Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 37

Количество 37

rocky логотип

RLSA-2026:22305

около 2 месяцев назад

Important: php:8.2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:22143

около 2 месяцев назад

Important: php:8.2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:22142

около 2 месяцев назад

Important: php:8.3 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22305

около 2 месяцев назад

ELSA-2026-22305: php:8.2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22143

около 1 месяца назад

ELSA-2026-22143: php:8.2 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:23388

около 2 месяцев назад

Important: php security update

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2091-1

2 месяца назад

Security update for php7

EPSS: Низкий
rocky логотип

RLSA-2026:22649

около 2 месяцев назад

Important: php8.4 security update

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2037-1

2 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1958-1

2 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1957-1

2 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20745-1

3 месяца назад

Security update for php8

EPSS: Низкий
ubuntu логотип

CVE-2026-6735

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2026-6735

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-6735

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2026-6735

3 месяца назад

XSS within PHP-FPM status endpoint

EPSS: Низкий
debian логотип

CVE-2026-6735

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7qg2-v9fj-4mwv

3 месяца назад

XSS within PHP-FPM status endpoint

EPSS: Низкий
ubuntu логотип

CVE-2026-7258

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-7258

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:22305

Important: php:8.2 security update

около 2 месяцев назад
rocky логотип
RLSA-2026:22143

Important: php:8.2 security update

около 2 месяцев назад
rocky логотип
RLSA-2026:22142

Important: php:8.3 security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-22305

ELSA-2026-22305: php:8.2 security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-22143

ELSA-2026-22143: php:8.2 security update (IMPORTANT)

около 1 месяца назад
rocky логотип
RLSA-2026:23388

Important: php security update

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2091-1

Security update for php7

2 месяца назад
rocky логотип
RLSA-2026:22649

Important: php8.4 security update

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2037-1

Security update for php8

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1958-1

Security update for php8

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1957-1

Security update for php8

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20745-1

Security update for php8

3 месяца назад
ubuntu логотип
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 6.1
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 5.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 6.1
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-6735

XSS within PHP-FPM status endpoint

0%
Низкий
3 месяца назад
debian логотип
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-7qg2-v9fj-4mwv

XSS within PHP-FPM status endpoint

0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-7258

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.

CVSS3: 7.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-7258

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.

CVSS3: 5.9
0%
Низкий
3 месяца назад

Уязвимостей на страницу