Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Trustwave

First CVE: Jun 3, 2009Active for: 17 yearsTotal CVEs: 18
40.3
VTI Score
Medium

Trustwave's vulnerability footprint centers on a focused set of security-focused products, including web application firewalls, email protection, and secure web gateway solutions that sit within critical request-handling infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes with an elevated share reaching critical severity and a marked tendency toward public exploit availability, while the recurring weakness classes—including buffer overflows, NULL pointer dereferences, and encoding errors—reflect the parsing and memory-safety demands of inline security appliances. Defenders should prioritize updates for internet-facing gateway and filtering products, as compromise of such components can undermine downstream security controls; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Trustwave over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2009
17 years ago
Most Recent CVE
May 21, 2025
429 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-18001CRITICAL
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain rem
Dec 31, 20179.847NOYES
CVE-2012-4528MEDIUM
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart requ
Dec 28, 20125.033NOYES
CVE-2009-1902MEDIUM
The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header na
Jun 3, 20095.030NOYES
CVE-2013-2765MEDIUM
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption)
Jul 15, 20135.028NOYES
CVE-2021-42717HIGH
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to se
Dec 7, 20217.526NONO
CVE-2025-47947HIGH
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of servic
May 21, 20257.525NONO
CVE-2023-24021HIGH
Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall w
Jan 20, 20237.525NONO
CVE-2025-27110HIGH
Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional
Feb 25, 20257.524NONO
CVE-2022-48279HIGH
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-3
Jan 20, 20237.524NONO
CVE-2014-2727CRITICAL
The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.
Feb 19, 20209.824NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
50%
39%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (44.4%)
Unknown10 (55.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (44.4%)
High0 (0.0%)
Unknown10 (55.6%)
User Interaction
None8 (44.4%)
Unknown10 (55.6%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (44.4%)
Unknown10 (55.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
22.2% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Trustwave.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Trustwave — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Trustwave's Products

View all 3 CNAs →

Top CWEs