Modwsgi
2 CVEs tracked since 2014. Since May 2014, none of them reached CISA KEV.
Modwsgi CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2014-05 | 1 | 0 |
| 2014-06 | null or fewer | |
| 2014-07 | null or fewer | |
| 2014-08 | null or fewer | |
| 2014-09 | null or fewer | |
| 2014-10 | null or fewer | |
| 2014-11 | null or fewer | |
| 2014-12 | 1 | 0 |
Products
The products that kept showing up in Modwsgi's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 4 most recently published vulnerabilities affecting Modwsgi.
- CVE-2022-2255A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI applicati...7.5
- CVE-2014-0242mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may h...7.5
- CVE-2014-8583mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecif...6.9
- CVE-2014-0240The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain p...6.2
The record
- Peak rank
- #173 in May 2014
- Busiest month shown
- May 2014, 1 CVEs
- Months with a KEV entry
- 0 since May 2014
- Monthly snapshots
- 2 since 2014