PHP / PHP
727 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-92842 | OOB read / info leak in convert.* stream filters when line-break-chars contains NUL | MEDIUM | 5.9 | Sep 25, 2026 |
| CVE-2026-91768 | IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes) | MEDIUM | 6.5 | Sep 25, 2026 |
| CVE-2026-91769 | TLS Hostname Verification Falls Back to CN After SAN Mismatch | MEDIUM | 4.3 | Sep 25, 2026 |
| CVE-2026-91767 | Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN | MEDIUM | 6.5 | Sep 25, 2026 |
| CVE-2025-1218 | Various packet overreads in mysqlnd_writeprotocol.c | LOW | 3.7 | Sep 25, 2026 |
| CVE-2026-91766 | Cross-origin credential leak in HTTP stream wrapper redirects | MEDIUM | 5.9 | Sep 25, 2026 |
| CVE-2026-91765 | SOAP: Unbounded Recursion in Server-Side cleanup_xml_node | HIGH | 7.5 | Sep 25, 2026 |
| CVE-2025-14181 | Integer overflow to buffer overflow in soap HTTP parsing | MEDIUM | 6.5 | Sep 25, 2026 |
| CVE-2026-17545 | PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS | MEDIUM | 6.9 | Sep 25, 2026 |
| CVE-2026-6103 | Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection | MEDIUM | 4.3 | Sep 25, 2026 |
| CVE-2026-93682 | Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header | MEDIUM | 5.8 | Sep 25, 2026 |
| CVE-2026-7260 | Stack overflow in phar with circular symlinks | MEDIUM | 5.4 | Jul 30, 2026 |
| CVE-2026-17544 | Out-of-bounds write in bccomp() via crafted operand and scale | HIGH | 8.1 | Jul 30, 2026 |
| CVE-2026-17543 | SQL injection in ext-pgsql via E'...' backslash breakout | HIGH | 8.1 | Jul 30, 2026 |
| CVE-2026-14355 | ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD | MEDIUM | 5.6 | Jul 3, 2026 |
| CVE-2026-7263 | DoS attack via DOMNode::C14N() | MEDIUM | 6.3 | May 10, 2026 |
| CVE-2026-6104 | Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding | MEDIUM | 6.3 | May 10, 2026 |
| CVE-2026-7258 | Out-of-bounds read in urldecode() on NetBSD | MEDIUM | 6.3 | May 10, 2026 |
| CVE-2026-6722 | Use-After-Free in SOAP using Apache map | CRITICAL | 9.5 | May 10, 2026 |
| CVE-2026-7259 | Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() | LOW | 2.1 | May 10, 2026 |
| CVE-2026-7261 | SoapServer session-persisted object use-after-free via SOAP header fault | MEDIUM | 6.3 | May 10, 2026 |
| CVE-2026-7262 | NULL pointer dereference in SOAP apache:Map decoder with missing <value> | LOW | 2.9 | May 10, 2026 |
| CVE-2025-14179 | SQL injection in pdo_firebird via NUL bytes in quoted strings | HIGH | 7.4 | May 10, 2026 |
| CVE-2026-7568 | Signed integer overflow in metaphone() | MEDIUM | 6.3 | May 10, 2026 |
| CVE-2026-6735 | XSS within PHP-FPM status endpoint | HIGH | 7.3 | May 10, 2026 |
Showing 1 to 25 of 727 CVEs