Products: 5
    Vulnerabilities: 17
    Known Exploited: 0
    4
    Critical Level Threats
    6
    High Level Threats
    7
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-50969

    Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability than CVE-2021-45468.

    Last Modified: Apr 15, 2026
    Published: Mar 28, 2024

    CVE-2021-45468

    Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAF security controls and send malicious HTTP POST requests to web servers behind the WAF.

    Last Modified: Nov 21, 2024
    Published: Jan 14, 2022

    CVE-2011-5266

    Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.

    Last Modified: Nov 21, 2024
    Published: Jan 08, 2020

    CVE-2018-16660

    A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to execute arbitrary OS commands on a vulnerable installation.

    Last Modified: Nov 21, 2024
    Published: Apr 25, 2019

    CVE-2018-5413

    Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privilege escalation.

    Last Modified: Nov 21, 2024
    Published: Jan 10, 2019
    Items Per Page