Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2024-11234 In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option,… PHP 8.1.31 / 8.2.26+ Fix from $1,9502024-11-24 MEDIUM 5.8 CVE-2024-8929 In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of… PHP 8.1.31 / 8.2.26+ Fix from $1,6002024-11-22 CRITICAL 9.8 CVE-2024-8932 In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit sy… PHP 8.1.31 / 8.2.26+ Fix from $2,3002024-11-22 HIGH 8.8 CVE-2024-8926 In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages,… PHP 8.1.30 / 8.2.24+ Fix from $1,9502024-10-08 HIGH 7.5 CVE-2024-8927 In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI bina… PHP 8.1.30 / 8.2.24+ Fix from $1,9502024-10-08 MEDIUM 5.3 CVE-2024-8925 In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST req… PHP 8.1.30 / 8.2.24+ Fix from $1,6002024-10-08 CRITICAL 9.8 CVE-2024-4577 KEVEPSS 100% In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to us… PHP 8.1.29 / 8.2.20+ Fix from $2,3002024-06-09 MEDIUM 5.9 CVE-2024-2408 The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Atta… PHP 8.1.29 / 8.2.20+ Fix from $1,6002024-06-09 HIGH 8.8 CVE-2024-5585EPSS 29% In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes tr… PHP 8.1.29 / 8.2.20+ Fix from $1,9502024-06-09 MEDIUM 5.3 CVE-2024-5458EPSS 12% In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when … PHP 8.1.29 / 8.2.20+ Fix from $1,6002024-06-09 HIGH 7.5 CVE-2024-2757 In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed … PHP 8.3.5+ Fix from $1,9502024-04-29 MEDIUM 6.5 CVE-2024-3096 In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00… PHP 8.1.28 / 8.2.18+ Fix from $1,6002024-04-29 CRITICAL 9.4 CVE-2024-1874EPSS 33% In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient e… PHP 8.1.28 / 8.2.18+ Fix from $2,3002024-04-29 MEDIUM 5.5 CVE-2022-4900 A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow. PHP 8.0.22+ Fix from $1,6002023-11-02 CRITICAL 9.8 CVE-2023-3824EPSS 21% In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insuf… PHP 8.0.30 / 8.1.22+ Fix from $2,3002023-08-11 HIGH 7.5 CVE-2023-3823 In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configura… PHP 8.0.30 / 8.1.22+ Fix from $1,9502023-08-11 MEDIUM 6.2 CVE-2023-0567 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. … PHP 8.0.28 / 8.1.16+ Fix from $1,6002023-03-01 HIGH 8.1 CVE-2023-0568 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolv… PHP 8.0.28 / 8.1.16+ Fix from $1,9502023-02-16 HIGH 7.5 CVE-2023-0662 In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consump… PHP 8.0.28 / 8.1.16+ Fix from $1,9502023-02-16 HIGH 7.1 CVE-2022-31630 In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted… PHP 7.4.33 / 8.0.25+ Fix from $1,9502022-11-14 MEDIUM 6.5 CVE-2022-31629EPSS 49% In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the … PHP 7.4.31 / 8.0.24+ Fix from $1,6002022-09-28 MEDIUM 5.5 CVE-2022-31628 In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infini… PHP 7.4.31 / 8.0.24+ Fix from $1,6002022-09-28 CRITICAL 9.8 CVE-2022-31627 In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagi… PHP 8.1.8+ Fix from $2,3002022-07-28 HIGH 8.8 CVE-2022-31626EPSS 58% In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is al… PHP 7.4.30 / 8.0.20+ Fix from $1,9502022-06-16 HIGH 8.1 CVE-2022-31625 In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters t… PHP 7.4.30 / 8.0.20+ Fix from $1,9502022-06-16 CRITICAL 9.8 CVE-2022-27157 pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php. Pearweb 1.32.0+ Fix from $2,3002022-04-15 CRITICAL 9.8 CVE-2022-27158 pearweb < 1.32 suffers from Deserialization of Untrusted Data. Pearweb 1.32.0+ Fix from $2,3002022-04-15 CRITICAL 9.8 CVE-2022-26635EPSS 21% PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have dispu… Memcached after 2.2.0 Fix from $2,3002022-04-05 CRITICAL 9.8 CVE-2021-21708 In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/… PHP 7.4.28 / 8.0.16+ Fix from $2,3002022-02-27 MEDIUM 5.3 CVE-2021-21707EPSS 26% In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode … PHP 5.21.0 / 7.3.33+ Fix from $1,6002021-11-29