Filters

Php-fpm Php-fpmPHP CGI Parameter Injection Vulnerability (CVE-2024-4577 bypass)

8.8
EPSS
0.05%
First published (updated )

Php-fpm Php-fpmcgi.force_redirect configuration is bypassable due to the environment variable collision

7.5
EPSS
0.08%
First published (updated )

PHP PHPCommand injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)

8.8
EPSS
0.44%
First published (updated )

PHP PHPPHP mb_encode_mimeheader runs endlessly for some inputs

7.5
First published (updated )

PHP PHPSecurity issue with external entity loading in XML without enabling it

8.6
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

PHP PHPpassword_verify() always returns true for some invalid hashes

8.1
First published (updated )

PHP PHPArray overrun in common path resolve code

8.1
First published (updated )

PHP PHPDoS vulnerability when parsing multipart request body

7.5
First published (updated )

PHP PHPOOB read due to insufficient input validation in imageloadfont()

7.1
First published (updated )

PHP PHPFreeing unallocated memory in php_pgsql_free_params()

8.1
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

PHP PHPmysqlnd/pdo password buffer overflow

8.8
First published (updated )

PHP PHPPHP-FPM memory access in root process leading to privilege escalation

7.8
First published (updated )

Fedoraproject FedoraIn Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a diff…

7.1
First published (updated )

PHP PHPNull Dereference in SoapClient

7.5
First published (updated )

Fedoraproject FedoraPEAR Archive_Tar Improper Link Resolution Vulnerability

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Fedoraproject FedoraPEAR Archive_Tar Deserialization of Untrusted Data Vulnerability

First published (updated )

Fedoraproject FedoraLast updated 3 September 2024

7.8
First published (updated )

Chadhaajay PhpkbAn issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part …

7.5
First published (updated )

PHP PHPTemporary files are not cleaned after OOM when parsing HTTP request data

7.5
First published (updated )

PHP PHPOOB Read in urldecode()

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Canonical Ubuntu Linuxmb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full

8.8
First published (updated )

FreeBSD FreeBSDregcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion…

7.8
First published (updated )

Canonical Ubuntu LinuxNull Pointer Dereference in PHP Session Upload Progress

7.5
First published (updated )

Magento MagentoInput Validation

8.8
First published (updated )

PHP PHPThe compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorr…

7.8
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

PHP PHPlink() silently truncates after a null byte on Windows

7.5
First published (updated )

redhat/rh-php73-phpLast updated 24 July 2024

7.5
First published (updated )

Canonical Ubuntu Linuxheap-buffer-overflow on exif_scan_thumbnail in EXIF extension

7.1
First published (updated )

Canonical Ubuntu Linuxheap-buffer-overflow on exif_process_user_comment in EXIF extension

7.1
First published (updated )

PHP PHPInput Validation

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

PHP PHPBuffer Overflow

8.1
First published (updated )

Canonical Ubuntu LinuxLast updated 24 July 2024

7.5
First published (updated )

Canonical Ubuntu LinuxLast updated 24 July 2024

7.5
First published (updated )

Canonical Ubuntu LinuxLast updated 24 July 2024

7.5
First published (updated )

Canonical Ubuntu LinuxLast updated 24 July 2024

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

PHP PHPLast updated 24 July 2024

7.5
First published (updated )

PHP PHPBuffer Overflow

7.5
First published (updated )

ubuntu/php-pearPotential RCE if filename starts with phar://

8.8
First published (updated )

PHP PHPBuffer Overflow

8.8
First published (updated )

PHP PHPNull Pointer Dereference

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Sdcms SdcmsCode Injection

8.8
First published (updated )

PHP PHPFixed bug (imap_open allows to run arbitrary shell commands via mailbox parameter). (CVE-2018-19518…

8.5
First published (updated )

PHP PHPNull Pointer Dereference

7.5
First published (updated )

PHP PHPext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of serv…

7.5
First published (updated )

PHP PHPBuffer Overflow

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

PHP PHPInfoleak

7.5
First published (updated )

PHP PHPInteger Overflow

7.5
First published (updated )

PHP PHPLast updated 24 July 2024

7.5
First published (updated )

PHP PHPBuffer Overflow

8.8
First published (updated )

PHP PHPNull Pointer Dereference

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203