Логотип exploitDog
bind:"CVE-2025-55753" OR bind:"CVE-2025-58098" OR bind:"CVE-2025-65082" OR bind:"CVE-2025-66200"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-55753" OR bind:"CVE-2025-58098" OR bind:"CVE-2025-65082" OR bind:"CVE-2025-66200"

Количество 44

Количество 44

fstec логотип

BDU:2025-15636

6 месяцев назад

Уязвимость модуля mod_md веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260122-73-0024

15 дней назад

Уязвимость httpd

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-58098

2 месяца назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2025-58098

2 месяца назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
EPSS: Низкий
msrc логотип

CVE-2025-58098

около 2 месяцев назад

Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

CVSS3: 8.3
EPSS: Низкий
debian логотип

CVE-2025-58098

2 месяца назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) ...

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-4m29-g52g-c6qc

2 месяца назад

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
EPSS: Низкий
oracle-oval логотип

ELSA-2026-0075

28 дней назад

ELSA-2026-0075: httpd security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-15635

6 месяцев назад

Уязвимость модуля mod_cgid веб-сервера Apache HTTP Server, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.3
EPSS: Низкий
redos логотип

ROS-20260122-73-0025

15 дней назад

Уязвимость httpd

CVSS3: 8.3
EPSS: Низкий
ubuntu логотип

CVE-2025-66200

2 месяца назад

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-66200

2 месяца назад

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
EPSS: Низкий
msrc логотип

CVE-2025-66200

около 2 месяцев назад

Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-66200

2 месяца назад

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2025-65082

2 месяца назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-65082

2 месяца назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2025-65082

около 2 месяцев назад

Apache HTTP Server: CGI environment variable override

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-65082

2 месяца назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-768g-4qpg-32w7

2 месяца назад

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3j3g-3pw9-9vcc

2 месяца назад

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-15636

Уязвимость модуля mod_md веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
6 месяцев назад
redos логотип
ROS-20260122-73-0024

Уязвимость httpd

CVSS3: 7.5
0%
Низкий
15 дней назад
ubuntu логотип
CVE-2025-58098

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-58098

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
0%
Низкий
2 месяца назад
msrc логотип
CVE-2025-58098

Apache HTTP Server: Server Side Includes adds query string to #exec cmd=...

CVSS3: 8.3
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-58098

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) ...

CVSS3: 8.3
0%
Низкий
2 месяца назад
github логотип
GHSA-4m29-g52g-c6qc

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 8.3
0%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2026-0075

ELSA-2026-0075: httpd security update (IMPORTANT)

28 дней назад
fstec логотип
BDU:2025-15635

Уязвимость модуля mod_cgid веб-сервера Apache HTTP Server, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.3
0%
Низкий
6 месяцев назад
redos логотип
ROS-20260122-73-0025

Уязвимость httpd

CVSS3: 8.3
0%
Низкий
15 дней назад
ubuntu логотип
CVE-2025-66200

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-66200

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
0%
Низкий
2 месяца назад
msrc логотип
CVE-2025-66200

Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-66200

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in ...

CVSS3: 5.4
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2025-65082

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-65082

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
0%
Низкий
2 месяца назад
msrc логотип
CVE-2025-65082

Apache HTTP Server: CGI environment variable override

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-65082

Improper Neutralization of Escape, Meta, or Control Sequences vulnerab ...

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-768g-4qpg-32w7

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. Users are recommended to upgrade to version 2.4.66 which fixes the issue.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-3j3g-3pw9-9vcc

mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 5.4
0%
Низкий
2 месяца назад

Уязвимостей на страницу