Web1 vuln-feed

Vulnerability findings

Matches between monitored feeds (NVD, CISA KEV, NCSC-FI) and your inventory.

6
new (30 days)
0
acknowledged (30 days)
0
dismissed (30 days)
0
resolved (30 days)
SeverityFindingInventory item MatchStatusFirst seen (UTC)
8.3 CVE-2025-58098: Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd= software apache-test 2.4.37 cpe / high new 2026-09-26T00:07:16Z
8.3 CVE-2025-58098: Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd= software apache-test2 2.4.37 cpe / high new 2026-09-26T00:07:16Z
7.5 CVE-2025-59775: Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially l software apache-test 2.4.37 cpe / high new 2026-09-26T00:07:16Z
7.5 CVE-2025-59775: Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially l software apache-test2 2.4.37 cpe / high new 2026-09-26T00:07:16Z
6.5 CVE-2025-65082: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration software apache-test 2.4.37 cpe / high new 2026-09-26T00:07:16Z
6.5 CVE-2025-65082: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration software apache-test2 2.4.37 cpe / high new 2026-09-26T00:07:16Z