-Infinity
0

OWASP DefectDojoOWASP DefectDojo API/Web serializers.py UserSerializer privileges management

Risk 46
Severity
2.1
First published (updated )

ModSecurity modsecurityModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass

Risk 49
Severity
8.6
First published (updated )

ModSecurity modsecurityModSecurity: Transformation utf8toUnicode produces wrong output on i386 architecture

Risk 30
Severity
5.8
First published (updated )

OWASP Dependency-Track 5.0End of life details

First published (updated )

ModSecurity Libmodsecurity3ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators

Risk 43
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OWASP Owasp BltOWASP BLT: pre-commit-fix.yaml executes untrusted fork code via pull_request_target

Risk 77
Severity
8.8
First published (updated )

ModSecurity Libmodsecurity3libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query strings

Risk 43
Severity
8.2
First published (updated )

OWASP DefectDojoOWAP DefectDojo Benchmark/Engagement/Product/Survey authorization

Risk 33
Severity
2.1
EPSS
0.02%
First published (updated )

oss-sec[CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability

oss-sec[CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-sec[CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability

oss-sec[CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability

OWASP Owasp BltOWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow

Risk 77
Severity
8.8
First published (updated )

OWASP OWASP ModSecurity Core Rule SetOWASP CRS: Whitespace padding in filenames bypasses file upload extension checks

Risk 47
Severity
7.5
First published (updated )

oss-sec[CVE-2026-33691] OWASP CRS whitespace padding bypass vulnerability

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/defectdojoOWASP DefectDojo SonarQubeParser/MSDefenderParser parser.py input_zip.read denial of service

Risk 27
Severity
5.3
EPSS
0.02%
First published (updated )

OWASP Dependency-Track 4.14End of life details

EOL
Dec 9, 2026
First published (updated )

owasp/corerulesetOWASP CRS has multipart bypass using multiple content-type parts

Risk 65
Severity
9.3
EPSS
0.04%
First published (updated )

FACTION FACTIONFACTION Unauthenticated Custom Extension Upload leads to RCE

Risk 86
Severity
9.8
First published (updated )

maven/com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizerOWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization

Risk 61
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ModSecurity modsecurityModSecurity's Insufficient Return Value Handling can Lead to XSS and Source Code Disclosure

Risk 33
Severity
6.9
First published (updated )

ModSecurity modsecurityModSecurity has possible DoS vulnerability in sanitiseArg action

Risk 31
Severity
7.5
EPSS
0.06%
First published (updated )

OWASP Dependency-Track 4.13Reached end of life

EOL
Mar 9, 2026
First published (updated )

go/github.com/corazawaf/coraza/v3OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`

Risk 26
Severity
5.4
EPSS
0.04%
First published (updated )

OWASP Dependency-Track 4.12Reached end of life

EOL
Apr 7, 2025
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OWASP Dependency-Track 4.12Reached end of life

EOL
Apr 7, 2025
First published (updated )

OWASP Dependency-Track 4.11Reached end of life

EOL
Oct 1, 2024
First published (updated )

OWASP Dependency-Track 4.11Reached end of life

EOL
Oct 1, 2024
First published (updated )

OWASP DefectDojoAn issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via th…

Risk 79
Severity
8.8
First published (updated )

OWASP ModsecurityWAF bypass of the ModSecurity v3 release line

Risk 49
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203