With the growth of the internet, web pages evolved from being simple static information providers to web sites and nowadays to web apps. Symbiotically, flaws in security followed this development which in its turn could cause devastating damages to many areas of our lives. This report researches vulnerabilities that exist in web apps nowadays, in addition to the lack of proper protection that WAFs should offer. Selected web applications and WAFs with default rulesets were put through the tests for SQLi and XSS attacks. The conclusion that was derived was that the WAFs in question were not secure enough and that in fact there are issues with out-of-the-box rules that come with Web Application Firewalls in general.