All vulnerabilities
487 / 487
Sort
9.8
CVE-2012-1823DEB KEV
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI scrip…
2012-01-01KEV
EPSS100.0%
pct 99
8.1
CVE-2019-11043AST KEV
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain config…
2019-01-01KEV
EPSS99.5%
pct 99
8.1
CVE-2018-19518AST
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other pr…
2018-01-01
EPSS95.2%
pct 99
5.9
CVE-2018-7584AST
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, ther…
2018-01-01Pre-auth
EPSS87.9%
pct 99
5.0
CVE-2011-4885DEB
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to tr…
2011-01-01
EPSS83.9%
pct 99
6.1
CVE-2018-5712DEB
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2…
2018-01-01Pre-auth
EPSS80.3%
pct 99
6.8
CVE-2012-2311DEB
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI scrip…
2012-01-01
EPSS68.8%
pct 99
6.3
CVE-2019-6977AST
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in …
2019-01-01
EPSS65.1%
pct 99
6.8
CVE-2012-2329DEB
Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x befo…
2012-01-01
EPSS62.6%
pct 99
8.8
CVE-2022-31626AST
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql e…
2022-01-01
EPSS58.4%
pct 98
9.8
CVE-2016-3078DEB
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote a…
2016-01-01Pre-auth
EPSS57.6%
pct 98
5.1
CVE-2014-8142DEB
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializ…
2014-01-01
EPSS53.2%
pct 98
7.5
CVE-2012-2336DEB
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI scrip…
2012-01-01
EPSS50.7%
pct 98
5.0
CVE-2016-5385DEB
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and t…
2016-01-01
EPSS50.4%
pct 98
5.0
CVE-2015-4024DEB
Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c…
2015-01-01
EPSS50.1%
pct 98
6.5
CVE-2022-31629AST
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-si…
2022-01-01Pre-auth
EPSS49.3%
pct 98
9.8
CVE-2015-6834DEB
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x be…
2015-01-01Pre-auth
EPSS46.8%
pct 98
5.1
CVE-2015-0231DEB
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializ…
2015-01-01
EPSS42.6%
pct 98
6.8
CVE-2012-2386DEB
Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP befor…
2012-01-01
EPSS42.5%
pct 98
7.5
CVE-2016-7478DEB
Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote …
2016-01-01Pre-auth
EPSS42.4%
pct 98
8.1
CVE-2016-7479DEB
In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash ta…
2016-01-01Pre-auth
EPSS41.7%
pct 98
8.1
CVE-2016-7480DEB
The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 …
2016-01-01Pre-auth
EPSS41.6%
pct 98
5.1
CVE-2015-0273DEB
Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x befo…
2015-01-01
EPSS41.3%
pct 98
5.1
CVE-2015-3329DEB
Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP …
2015-01-01
EPSS38.4%
pct 98
9.8
CVE-2015-6835DEB
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mis…
2015-01-01Pre-auth
EPSS37.0%
pct 98
9.8
CVE-2016-3074DEB
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attac…
2016-01-01Pre-auth
EPSS37.0%
pct 98
9.8
CVE-2016-3141DEB
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x bef…
2016-01-01Pre-auth
EPSS35.4%
pct 98
5.1
CVE-2012-2335CVE
php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers…
2012-01-01
EPSS32.5%
pct 98
7.5
CVE-2012-0830DEB
The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers t…
2012-01-01
EPSS30.1%
pct 97
5.1
CVE-2014-3515DEB
The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that cer…
2014-01-01
EPSS30.1%
pct 97
5.8
CVE-2014-3669DEB
Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before…
2014-01-01
EPSS28.9%
pct 97
6.8
CVE-2015-2331DEB
Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as…
2015-01-01
EPSS27.9%
pct 97
4.3
CVE-2014-3668DEB
Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/x…
2014-01-01
EPSS27.0%
pct 97
2.9
CVE-2017-16642DEB
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extensio…
2017-01-01
EPSS26.4%
pct 97
5.3
CVE-2021-21707AST
In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML pars…
2021-01-01Pre-auth
EPSS26.0%
pct 97
9.8
CVE-2015-8617DEB
Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in P…
2015-01-01Pre-auth
EPSS23.9%
pct 97
2.6
CVE-2011-1938DEB
Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.…
2011-01-01
EPSS22.7%
pct 97
6.8
CVE-2014-3670DEB
The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x be…
2014-01-01
EPSS22.6%
pct 97
2.6
CVE-2014-2497DEB
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allow…
2014-01-01
EPSS22.3%
pct 97
5.1
CVE-2015-4021DEB
The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, an…
2015-01-01
EPSS20.9%
pct 97
Select a vulnerability on the left to open the preview.