Vulnerabilities (CVE)

Filtered by vendor Imperva Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-45468 1 Imperva 1 Web Application Firewall 2022-01-21 7.5 HIGH 9.8 CRITICAL
Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAF security controls and send malicious HTTP POST requests to web servers behind the WAF.
CVE-2011-5266 1 Imperva 1 Securesphere Web Application Firewall 2020-01-15 7.5 HIGH 9.8 CRITICAL
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.
CVE-2018-19646 1 Imperva 1 Securesphere 2019-02-04 10.0 HIGH 9.8 CRITICAL
The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because command-line arguments are mishandled.