|
1
|
9.8
-
|
CRITICAL
Network
|
A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-28254
|
cpe:2.3:a:laravel:laravel:8.5.9:*
|
|
|
|
|
2025-03-6 04:15
2023-04-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2
|
8.8
-
|
HIGH
Network
|
A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch the attack remotely. …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2022-2886
|
cpe:2.3:a:laravel:laravel:*:*
|
5.1.0
|
5.1.46
|
|
|
2024-11-21 16:01
2022-08-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3
|
9.8
-
|
CRITICAL
Network
|
A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. Th…
|
-
|
CVE-2022-2870
|
cpe:2.3:a:laravel:laravel:*:*
|
5.1.0
|
5.1.46
|
|
|
2024-11-21 16:01
2022-08-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4
|
5.3
5.0
|
MEDIUM
Network
|
Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which …
|
CWE-89
SQL Injection
|
CVE-2021-21263
|
cpe:2.3:a:laravel:laravel:*:*
|
8.0.0 7.0.0 6.0.0
|
|
|
8.22.1 7.30.2 6.20.11
|
2024-11-21 14:47
2021-01-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5
|
7.5
4.3
|
HIGH
Network
|
An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions.
|
CWE-863
Incorrect Authorization
|
CVE-2020-24941
|
cpe:2.3:a:laravel:laravel:*:*
|
7.0.0
|
|
|
7.24.0 6.18.35
|
2024-11-21 14:16
2020-09-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6
|
7.5
4.3
|
HIGH
Network
|
An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a mass assignment.
|
CWE-20
Improper Input Validation
|
CVE-2020-24940
|
cpe:2.3:a:laravel:laravel:*:*
|
7.0.0
|
|
|
7.23.2 6.18.34
|
2024-11-21 14:16
2020-09-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7
|
8.1
6.8
|
HIGH
Network
|
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the dec…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-15133
|
cpe:2.3:a:laravel:laravel:*:*
|
5.6.0
|
5.5.40 5.6.29
|
|
|
2024-11-21 12:50
2018-08-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
8
|
7.5
5.0
|
HIGH
Network
|
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Larav…
|
CWE-200
Information Exposure
|
CVE-2017-16894
|
cpe:2.3:a:laravel:laravel:*:*
|
|
5.5.21
|
|
|
2024-11-21 12:17
2017-11-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
9
|
5.9
4.3
|
MEDIUM
Network
|
Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.
|
CWE-200
Information Exposure
|
CVE-2017-14775
|
cpe:2.3:a:laravel:laravel:*:*
|
|
5.5.9
|
|
|
2024-11-21 12:13
2017-09-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
10
|
6.1
5.8
|
MEDIUM
Network
|
Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-cont…
|
CWE-20
Improper Input Validation
|
CVE-2017-9303
|
cpe:2.3:a:laravel:laravel:5.4.0:*
|
|
|
|
|
2024-11-21 12:35
2017-05-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|