Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 009

redhat логотип

CVE-2026-17544

около 2 месяцев назад

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-17543

около 2 месяцев назад

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-vc5h-9ppw-p5f3

около 2 месяцев назад

Stack overflow in phar with circular symlinks

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-x692-q9x7-8c3f

около 2 месяцев назад

Out-of-bounds write in bccomp() via crafted operand and scale

EPSS: Низкий
github логотип

GHSA-7qpv-r5mr-78m4

около 2 месяцев назад

SQL injection in ext-pgsql via E'...' backslash breakout

EPSS: Низкий
oracle-oval логотип

ELSA-2026-48170

около 2 месяцев назад

ELSA-2026-48170: php security, bug fix, and enhancement update (LOW)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3165-1

около 2 месяцев назад

Security update for php7

EPSS: Низкий
oracle-oval логотип

ELSA-2026-40416

около 2 месяцев назад

ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW)

EPSS: Низкий
nvd логотип

CVE-2026-14355

2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
EPSS: Низкий
debian логотип

CVE-2026-14355

2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2026-17544

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-17543

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

CVSS3: 7.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-vc5h-9ppw-p5f3

Stack overflow in phar with circular symlinks

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-x692-q9x7-8c3f

Out-of-bounds write in bccomp() via crafted operand and scale

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-7qpv-r5mr-78m4

SQL injection in ext-pgsql via E'...' backslash breakout

0%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-48170

ELSA-2026-48170: php security, bug fix, and enhancement update (LOW)

0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3165-1

Security update for php7

0%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-40416

ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW)

0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-14355

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-14355

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...

CVSS3: 5.6
0%
Низкий
2 месяца назад

Уязвимостей на страницу


Поделиться