CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-92842 MEDIUM

OOB read / info leak in convert.* stream filters when line-break-chars contains NUL

CVSS 5.9 EPSS 0.36% Sep 25, 2026
CVE-2026-91768 MEDIUM

IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)

CVSS 6.5 EPSS 0.56% Sep 25, 2026
CVE-2026-91769 MEDIUM

TLS Hostname Verification Falls Back to CN After SAN Mismatch

CVSS 4.3 EPSS 0.14% Sep 25, 2026
CVE-2026-91767 MEDIUM

Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN

CVSS 6.5 EPSS 0.15% Sep 25, 2026
CVE-2025-1218 LOW

Various packet overreads in mysqlnd_writeprotocol.c

CVSS 3.7 EPSS 0.18% Sep 25, 2026
CVE-2026-91766 MEDIUM

Cross-origin credential leak in HTTP stream wrapper redirects

CVSS 5.9 EPSS 0.34% Sep 25, 2026
CVE-2026-91765 HIGH

SOAP: Unbounded Recursion in Server-Side cleanup_xml_node

CVSS 7.5 EPSS 0.52% Sep 25, 2026
CVE-2025-14181 MEDIUM

Integer overflow to buffer overflow in soap HTTP parsing

CVSS 6.5 EPSS 0.34% Sep 25, 2026
CVE-2026-17545 MEDIUM

PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS

CVSS 6.9 EPSS 0.32% Sep 25, 2026
CVE-2026-6103 MEDIUM

Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection

CVSS 4.3 EPSS 0.17% Sep 25, 2026
CVE-2026-93682 MEDIUM

Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header

CVSS 5.8 EPSS 0.35% Sep 25, 2026
CVE-2026-7260 MEDIUM

Stack overflow in phar with circular symlinks

CVSS 5.4 EPSS 0.15% Jul 30, 2026
CVE-2026-17544 HIGH

Out-of-bounds write in bccomp() via crafted operand and scale

CVSS 8.1 EPSS 0.43% Jul 30, 2026
CVE-2026-17543 HIGH

SQL injection in ext-pgsql via E'...' backslash breakout

CVSS 8.1 EPSS 0.33% Jul 30, 2026
CVE-2026-14355 MEDIUM

ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD

CVSS 5.6 EPSS 0.28% Jul 3, 2026
CVE-2026-45062 HIGH

FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files

CVSS 8.1 EPSS 0.75% Jun 10, 2026
Go
CVE-2026-7263 MEDIUM

DoS attack via DOMNode::C14N()

CVSS 6.3 EPSS 0.63% May 10, 2026
CVE-2026-6104 MEDIUM

Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding

CVSS 6.3 EPSS 0.60% May 10, 2026
CVE-2026-7258 MEDIUM

Out-of-bounds read in urldecode() on NetBSD

CVSS 6.3 EPSS 0.40% May 10, 2026
CVE-2026-6722 CRITICAL

Use-After-Free in SOAP using Apache map

CVSS 9.5 EPSS 1.29% May 10, 2026
CVE-2026-7259 LOW

Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()

CVSS 2.1 EPSS 0.34% May 10, 2026
CVE-2026-7261 MEDIUM

SoapServer session-persisted object use-after-free via SOAP header fault

CVSS 6.3 EPSS 0.53% May 10, 2026
CVE-2026-7262 LOW

NULL pointer dereference in SOAP apache:Map decoder with missing <value>

CVSS 2.9 EPSS 1.05% May 10, 2026
CVE-2025-14179 HIGH

SQL injection in pdo_firebird via NUL bytes in quoted strings

CVSS 7.4 EPSS 0.44% May 10, 2026
CVE-2026-7568 MEDIUM

Signed integer overflow in metaphone()

CVSS 6.3 EPSS 0.84% May 10, 2026

Showing 1 to 25 CVEs · page 1 (more available)