% | Jan 20, 2023 |
30Monitor | CVE-2024-46292No exploit | A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name paratrustwave · modsecurity · CWE-120 | High7.5 | — | 0.8% | Oct 9, 2024 |
30Monitor | CVE-2025-47947No exploit | ModSecurity Has Possible DoS Vulnerabilitytrustwave · modsecurity · CWE-1050 | High7.5 | — | 0.6% | May 21, 2025 |
24Monitor | CVE-2009-1902Proof of concept | The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapotrustwave · modsecurity · CWE-476 | Medium5.0 | — | 13.7% | Jun 3, 2009 |
24Monitor | CVE-2013-2765Proof of concept | The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereferencapache · http server · CWE-476 | Medium5.0 | — | 13.7% | Jul 15, 2013 |
24Monitor | CVE-2012-4528Proof of concept | The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data totrustwave · modsecurity | Medium5.0 | — | 12.5% | Dec 28, 2012 |
21Monitor | CVE-2013-5705No exploit | apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalizetrustwave · modsecurity | Medium5.0 | — | 2.7% | Apr 15, 2014 |
20Monitor | CVE-2011-1906No exploit | Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier ftrustwave · webdefend · CWE-255 | Medium5.0 | — | 1.1% | May 5, 2011 |
20Monitor | CVE-2011-0756No exploit | The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote atttrustwave · webdefend · CWE-255 | Medium5.0 | — | 1.1% | May 4, 2011 |
18Monitor | CVE-2012-2751No exploit | ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in thtrustwave · modsecurity | Medium4.3 | — | 3.3% | Jul 22, 2012 |
18Monitor | CVE-2009-1903No exploit | The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a rtrustwave · modsecurity | Medium4.3 | — | 3.0% | Jun 3, 2009 |
18Monitor | CVE-2009-5031No exploit | ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filteritrustwave · modsecurity · CWE-79 | Medium4.3 | — | 2.9% | Jul 22, 2012 |
- CVE-2017-1800143Plan
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorize
CriticalCVSS 9.8Proof of conceptEPSS 14%trustwave · secure web gatewayDec 31, 2017
- CVE-2014-272740Plan
The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.
CriticalCVSS 9.8No exploitEPSS 2%trustwave · mailmarshalFeb 19, 2020
- CVE-2013-191531Monitor
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of servi
HighCVSS 7.5No exploitEPSS 4%trustwave · modsecurityApr 25, 2013
- CVE-2021-4271731Monitor
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.
HighCVSS 7.5Proof of conceptEPSS 3%owasp · modsecurityDec 7, 2021
- CVE-2025-2711031Monitor
Libmodsecurity3 has possible bypass of encoded HTML entities
HighCVSS 7.9No exploitEPSS 0%trustwave · modsecurityFeb 25, 2025
- CVE-2022-4827930Monitor
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firew
HighCVSS 7.5No exploitEPSS 1%owasp · modsecurityJan 20, 2023
- CVE-2023-2402130Monitor
Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over
HighCVSS 7.5No exploitEPSS 1%trustwave · modsecurityJan 20, 2023
- CVE-2024-4629230Monitor
A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name para
HighCVSS 7.5No exploitEPSS 1%trustwave · modsecurityOct 9, 2024
- CVE-2025-4794730Monitor
ModSecurity Has Possible DoS Vulnerability
HighCVSS 7.5No exploitEPSS 1%trustwave · modsecurityMay 21, 2025
- CVE-2009-190224Monitor
The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapo
MediumCVSS 5.0Proof of conceptEPSS 14%trustwave · modsecurityJun 3, 2009
- CVE-2013-276524Monitor
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereferenc
MediumCVSS 5.0Proof of conceptEPSS 14%apache · http serverJul 15, 2013
- CVE-2012-452824Monitor
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to
MediumCVSS 5.0Proof of conceptEPSS 13%trustwave · modsecurityDec 28, 2012
- CVE-2013-570521Monitor
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalize
MediumCVSS 5.0No exploitEPSS 3%trustwave · modsecurityApr 15, 2014
- CVE-2011-190620Monitor
Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier f
MediumCVSS 5.0No exploitEPSS 1%trustwave · webdefendMay 5, 2011
- CVE-2011-075620Monitor
The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote att
MediumCVSS 5.0No exploitEPSS 1%trustwave · webdefendMay 4, 2011
- CVE-2012-275118Monitor
ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in th
MediumCVSS 4.3No exploitEPSS 3%trustwave · modsecurityJul 22, 2012
- CVE-2009-190318Monitor
The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a r
MediumCVSS 4.3No exploitEPSS 3%trustwave · modsecurityJun 3, 2009
- CVE-2009-503118Monitor
ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filteri
MediumCVSS 4.3No exploitEPSS 3%trustwave · modsecurityJul 22, 2012