Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.9% | — | Owasp ModsecurityDebian Linux | 6/10/2020 | 17/6/2026 | Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are disputing our claims." The CVE suggests that there is a security issue with how ModSecurity handles regular expressions that can result in a Denial of Service condition.… | |
| Modificada | Alta (7.5) | 2.5% | — | Owasp ModsecurityFedoraproject Fedora | 21/1/2020 | 17/6/2026 | Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsive (Denial of Service) because of a flaw in Transaction::addRequestHeader in transaction.cc. | |
| Modificada | Alta (7.5) | 1.5% | — | Owasp Modsecurity Core Rule SET | 9/7/2019 | 17/6/2026 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid. | |
| Modificada | Media (5.3) | 1.6% | — | Owasp Modsecurity Core Rule SET | 21/4/2019 | 17/6/2026 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted string with $a# at the beginning and nested repetition operators. NOTE: the software maintainer… | |
| Modificada | Media (5.3) | 1.7% | — | Owasp Modsecurity Core Rule SET | 21/4/2019 | 17/6/2026 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted string with set_error_handler# at the beginning and nested repetition operators. NOTE: the software… | |
| Modificada | Media (5.3) | 1.7% | — | Owasp Modsecurity Core Rule SET | 21/4/2019 | 17/6/2026 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted string with next# at the beginning and nested repetition operators. NOTE: the software maintainer… | |
| Modificada | Media (5.3) | 1.6% | — | Owasp Modsecurity Core Rule SET | 21/4/2019 | 17/6/2026 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted string with nested repetition operators. NOTE: the software maintainer disputes that this is a… | |
| Modificada | Media (5.3) | 2.4% | — | Owasp Modsecurity Core Rule SET | 21/4/2019 | 17/6/2026 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted string with nested repetition operators. | |
| Modificada | Alta (7.5) | 1.7% | — | Owasp Modsecurity Core Rule SET | 3/9/2018 | 17/6/2026 | A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed. | |
| Modificada | Media (6.1) | 1.4% | — | Owasp Modsecurity | 3/7/2018 | 17/6/2026 | ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set configured | |
| Modificada | Media (5) | 2.7% | — | Trustwave ModsecurityDebian Linux | 15/4/2014 | 16/6/2026 | apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header. | |
| Modificada | Media (5) | 14% | — | Trustwave ModsecurityOpensuse | 15/7/2013 | 16/6/2026 | The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header. | |
| Modificada | Alta (7.5) | 4.2% | — | Trustwave ModsecurityOpensuseFedoraproject FedoraDebian Linux | 25/4/2013 | 16/6/2026 | ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability. | |
| Modificada | Media (5) | 13% | — | Trustwave ModsecurityOpensuseFedoraproject Fedora | 28/12/2012 | 16/6/2026 | The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data. | |
| Modificada | Media (4.3) | 3.3% | — | Trustwave ModsecurityOpensuseDebian LinuxOracle Http Server | 22/7/2012 | 16/6/2026 | ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as… | |
| Modificada | Media (4.3) | 2.9% | — | Trustwave ModsecurityOpensuse | 22/7/2012 | 16/6/2026 | ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a… | |
| Modificada | Media (4.3) | 3.0% | — | Trustwave ModsecurityFedoraproject Fedora | 3/6/2009 | 16/6/2026 | The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method. | |
| Modificada | Media (5) | 14% | — | Trustwave ModsecurityFedoraproject Fedora | 3/6/2009 | 16/6/2026 | The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header name, which triggers a NULL pointer dereference. | |
| Modificada | Media (5) | 1.5% | — | Breach Modsecurity | 19/12/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to… |