Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pearweb CRITICAL 9.8
CVE-2026-25238

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription d…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25240

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::ma…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25241

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<packa…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb HIGH 7.5
CVE-2026-25239

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in apidoc queue inser…

Fix: 1.33.0+
Fix from $1,950 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25236

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25237

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug u…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb HIGH 7.5
CVE-2026-25235

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes may allow attackers…

Fix: 1.33.0+
Fix from $1,950 2026-02-03
Pearweb CRITICAL 9.8
CVE-2026-25234

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion …

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Pearweb CRITICAL 9.1
CVE-2026-25233

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead…

Fix: 1.33.0+
Fix from $2,300 2026-02-03
Crypt Gpg MEDIUM 5.3
CVE-2022-24953

The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG…

Fix: 1.6.7+
Fix from $1,600 2022-02-17
Html Ajax CRITICAL 9.8
CVE-2017-5677

PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint,…

Mitigation only
Fix from $2,300 2017-02-06
Mail MEDIUM 6.8
CVE-2009-4111

Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remote attacke…

No fix yet
Fix from $1,600 2009-11-29
Pear HIGH 10.0
CVE-2009-4024EPSS 6%

Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute ar…

Fix: after 2.4.4
Fix from $1,950 2009-11-29
Pear HIGH 10.0
CVE-2009-4025EPSS 6%

Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote atta…

Fix: after 0.21.1
Fix from $1,950 2009-11-29
Pear HIGH 7.5
CVE-2009-4023

Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allo…

Patch available
Fix from $1,950 2009-11-29
Structures Datagrid Datasource Mdb2 MEDIUM 5.0
CVE-2007-3628

Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers to "manipu…

Fix: after 0.1.9
Fix from $1,600 2007-07-09
Pear Archive Tar MEDIUM 5.0
CVE-2006-0931

Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrar…

Fix: after 1.3.1
Fix from $1,600 2006-02-28
Pear Archive Zip MEDIUM 5.0
CVE-2006-0932

Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certa…

Mitigation only
Fix from $1,600 2006-02-28
Xml Rpc HIGH 7.5
CVE-2006-0868

Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4, allow r…

Patch available
Fix from $1,950 2006-02-23
Pear Liveuser MEDIUM 6.4
CVE-2006-0869

Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and…

Patch available
Fix from $1,600 2006-02-23
Text Password HIGH 10.0
CVE-2005-4730

Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number gene…

Patch available
Fix from $1,950 2005-12-31