Логотип exploitDog
product: "laravel"
Консоль
Логотип exploitDog

exploitDog

product: "laravel"

Количество 38

Количество 38

github логотип

GHSA-w68r-5p45-5rqp

около 4 лет назад

Improper Input Validation in Laravel

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rc8x-jrrc-frfv

около 3 лет назад

Laravel does not properly constrain the host portion of a password-reset URL

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-qvqm-h22r-4cp9

около 3 лет назад

Laravel Framework RCE Vulnerability

CVSS3: 8.1
EPSS: Высокий
github логотип

GHSA-g4q4-r6rr-r4w2

почти 3 года назад

A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206501 was assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-c7rm-w2hj-x8g3

около 3 лет назад

Guard bypass in Eloquent models affecting Laravel illuminate database component

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c2v7-j5gq-wcq4

около 3 лет назад

Laravel Sensitive Data Exposure

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-7236-phg4-48mj

почти 3 года назад

A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206688.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-5hq5-9pj6-4c2r

около 2 лет назад

A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p32-j457-pg5x

больше 4 лет назад

Query Binding Exploitation

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2v4r-7m2m-5chh

около 3 лет назад

In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.

CVSS3: 7.5
EPSS: Высокий
nvd логотип

CVE-2022-2886

почти 3 года назад

A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206688.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2022-2886

почти 3 года назад

A vulnerability, which was classified as critical, was found in Larave ...

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2022-2870

почти 3 года назад

A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206501 was assigned to this vulnerability.

CVSS3: 4.1
EPSS: Низкий
debian логотип

CVE-2022-2870

почти 3 года назад

A vulnerability was found in laravel 5.1 and classified as problematic ...

CVSS3: 4.1
EPSS: Низкий
nvd логотип

CVE-2021-28254

около 2 лет назад

A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2021-21263

больше 4 лет назад

Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a field that is normally a non-array value is an array, and that input is not validated or cast to its expected type before being passed to the query builder, an unexpected number of query bindings can be added to the query. In some situations, this will simply lead to no results being returned by the query builder; however, it is possible certain queries could be affected in a way that causes the query to return unexpected results.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2021-21263

больше 4 лет назад

Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a field that is normally a non-array value is an array, and that input is not validated or cast to its expected type before being passed to the query builder, an unexpected number of query bindings can be added to the query. In some situations, this will simply lead to no results being returned by the query builder; however, it is possible certain queries could be affected in a way that causes the query to return unexpected results.

CVSS3: 7.2
EPSS: Низкий
debian логотип

CVE-2021-21263

больше 4 лет назад

Laravel is a web application framework. Versions of Laravel before 6.2 ...

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2020-24941

почти 5 лет назад

An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-24941

почти 5 лет назад

An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24. ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-w68r-5p45-5rqp

Improper Input Validation in Laravel

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-rc8x-jrrc-frfv

Laravel does not properly constrain the host portion of a password-reset URL

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-qvqm-h22r-4cp9

Laravel Framework RCE Vulnerability

CVSS3: 8.1
80%
Высокий
около 3 лет назад
github логотип
GHSA-g4q4-r6rr-r4w2

A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206501 was assigned to this vulnerability.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-c7rm-w2hj-x8g3

Guard bypass in Eloquent models affecting Laravel illuminate database component

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-c2v7-j5gq-wcq4

Laravel Sensitive Data Exposure

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-7236-phg4-48mj

A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206688.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-5hq5-9pj6-4c2r

A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3p32-j457-pg5x

Query Binding Exploitation

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2v4r-7m2m-5chh

In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.

CVSS3: 7.5
86%
Высокий
около 3 лет назад
nvd логотип
CVE-2022-2886

A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206688.

CVSS3: 5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-2886

A vulnerability, which was classified as critical, was found in Larave ...

CVSS3: 5
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-2870

A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206501 was assigned to this vulnerability.

CVSS3: 4.1
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-2870

A vulnerability was found in laravel 5.1 and classified as problematic ...

CVSS3: 4.1
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2021-28254

A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2021-21263

Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a field that is normally a non-array value is an array, and that input is not validated or cast to its expected type before being passed to the query builder, an unexpected number of query bindings can be added to the query. In some situations, this will simply lead to no results being returned by the query builder; however, it is possible certain queries could be affected in a way that causes the query to return unexpected results.

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-21263

Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a field that is normally a non-array value is an array, and that input is not validated or cast to its expected type before being passed to the query builder, an unexpected number of query bindings can be added to the query. In some situations, this will simply lead to no results being returned by the query builder; however, it is possible certain queries could be affected in a way that causes the query to return unexpected results.

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-21263

Laravel is a web application framework. Versions of Laravel before 6.2 ...

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-24941

An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions.

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-24941

An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24. ...

CVSS3: 7.5
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу