php records
781 published records for vendor php.
Researcher profile
- Entered KEV
- 5 · 0.6%
- Weaponized
- 11 · 1.4%
- Pre-auth RCE
- 165
- With a fix record
- 70%
- Median publish → KEV
- 644 days
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer94
- CWE-20 Improper Input Validation75
- CWE-125 Out-of-bounds Read46
- CWE-189 Numeric Errors32
- CWE-264 Permissions, Privileges, and Access Controls29
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor27
The weakness classes this vendor ships most often: where to look.
CWEAll records
781 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2012-1823Weaponized | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Critical9.8 | KEV | 100.0% | May 11, 2012 |
99Now | CVE-2024-4577Weaponized | Argument Injection in PHP-CGIphp · php · CWE-78 | Critical9.8 | KEV | 100.0% | Jun 9, 2024 |
99Now | CVE-2019-11043Weaponized | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Critical9.8 | KEV | 99.8% | Oct 28, 2019 |
86Now | CVE-2020-28949Weaponized | Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as filphp · archive tar | High7.8 | KEV | 84.6% | Nov 19, 2020 |
81Now | CVE-2020-36193Weaponized | Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relatphp · archive tar · CWE-22 | High7.5 | KEV | 70.6% | Jan 18, 2021 |
68This week | CVE-2015-0235Weaponized | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depengnu · glibc · CWE-787 | Critical10.0 | — | 94.6% | Jan 28, 2015 |
65This week | CVE-2018-7584Proof of concept | In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while paphp · php · CWE-119 | Critical9.8 | — | 87.3% | Mar 1, 2018 |
59Plan | CVE-2018-19518Weaponized | University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of php · php · CWE-88 | High7.5 | — | 96.1% | Nov 25, 2018 |
56Plan | CVE-2019-6977Proof of concept | gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.libgd · libgd · CWE-787 | High8.8 | — | 71.5% | Jan 26, 2019 |
56Plan | CVE-2016-3078Proof of concept | Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-bphp · php · CWE-190 | Critical9.8 | — | 56.1% | Aug 7, 2016 |
54Plan | CVE-2005-1921Weaponized | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1php · xml rpc · CWE-94 | High7.5 | — | 79.1% | Jul 5, 2005 |
53Plan | CVE-2015-6834Proof of concept | Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to executephp · php | Critical9.8 | — | 46.8% | May 16, 2016 |
52Plan | CVE-2022-31626Proof of concept | mysqlnd/pdo password buffer overflowphp · php · CWE-120 | High8.8 | — | 58.1% | Jun 16, 2022 |
52Plan | CVE-2016-7479No exploit | In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-afphp · php · CWE-416 | Critical9.8 | — | 41.7% | Jan 11, 2017 |
51Plan | CVE-2012-2311Proof of concept | sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-89 | High7.5 | — | 69.3% | May 11, 2012 |
51Plan | CVE-2016-7480No exploit | The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, whicphp · php · CWE-119 | Critical9.8 | — | 41.6% | Jan 11, 2017 |
50Plan | CVE-2021-32610No exploit | In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.php · archive tar · CWE-59 | High7.1 | — | 73.4% | Jul 30, 2021 |
50Plan | CVE-2005-3390Proof of concept | The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modphp · php | High7.5 | — | 65.5% | Nov 1, 2005 |
50Plan | CVE-2016-3074Proof of concept | Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or libgd · libgd · CWE-681 | Critical9.8 | — | 37.2% | Apr 26, 2016 |
50Plan | CVE-2015-6835Proof of concept | The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, wphp · php | Critical9.8 | — | 36.2% | May 16, 2016 |
50Plan | CVE-2016-3141Proof of concept | Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause aphp · php · CWE-119 | Critical9.8 | — | 36.0% | Mar 31, 2016 |
49Plan | CVE-2004-0542No exploit | PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbphp · php | Critical10.0 | — | 31.1% | Aug 6, 2004 |
48Plan | CVE-2018-5712No exploit | An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1.php · php · CWE-79 | Medium6.1 | — | 79.9% | Jan 16, 2018 |
47Plan | CVE-2016-5385No exploit | PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from thp · storeever msl6480 tape library firmware · CWE-601 | High8.1 | — | 50.4% | Jul 18, 2016 |
47Plan | CVE-2024-1874Proof of concept | Command injection via array-ish $command parameter of proc_open()php · php · CWE-116 | Critical9.4 | — | 32.6% | Apr 29, 2024 |
- CVE-2012-182399Now
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpMay 11, 2012
- CVE-2024-457799Now
Argument Injection in PHP-CGI
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpJun 9, 2024
- CVE-2019-1104399Now
Underflow in PHP-FPM can lead to RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpOct 28, 2019
- CVE-2020-2894986Now
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil
HighCVSS 7.8KEVWeaponizedEPSS 85%php · archive tarNov 19, 2020
- CVE-2020-3619381Now
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relat
HighCVSS 7.5KEVWeaponizedEPSS 71%php · archive tarJan 18, 2021
- CVE-2015-023568This week
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen
CriticalCVSS 10.0WeaponizedEPSS 95%gnu · glibcJan 28, 2015
- CVE-2018-758465This week
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while pa
CriticalCVSS 9.8Proof of conceptEPSS 87%php · phpMar 1, 2018
- CVE-2018-1951859Plan
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of
HighCVSS 7.5WeaponizedEPSS 96%php · phpNov 25, 2018
- CVE-2019-697756Plan
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.
HighCVSS 8.8Proof of conceptEPSS 71%libgd · libgdJan 26, 2019
- CVE-2016-307856Plan
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-b
CriticalCVSS 9.8Proof of conceptEPSS 56%php · phpAug 7, 2016
- CVE-2005-192154Plan
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1
HighCVSS 7.5WeaponizedEPSS 79%php · xml rpcJul 5, 2005
- CVE-2015-683453Plan
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute
CriticalCVSS 9.8Proof of conceptEPSS 47%php · phpMay 16, 2016
- CVE-2022-3162652Plan
mysqlnd/pdo password buffer overflow
HighCVSS 8.8Proof of conceptEPSS 58%php · phpJun 16, 2022
- CVE-2016-747952Plan
In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-af
CriticalCVSS 9.8No exploitEPSS 42%php · phpJan 11, 2017
- CVE-2012-231151Plan
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle que
HighCVSS 7.5Proof of conceptEPSS 69%php · phpMay 11, 2012
- CVE-2016-748051Plan
The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, whic
CriticalCVSS 9.8No exploitEPSS 42%php · phpJan 11, 2017
- CVE-2021-3261050Plan
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
HighCVSS 7.1No exploitEPSS 73%php · archive tarJul 30, 2021
- CVE-2005-339050Plan
The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to mod
HighCVSS 7.5Proof of conceptEPSS 66%php · phpNov 1, 2005
- CVE-2016-307450Plan
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or
CriticalCVSS 9.8Proof of conceptEPSS 37%libgd · libgdApr 26, 2016
- CVE-2015-683550Plan
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, w
CriticalCVSS 9.8Proof of conceptEPSS 36%php · phpMay 16, 2016
- CVE-2016-314150Plan
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a
CriticalCVSS 9.8Proof of conceptEPSS 36%php · phpMar 31, 2016
- CVE-2004-054249Plan
PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arb
CriticalCVSS 10.0No exploitEPSS 31%php · phpAug 6, 2004
- CVE-2018-571248Plan
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1.
MediumCVSS 6.1No exploitEPSS 80%php · phpJan 16, 2018
- CVE-2016-538547Plan
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t
HighCVSS 8.1No exploitEPSS 50%hp · storeever msl6480 tape library firmwareJul 18, 2016
- CVE-2024-187447Plan
Command injection via array-ish $command parameter of proc_open()
CriticalCVSS 9.4Proof of conceptEPSS 33%php · phpApr 29, 2024