Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 50

Количество 50

github логотип

GHSA-3j5h-f552-7rhh

8 месяцев назад

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2025-23739

8 месяцев назад

ELSA-2025-23739: mod_md security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23738

8 месяцев назад

ELSA-2025-23738: mod_md security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-15636

12 месяцев назад

Уязвимость модуля mod_md веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260122-73-0024

6 месяцев назад

Уязвимость httpd

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-58098

8 месяцев назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
EPSS: Низкий
redhat логотип

CVE-2025-58098

8 месяцев назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2025-58098

8 месяцев назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
EPSS: Низкий
msrc логотип

CVE-2025-58098

8 месяцев назад

Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

CVSS3: 8.3
EPSS: Низкий
debian логотип

CVE-2025-58098

8 месяцев назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) ...

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-4m29-g52g-c6qc

8 месяцев назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
EPSS: Низкий
oracle-oval логотип

ELSA-2026-0075

7 месяцев назад

ELSA-2026-0075: httpd security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-15635

12 месяцев назад

Уязвимость модуля mod_cgid веб-сервера Apache HTTP Server, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.3
EPSS: Низкий
redos логотип

ROS-20260122-73-0025

6 месяцев назад

Уязвимость httpd

CVSS3: 8.3
EPSS: Низкий
ubuntu логотип

CVE-2025-66200

8 месяцев назад

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2025-66200

8 месяцев назад

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-66200

8 месяцев назад

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
EPSS: Низкий
msrc логотип

CVE-2025-66200

8 месяцев назад

Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-66200

8 месяцев назад

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2025-65082

8 месяцев назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3j5h-f552-7rhh

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
oracle-oval логотип
ELSA-2025-23739

ELSA-2025-23739: mod_md security update (IMPORTANT)

0%
Низкий
8 месяцев назад
oracle-oval логотип
ELSA-2025-23738

ELSA-2025-23738: mod_md security update (IMPORTANT)

0%
Низкий
8 месяцев назад
fstec логотип
BDU:2025-15636

Уязвимость модуля mod_md веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
12 месяцев назад
redos логотип
ROS-20260122-73-0024

Уязвимость httpd

CVSS3: 7.5
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-58098

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
2%
Низкий
8 месяцев назад
redhat логотип
CVE-2025-58098

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 7.1
2%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-58098

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
2%
Низкий
8 месяцев назад
msrc логотип
CVE-2025-58098

Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

CVSS3: 8.3
2%
Низкий
8 месяцев назад
debian логотип
CVE-2025-58098

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) ...

CVSS3: 8.3
2%
Низкий
8 месяцев назад
github логотип
GHSA-4m29-g52g-c6qc

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
2%
Низкий
8 месяцев назад
oracle-oval логотип
ELSA-2026-0075

ELSA-2026-0075: httpd security update (IMPORTANT)

2%
Низкий
7 месяцев назад
fstec логотип
BDU:2025-15635

Уязвимость модуля mod_cgid веб-сервера Apache HTTP Server, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.3
2%
Низкий
12 месяцев назад
redos логотип
ROS-20260122-73-0025

Уязвимость httpd

CVSS3: 8.3
2%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-66200

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
1%
Низкий
8 месяцев назад
redhat логотип
CVE-2025-66200

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
1%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-66200

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
1%
Низкий
8 месяцев назад
msrc логотип
CVE-2025-66200

Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo

CVSS3: 5.4
1%
Низкий
8 месяцев назад
debian логотип
CVE-2025-66200

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in ...

CVSS3: 5.4
1%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2025-65082

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
1%
Низкий
8 месяцев назад

Уязвимостей на страницу