Filter
-Infinity
0

Dependency-Track 4.13End of life

First published (updated )

go/github.com/corazawaf/coraza/v3OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`

EPSS
0.04%
First published (updated )

Dependency-Track 4.12Reached end of life

First published (updated )

Dependency-Track 4.12Reached end of life

First published (updated )

Dependency-Track 4.11Reached end of life

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Dependency-Track 4.11Reached end of life

First published (updated )

OWASP DefectDojoAn issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via th…

8.8
First published (updated )

OWASP Dependency-CheckDependencyCheck Debug Mode Logging of NVD API Key

EPSS
0.05%
First published (updated )

Dependency-Track 4.10Reached end of life

First published (updated )

Dependency-Track 4.10Reached end of life

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Dependency-Track 4.9Reached end of life

First published (updated )

Dependency-Track 4.9Reached end of life

First published (updated )

OWASP ModSecurity Core Rule Setcoreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not block multiple Content-Type…

First published (updated )

Dependency-Track 4.8Reached end of life

First published (updated )

Dependency-Track 4.8Reached end of life

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

OWASP NodeGoatOWASP NodeGoat Query Parameter research.js denial of service

7.5
First published (updated )

Dependency-Track 4.7Reached end of life

First published (updated )

Dependency-Track 4.7Reached end of life

First published (updated )

Dependency-TrackDependency-Track vulnerable to logging of API keys in clear text when handling API requests using keys with insufficient permissions

First published (updated )

OWASP Dependency-Track@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Red Hat FedoraResponse body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte range

7.5
First published (updated )

Red Hat FedoraResponse body bypass in OWASP ModSecurity Core Rule Set via a specialy crafted charset in the HTTP Accept header

7.5
First published (updated )

Red Hat FedoraPartial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header

First published (updated )

Red Hat FedoraPartial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encoding header

First published (updated )

OWASP ModSecurity Core Rule SetSQL Injection

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Oracle WebLogic ServerCross-site Scripting in org.owasp.esapi:esapi -- antisamy-esapi.xml configuration file

First published (updated )

Oracle WebLogic ServerPath Traversal in ESAPI

First published (updated )

OWASP Zed Attack ProxyOWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTT…

First published (updated )

OWASP ModSecurity Core Rule SetOWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is af…

First published (updated )

Oracle UnifierThe OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with t…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203