Vulnerabilities (CVE)

Filtered by vendor Owasp Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-28490 1 Owasp 1 Csrfguard 2021-08-24 6.8 MEDIUM 8.8 HIGH
In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.
CVE-2018-16384 1 Owasp 1 Owasp Modsecurity Core Rule Set 2021-05-10 5.0 MEDIUM 7.5 HIGH
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed.
CVE-2021-23900 1 Owasp 1 Json-sanitizer 2021-01-19 5.0 MEDIUM 7.5 HIGH
OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if the application is not prepared to handle these situations.
CVE-2018-12036 1 Owasp 1 Dependency-check 2018-07-27 6.8 MEDIUM 7.8 HIGH
OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenames.