facade records
3 published records for vendor facade.
Researcher profile
- Entered KEV
- 1 · 33.3%
- Weaponized
- 1 · 33.3%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- 979 days
Attack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2021-3129Weaponized | Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of ilaravel · laravel | Critical9.8 | KEV | 99.9% | Jan 12, 2021 |
40Plan | CVE-2021-43996No exploit | The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect accfacade · ignition | Critical9.8 | — | 1.7% | Nov 17, 2021 |
39Monitor | CVE-2020-13909No exploit | The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env.facade · ignition | Critical9.8 | — | 1.5% | Jun 7, 2020 |
- CVE-2021-312999Now
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of i
CriticalCVSS 9.8KEVWeaponizedEPSS 100%laravel · laravelJan 12, 2021
- CVE-2021-4399640Plan
The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect acc
CriticalCVSS 9.8No exploitEPSS 2%facade · ignitionNov 17, 2021
- CVE-2020-1390939Monitor
The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env.
CriticalCVSS 9.8No exploitEPSS 1%facade · ignitionJun 7, 2020