Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.41% | — | Owasp Modsecurity | 10/7/2026 | 14/7/2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386 architecture because snprintf uses sizeof on a char pointer rather… | |
| Analizada | Alta (8.6) | 0.48% | — | Owasp Modsecurity | 10/7/2026 | 14/7/2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_POST because… | |
| Analizada | Alta (8.2) | 0.49% | — | Owasp Modsecurity | 12/5/2026 | 17/6/2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF,… | |
| Analizada | Alta (8.2) | 0.52% | — | Owasp Modsecurity | 5/5/2026 | 25/7/2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project. A segmentation fault occurs when a rule using the t:hexDecode transformation inspects a query string parameter containing a single character. An… | |
| Modificada | Alta (7.5) | 1.6% | — | Owasp Modsecurity Core Rule SET | 2/4/2026 | 24/7/2026 | The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the… | |
| Modificada | Media (5.3) | 18% | — | Owasp Modsecurity Core Rule SET | 8/1/2026 | 17/6/2026 | The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests with multiple parts. When the first rule in a chain iterates over a collection (like… | |
| Modificada | Media (6.9) | 0.28% | — | Owasp Modsecurity | 6/8/2025 | 17/6/2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can override the HTTP response’s Content-Type, which could lead to several issues depending on the HTTP scenario. For example, we have demonstrated the potential for… | |
| Aplazada | Media (6.5) | 0.36% | — | ModsecurityAI | 2/7/2025 | 17/6/2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.8 to before 2.9.11, an empty XML tag can cause a segmentation fault. If SecParseXmlIntoArgs is set to On or OnlyArgs, and the request type is application/xml, and at least one XML tag is empty… | |
| Analizada | Alta (7.5) | 0.83% | — | Owasp Modsecurity | 2/6/2025 | 17/6/2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to… | |
| Analizada | Alta (7.5) | 0.60% | — | Trustwave Modsecurity | 21/5/2025 | 17/6/2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable released versions): when the payload's content type is `application/json`, and there is at least one rule… | |
| Analizada | Alta (7.9) | 0.48% | — | Trustwave Modsecurity | 25/2/2025 | 17/6/2026 | Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. A bug that exists only in Libmodsecurity3 version 3.0.13 means that, in 3.0.13, Libmodsecurity3 can't decode… | |
| Analizada | Alta (7.5) | 0.82% | — | Trustwave Modsecurity | 9/10/2024 | 17/6/2026 | A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large… | |
| Modificada | Alta (8.6) | 0.69% | — | Owasp Modsecurity | 30/1/2024 | 17/6/2026 | ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path component from the optional query string component. This results in… | |
| Modificada | Alta (7.5) | 0.90% | — | Owasp Modsecurity | 26/7/2023 | 17/6/2026 | Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity. | |
| Modificada | Alta (7.5) | 0.73% | — | Owasp Modsecurity | 28/4/2023 | 17/6/2026 | Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a segfault in the Transaction class for some configurations. | |
| Modificada | Alta (7.5) | 0.91% | — | Trustwave ModsecurityDebian Linux | 20/1/2023 | 17/6/2026 | Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILES_TMP_CONTENT collection. | |
| Modificada | Alta (7.5) | 1.2% | — | Owasp ModsecurityTrustwave ModsecurityDebian Linux | 20/1/2023 | 17/6/2026 | In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase. | |
| Modificada | Alta (7.5) | 1.2% | — | Owasp Modsecurity Core Rule SETFedoraproject FedoraDebian Linux | 20/9/2022 | 17/6/2026 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, access to which would ordinarily be detected, may be exfiltrated from… | |
| Modificada | Alta (7.5) | 0.99% | — | Owasp Modsecurity Core Rule SETFedoraproject FedoraDebian Linux | 20/9/2022 | 17/6/2026 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset", this response can not be decoded by the web application firewall. A… | |
| Modificada | Crítica (9.8) | 1.2% | — | Owasp Modsecurity Core Rule SETFedoraproject FedoraDebian Linux | 20/9/2022 | 17/6/2026 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web… | |
| Modificada | Crítica (9.8) | 1.4% | — | Owasp Modsecurity Core Rule SETFedoraproject FedoraDebian Linux | 20/9/2022 | 17/6/2026 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially be exploited by declaring multiple Content-Type "charset" names and therefore… | |
| Modificada | Crítica (9.8) | 1.3% | — | Owasp Modsecurity Core Rule SETDebian Linux | 2/9/2022 | 17/6/2026 | Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications. | |
| Modificada | Alta (7.5) | 3.2% | — | Owasp ModsecurityTrustwave ModsecurityF5 Nginx Modsecurity WAFDebian Linux+2 | 7/12/2021 | 17/6/2026 | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for… | |
| Modificada | Crítica (9.8) | 2.7% | — | Owasp Modsecurity Core Rule SETFedoraproject FedoraDebian Linux | 5/11/2021 | 17/6/2026 | OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname. | |
| Modificada | Media (5.3) | 1.2% | — | Owasp Modsecurity | 6/5/2021 | 17/6/2026 | ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header. |