Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2018-19518EPSS 95%
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_…
PHP
after 7.2.12
HIGH 7.5
CVE-2018-19395
ext/standard/var.c in PHP 5.x through 7.1.24 on Windows allows attackers to cause a denial of service (NULL pointer dereference and application crash…
PHP
after 7.1.24
HIGH 7.5
CVE-2018-19396
ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call f…
PHP
after 7.1.24
MEDIUM 6.1
CVE-2018-17082
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-…
PHP
5.6.38 / 7.0.32+
HIGH 7.5
CVE-2018-15132EPSS 5%
An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The link…
PHP
5.6.37 / 7.0.31+
HIGH 7.5
CVE-2018-14883EPSS 9%
An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-b…
PHP
5.6.37 / 7.0.31+
HIGH 7.5
CVE-2018-14884
An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a …
PHP
7.0.27 / 7.1.13+
MEDIUM 5.5
CVE-2018-14851
exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote…
PHP
7.0.31 / 7.1.20+
CRITICAL 9.8
CVE-2017-9120EPSS 8%
PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other…
PHP
7.4.23 / 8.0.10+
HIGH 7.5
CVE-2017-9118
PHP 7.1.5 has an Out of bounds access in php_pcre_replace_impl via a crafted preg_replace call.
PHP
7.4.27 / 8.0.14+
CRITICAL 9.8
CVE-2018-12882EPSS 7%
exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it cl…
PHP
after 7.2.7
HIGH 8.8
CVE-2018-10549EPSS 7%
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_read_data in ext/exif/exif.c has…
PHP
5.6.36 / 7.0.30+
HIGH 7.5
CVE-2018-10546EPSS 10%
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/…
PHP
5.6.36 / 7.0.30+
HIGH 7.5
CVE-2018-10548EPSS 9%
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap/ldap.c allows remote LDAP se…
PHP
5.6.36 / 7.0.30+
MEDIUM 6.1
CVE-2018-10547
An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Re…
PHP
5.6.36 / 7.0.30+
CRITICAL 9.8
CVE-2018-7584EPSS 87%
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an …
PHP
7.0.28+
MEDIUM 6.5
CVE-2015-9253
An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process i…
PHP
7.1.20 / 7.2.8+
HIGH 7.5
CVE-2016-10712
In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can …
PHP
after 7.0.2
MEDIUM 6.1
CVE-2018-5712EPSS 80%
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 40…
PHP
after 7.1.12
MEDIUM 5.5
CVE-2018-5711EPSS 13%
gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, h…
PHP
after 7.1.12
HIGH 7.5
CVE-2017-16642EPSS 26%
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back …
PHP
5.6.32 / 7.0.25+
CRITICAL 9.8
CVE-2017-12932EPSS 7%
ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free while unserializing untrusted …
PHP
Patch available
CRITICAL 9.8
CVE-2017-12933EPSS 7%
The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a b…
PHP
after 5.6.30
HIGH 7.5
CVE-2017-12934
ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted da…
PHP
Mitigation only
MEDIUM 6.5
CVE-2017-7890
The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before …
PHP
after 5.6.30
HIGH 7.8
CVE-2017-11628
In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_pars…
PHP
after 5.6.30
CRITICAL 9.8
CVE-2017-11362
In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attack…
PHP
Mitigation only
CRITICAL 9.1
CVE-2017-11147
In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP in…
PHP
5.6.30 / 7.0.15+
HIGH 7.5
CVE-2016-10397
In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostn…
PHP
after 5.6.27
HIGH 7.5
CVE-2017-11142EPSS 8%
In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting…
PHP
after 5.6.30