Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

PHP HIGH 7.2
CVE-2024-11234

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option,…

Fix: 8.1.31 / 8.2.26+
Fix from $1,950 2024-11-24
PHP MEDIUM 5.8
CVE-2024-8929

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of…

Fix: 8.1.31 / 8.2.26+
Fix from $1,600 2024-11-22
PHP CRITICAL 9.8
CVE-2024-8932

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit sy…

Fix: 8.1.31 / 8.2.26+
Fix from $2,300 2024-11-22
PHP HIGH 8.8
CVE-2024-8926

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages,…

Fix: 8.1.30 / 8.2.24+
Fix from $1,950 2024-10-08
PHP HIGH 7.5
CVE-2024-8927

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI bina…

Fix: 8.1.30 / 8.2.24+
Fix from $1,950 2024-10-08
PHP MEDIUM 5.3
CVE-2024-8925

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST req…

Fix: 8.1.30 / 8.2.24+
Fix from $1,600 2024-10-08
PHP CRITICAL 9.8
CVE-2024-4577 KEVEPSS 100%

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to us…

Fix: 8.1.29 / 8.2.20+
Fix from $2,300 2024-06-09
PHP MEDIUM 5.9
CVE-2024-2408

The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Atta…

Fix: 8.1.29 / 8.2.20+
Fix from $1,600 2024-06-09
PHP HIGH 8.8
CVE-2024-5585EPSS 29%

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes tr…

Fix: 8.1.29 / 8.2.20+
Fix from $1,950 2024-06-09
PHP MEDIUM 5.3
CVE-2024-5458EPSS 12%

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when …

Fix: 8.1.29 / 8.2.20+
Fix from $1,600 2024-06-09
PHP HIGH 7.5
CVE-2024-2757

In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed …

Fix: 8.3.5+
Fix from $1,950 2024-04-29
PHP MEDIUM 6.5
CVE-2024-3096

In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00…

Fix: 8.1.28 / 8.2.18+
Fix from $1,600 2024-04-29
PHP CRITICAL 9.4
CVE-2024-1874EPSS 33%

In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient e…

Fix: 8.1.28 / 8.2.18+
Fix from $2,300 2024-04-29
PHP MEDIUM 5.5
CVE-2022-4900

A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.

Fix: 8.0.22+
Fix from $1,600 2023-11-02
PHP CRITICAL 9.8
CVE-2023-3824EPSS 21%

In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insuf…

Fix: 8.0.30 / 8.1.22+
Fix from $2,300 2023-08-11
PHP HIGH 7.5
CVE-2023-3823

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configura…

Fix: 8.0.30 / 8.1.22+
Fix from $1,950 2023-08-11
PHP MEDIUM 6.2
CVE-2023-0567

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. …

Fix: 8.0.28 / 8.1.16+
Fix from $1,600 2023-03-01
PHP HIGH 8.1
CVE-2023-0568

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolv…

Fix: 8.0.28 / 8.1.16+
Fix from $1,950 2023-02-16
PHP HIGH 7.5
CVE-2023-0662

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consump…

Fix: 8.0.28 / 8.1.16+
Fix from $1,950 2023-02-16
PHP HIGH 7.1
CVE-2022-31630

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted…

Fix: 7.4.33 / 8.0.25+
Fix from $1,950 2022-11-14
PHP MEDIUM 6.5
CVE-2022-31629EPSS 49%

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the …

Fix: 7.4.31 / 8.0.24+
Fix from $1,600 2022-09-28
PHP MEDIUM 5.5
CVE-2022-31628

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infini…

Fix: 7.4.31 / 8.0.24+
Fix from $1,600 2022-09-28
PHP CRITICAL 9.8
CVE-2022-31627

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagi…

Fix: 8.1.8+
Fix from $2,300 2022-07-28
PHP HIGH 8.8
CVE-2022-31626EPSS 58%

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is al…

Fix: 7.4.30 / 8.0.20+
Fix from $1,950 2022-06-16
PHP HIGH 8.1
CVE-2022-31625

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters t…

Fix: 7.4.30 / 8.0.20+
Fix from $1,950 2022-06-16
Pearweb CRITICAL 9.8
CVE-2022-27157

pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.

Fix: 1.32.0+
Fix from $2,300 2022-04-15
Pearweb CRITICAL 9.8
CVE-2022-27158

pearweb < 1.32 suffers from Deserialization of Untrusted Data.

Fix: 1.32.0+
Fix from $2,300 2022-04-15
Memcached CRITICAL 9.8
CVE-2022-26635EPSS 21%

PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have dispu…

Fix: after 2.2.0
Fix from $2,300 2022-04-05
PHP CRITICAL 9.8
CVE-2021-21708

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/…

Fix: 7.4.28 / 8.0.16+
Fix from $2,300 2022-02-27
PHP MEDIUM 5.3
CVE-2021-21707EPSS 26%

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode …

Fix: 5.21.0 / 7.3.33+
Fix from $1,600 2021-11-29