Записи OWASP
49 опубликованных записей вендора owasp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 81,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-404 Improper Resource Shutdown or Release3
- CWE-863 Incorrect Authorization3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-310 Cryptographic Issues2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
49 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-42575Эксплойта нет | The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.owasp · java html sanitizer | Критическая9,8 | — | 3,0 % | 18 окт. 2021 г. |
40В плане | CVE-2022-23457Proof of concept | Path Traversal in ESAPIowasp · enterprise security api · CWE-22 | Критическая9,8 | — | 2,8 % | 25 апр. 2022 г. |
40В плане | CVE-2021-35368Эксплойта нет | OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trowasp · owasp modsecurity core rule set | Критическая9,8 | — | 2,7 % | 5 нояб. 2021 г. |
40В плане | CVE-2021-23899Эксплойта нет | OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input.owasp · json-sanitizer · CWE-611 | Критическая9,8 | — | 2,1 % | 13 янв. 2021 г. |
39Наблюдать | CVE-2022-39955Эксплойта нет | Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type headerowasp · owasp modsecurity core rule set · CWE-863 | Критическая9,8 | — | 1,4 % | 20 сент. 2022 г. |
39Наблюдать | CVE-2020-22669Эксплойта нет | Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability.owasp · owasp modsecurity core rule set · CWE-89 | Критическая9,8 | — | 1,3 % | 2 сент. 2022 г. |
39Наблюдать | CVE-2022-39956Эксплойта нет | Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encodiowasp · owasp modsecurity core rule set · CWE-863 | Критическая9,8 | — | 1,2 % | 20 сент. 2022 г. |
39Наблюдать | CVE-2023-38199Эксплойта нет | coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms.owasp · coreruleset · CWE-843 | Критическая9,8 | — | 0,7 % | 12 июл. 2023 г. |
39Наблюдать | CVE-2025-66022Эксплойта нет | FACTION Unauthenticated Custom Extension Upload leads to RCEowasp · faction · CWE-287 | Критическая9,8 | — | 0,7 % | 25 нояб. 2025 г. |
35Наблюдать | CVE-2023-48171Эксплойта нет | An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.owasp · defectdojo · CWE-269 | Высокая8,8 | — | 0,6 % | 12 авг. 2024 г. |
35Наблюдать | CVE-2026-40316Эксплойта нет | OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflowowasp · owasp blt · CWE-94 | Высокая8,8 | — | 0,6 % | 15 апр. 2026 г. |
35Наблюдать | CVE-2021-28490Эксплойта нет | In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.owasp · csrfguard · CWE-352 | Высокая8,8 | — | 0,5 % | 19 авг. 2021 г. |
34Наблюдать | CVE-2024-1019Эксплойта нет | WAF bypass of the ModSecurity v3 release lineowasp · modsecurity · CWE-20 | Высокая8,6 | — | 0,7 % | 30 янв. 2024 г. |
34Наблюдать | CVE-2026-52747Эксплойта нет | ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypassowasp · modsecurity · CWE-180 | Высокая8,6 | — | 0,5 % | 10 июл. 2026 г. |
34Наблюдать | CVE-2025-66021Эксплойта нет | OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitizationowasp · java html sanitizer · CWE-79 | Высокая8,6 | — | 0,2 % | 25 нояб. 2025 г. |
32Наблюдать | CVE-2018-12036Proof of concept | OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenaowasp · dependency-check · CWE-22 | Высокая7,8 | — | 1,7 % | 7 июн. 2018 г. |
32Наблюдать | CVE-2026-30923Эксплойта нет | libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query stringsowasp · modsecurity · CWE-125 | Высокая8,2 | — | 0,5 % | 5 мая 2026 г. |
32Наблюдать | CVE-2026-42268Эксплойта нет | ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operatorsowasp · modsecurity · CWE-191 | Высокая8,2 | — | 0,5 % | 12 мая 2026 г. |
31Наблюдать | CVE-2021-42717Proof of concept | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.owasp · modsecurity · CWE-674 | Высокая7,5 | — | 3,1 % | 7 дек. 2021 г. |
31Наблюдать | CVE-2020-15598Эксплойта нет | Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request.owasp · modsecurity · CWE-835 | Высокая7,5 | — | 2,9 % | 6 окт. 2020 г. |
31Наблюдать | CVE-2019-19886Эксплойта нет | Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to owasp · modsecurity · CWE-404 | Высокая7,5 | — | 2,5 % | 21 янв. 2020 г. |
31Наблюдать | CVE-2021-23900Эксплойта нет | OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input.owasp · json-sanitizer | Высокая7,5 | — | 2,1 % | 13 янв. 2021 г. |
31Наблюдать | CVE-2018-16384Эксплойта нет | A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} wherowasp · owasp modsecurity core rule set · CWE-89 | Высокая7,5 | — | 1,7 % | 2 сент. 2018 г. |
30Наблюдать | CVE-2026-33691Proof of concept | OWASP CRS: Whitespace padding in filenames bypasses file upload extension checksowasp · owasp modsecurity core rule set · CWE-178 | Высокая7,5 | — | 1,6 % | 2 апр. 2026 г. |
30Наблюдать | CVE-2022-39958Эксплойта нет | Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte rangeowasp · owasp modsecurity core rule set · CWE-863 | Высокая7,5 | — | 1,2 % | 20 сент. 2022 г. |
- CVE-2021-4257540В плане
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %owasp · java html sanitizer18 окт. 2021 г.
- CVE-2022-2345740В плане
Path Traversal in ESAPI
КритическаяCVSS 9,8Proof of conceptEPSS 3 %owasp · enterprise security api25 апр. 2022 г.
- CVE-2021-3536840В плане
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a tr
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %owasp · owasp modsecurity core rule set5 нояб. 2021 г.
- CVE-2021-2389940В плане
OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %owasp · json-sanitizer13 янв. 2021 г.
- CVE-2022-3995539Наблюдать
Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %owasp · owasp modsecurity core rule set20 сент. 2022 г.
- CVE-2020-2266939Наблюдать
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %owasp · owasp modsecurity core rule set2 сент. 2022 г.
- CVE-2022-3995639Наблюдать
Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encodi
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %owasp · owasp modsecurity core rule set20 сент. 2022 г.
- CVE-2023-3819939Наблюдать
coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %owasp · coreruleset12 июл. 2023 г.
- CVE-2025-6602239Наблюдать
FACTION Unauthenticated Custom Extension Upload leads to RCE
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %owasp · faction25 нояб. 2025 г.
- CVE-2023-4817135Наблюдать
An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %owasp · defectdojo12 авг. 2024 г.
- CVE-2026-4031635Наблюдать
OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %owasp · owasp blt15 апр. 2026 г.
- CVE-2021-2849035Наблюдать
In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %owasp · csrfguard19 авг. 2021 г.
- CVE-2024-101934Наблюдать
WAF bypass of the ModSecurity v3 release line
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %owasp · modsecurity30 янв. 2024 г.
- CVE-2026-5274734Наблюдать
ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %owasp · modsecurity10 июл. 2026 г.
- CVE-2025-6602134Наблюдать
OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %owasp · java html sanitizer25 нояб. 2025 г.
- CVE-2018-1203632Наблюдать
OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filena
ВысокаяCVSS 7,8Proof of conceptEPSS 2 %owasp · dependency-check7 июн. 2018 г.
- CVE-2026-3092332Наблюдать
libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query strings
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %owasp · modsecurity5 мая 2026 г.
- CVE-2026-4226832Наблюдать
ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %owasp · modsecurity12 мая 2026 г.
- CVE-2021-4271731Наблюдать
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %owasp · modsecurity7 дек. 2021 г.
- CVE-2020-1559831Наблюдать
Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %owasp · modsecurity6 окт. 2020 г.
- CVE-2019-1988631Наблюдать
Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %owasp · modsecurity21 янв. 2020 г.
- CVE-2021-2390031Наблюдать
OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %owasp · json-sanitizer13 янв. 2021 г.
- CVE-2018-1638431Наблюдать
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} wher
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %owasp · owasp modsecurity core rule set2 сент. 2018 г.
- CVE-2026-3369130Наблюдать
OWASP CRS: Whitespace padding in filenames bypasses file upload extension checks
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %owasp · owasp modsecurity core rule set2 апр. 2026 г.
- CVE-2022-3995830Наблюдать
Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte range
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %owasp · owasp modsecurity core rule set20 сент. 2022 г.