Vulnerabilities

Last updated 4 hours ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
github.com/corazawaf/coraza/v3 Coraza: Silent argument drop at ArgumentLimit allows bypass of ARGS-targeted rules via parameter flooding High Risk 7.2 5 hours ago 5 hours ago
github.com/corazawaf/coraza/v3 Coraza: Native audit-log format allows CRLF injection and log forgery via request body and header fields Medium Risk 5.8 5 hours ago 5 hours ago
github.com/corazawaf/coraza/v3 Coraza: Truncated multipart body bypasses MULTIPART_STRICT_ERROR (rule 200003) via silent io.ErrUnexpectedEOF handling Medium Risk 5.8 5 hours ago 5 hours ago
github.com/corazawaf/coraza/v3 OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` in github.com/corazawaf/coraza Unknown 1 year ago 7 months ago
github.com/corazawaf/coraza/v3 OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME` Medium Risk 5.4 1 year ago 1 year ago
github.com/corazawaf/coraza/v3 Denial of service in github.com/corazawaf/coraza/v2 and v3 Unknown 3 years ago 2 years ago
github.com/corazawaf/coraza/v3 Coraza has potential denial of service vulnerability High Risk 7.5 3 years ago 2 years ago