Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.2
CVE-2024-11234
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option,…
PHP
8.1.31 / 8.2.26+
MEDIUM 5.8
CVE-2024-8929
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of…
PHP
8.1.31 / 8.2.26+
CRITICAL 9.8
CVE-2024-8932
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit sy…
PHP
8.1.31 / 8.2.26+
HIGH 8.8
CVE-2024-8926
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages,…
PHP
8.1.30 / 8.2.24+
HIGH 7.5
CVE-2024-8927
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI bina…
PHP
8.1.30 / 8.2.24+
MEDIUM 5.3
CVE-2024-8925
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST req…
PHP
8.1.30 / 8.2.24+
CRITICAL 9.8
CVE-2024-4577 KEVEPSS 100%
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to us…
PHP
8.1.29 / 8.2.20+
MEDIUM 5.9
CVE-2024-2408
The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Atta…
PHP
8.1.29 / 8.2.20+
HIGH 8.8
CVE-2024-5585EPSS 29%
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes tr…
PHP
8.1.29 / 8.2.20+
MEDIUM 5.3
CVE-2024-5458EPSS 12%
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when …
PHP
8.1.29 / 8.2.20+
HIGH 7.5
CVE-2024-2757
In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed …
PHP
8.3.5+
MEDIUM 6.5
CVE-2024-3096
In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00…
PHP
8.1.28 / 8.2.18+
CRITICAL 9.4
CVE-2024-1874EPSS 33%
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient e…
PHP
8.1.28 / 8.2.18+
MEDIUM 5.5
CVE-2022-4900
A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.
PHP
8.0.22+
CRITICAL 9.8
CVE-2023-3824EPSS 21%
In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insuf…
PHP
8.0.30 / 8.1.22+
HIGH 7.5
CVE-2023-3823
In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configura…
PHP
8.0.30 / 8.1.22+
MEDIUM 6.2
CVE-2023-0567
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. …
PHP
8.0.28 / 8.1.16+
HIGH 8.1
CVE-2023-0568
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolv…
PHP
8.0.28 / 8.1.16+
HIGH 7.5
CVE-2023-0662
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consump…
PHP
8.0.28 / 8.1.16+
HIGH 7.1
CVE-2022-31630
In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted…
PHP
7.4.33 / 8.0.25+
MEDIUM 6.5
CVE-2022-31629EPSS 49%
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the …
PHP
7.4.31 / 8.0.24+
MEDIUM 5.5
CVE-2022-31628
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infini…
PHP
7.4.31 / 8.0.24+
CRITICAL 9.8
CVE-2022-31627
In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagi…
PHP
8.1.8+
HIGH 8.8
CVE-2022-31626EPSS 58%
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is al…
PHP
7.4.30 / 8.0.20+
HIGH 8.1
CVE-2022-31625
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters t…
PHP
7.4.30 / 8.0.20+
CRITICAL 9.8
CVE-2022-27157
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
Pearweb
1.32.0+
CRITICAL 9.8
CVE-2022-27158
pearweb < 1.32 suffers from Deserialization of Untrusted Data.
Pearweb
1.32.0+
CRITICAL 9.8
CVE-2022-26635EPSS 21%
PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have dispu…
Memcached
after 2.2.0
CRITICAL 9.8
CVE-2021-21708
In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/…
PHP
7.4.28 / 8.0.16+
MEDIUM 5.3
CVE-2021-21707EPSS 26%
In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode …
PHP
5.21.0 / 7.3.33+