Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 28.81%
  • Veröffentlicht 09.06.2024 19:15:52
  • Zuletzt bearbeitet 21.11.2024 09:47:58

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient ...

Exploit
  • EPSS 1.92%
  • Veröffentlicht 29.04.2024 04:15:08
  • Zuletzt bearbeitet 04.11.2025 18:16:18

In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application ...

Exploit
  • EPSS 1.48%
  • Veröffentlicht 29.04.2024 04:15:08
  • Zuletzt bearbeitet 04.11.2025 18:16:30

In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return true.

Exploit
  • EPSS 32.57%
  • Veröffentlicht 29.04.2024 04:15:07
  • Zuletzt bearbeitet 04.11.2025 19:16:27

In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can su...

  • EPSS 37.86%
  • Veröffentlicht 29.04.2024 04:15:07
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applic...

Exploit
  • EPSS 6.88%
  • Veröffentlicht 10.04.2024 16:15:16
  • Zuletzt bearbeitet 15.05.2026 15:03:11

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

  • EPSS 0.37%
  • Veröffentlicht 02.11.2023 16:15:08
  • Zuletzt bearbeitet 03.11.2025 22:16:01

A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.

Exploit
  • EPSS 21.13%
  • Veröffentlicht 11.08.2023 06:15:10
  • Zuletzt bearbeitet 13.02.2025 17:16:59

In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption...

Exploit
  • EPSS 1.64%
  • Veröffentlicht 11.08.2023 06:15:09
  • Zuletzt bearbeitet 13.02.2025 17:16:59

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unle...

  • EPSS 0.71%
  • Veröffentlicht 22.07.2023 05:15:37
  • Zuletzt bearbeitet 21.11.2024 08:16:47

In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP Digest Authentication, random value generator was not checked for failure, and was using narrower range of values than it should have. In case of random...