CVE Browser
CVE-2021-43996 CRITICAL
The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.
CVSS 9.8 EPSS 1.73% Nov 17, 2021
CVE-2021-3129 KEV CRITICAL
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of fi…
CVSS 9.8 EPSS 99.94% Jan 12, 2021
CVE-2020-13909 CRITICAL
The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x series, versions 1.16.15 and later are una…
CVSS 9.8 EPSS 1.48% Jun 7, 2020
Showing 1 to 3 CVEs · page 1