Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 009

debian логотип

CVE-2026-7260

около 2 месяцев назад

Circular symbolic links in phar archives could lead to unbounded recur ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-7260

около 2 месяцев назад

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2026-7260

около 2 месяцев назад

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2026-17544

около 2 месяцев назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-17544

около 2 месяцев назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-17543

около 2 месяцев назад

Improper escaping of backslashes in attacker-provided parameters would ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-17543

около 2 месяцев назад

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2026-17543

около 2 месяцев назад

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2026-17544

около 2 месяцев назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2026-7260

около 2 месяцев назад

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2026-7260

Circular symbolic links in phar archives could lead to unbounded recur ...

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-7260

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-7260

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-17544

Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-17544

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-17543

Improper escaping of backslashes in attacker-provided parameters would ...

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-17543

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-17543

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-17544

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-7260

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу


Поделиться