Known vulnerabilities in php
Vendor:
Fedoraproject
Software:
php
Software CPE:
cpe:2.3:o:fedoraproject:php:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
128
Public exploits:
12
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
8.4.24-1.fc43
8.5.9-1.fc44
8.4.23-1.fc43
8.5.8-1.fc44
8.5.7-4.fc45
8.5.6-1.fc44
8.4.21-1.fc43
8.4.21-1.fc42
8.3.23-1.fc41
8.4.10-1.fc42
7.4.11-1.fc33
7.4.11-1.fc32
7.3.23-1.fc31
7.3.21-1.fc31
7.4.9-1.fc32
7.3.18-1.fc30
7.3.18-1.fc31
7.4.6-1.fc32
7.4.5-1.fc32
7.3.17-1.fc30
7.3.17-1.fc31
7.4.4-1.fc32
7.3.16-1.fc31
7.3.16-1.fc30
7.3.15-1.fc30
7.3.15-1.fc31
7.3.14-1.fc31
7.3.14-1.fc30
7.3.13-1.fc31
7.3.13-1.fc30
7.3.11-1.fc31
7.3.11-1.fc30
7.2.24-1.fc29
7.3.8-1.fc30
7.2.21-1.fc29
7.2.19-2.fc29
7.3.6-1.fc30
7.3.5-1.fc30
7.2.18-1.fc28
7.2.18-1.fc29
7.2.17-1.fc29
7.2.17-1.fc28
7.3.4-1.fc30
7.2.16-1.fc29
7.2.16-1.fc28
7.3.3-1.fc30
7.2.14-1.fc29
7.2.14-1.fc28
7.2.13-2.fc29
7.2.13-2.fc28
7.2.12-1.fc29
7.2.12-1.fc28
7.1.22-1.fc27
7.2.10-1.fc29
7.2.10-1.fc28
7.1.20-1.fc27
7.2.8-1.fc28
7.1.17-1.fc26
7.1.17-1.fc27
7.2.5-1.fc28
7.1.16-1.fc27
7.1.16-1.fc26
7.2.4-1.fc28
7.1.15-1.fc26
7.1.15-1.fc27
7.1.13-1.fc26
7.1.13-1.fc27
7.0.25-1.fc25
7.1.11-1.fc27
7.1.11-1.fc26
7.1.7-1.fc26
5.6.31-1.fc24
7.0.21-1.fc25
5.6.27-1.fc24
5.6.27-1.fc23
7.0.12-2.fc25
5.6.26-1.fc23
5.6.26-1.fc24
7.0.11-1.fc25
7.0.10-1.fc25
5.6.24-2.fc24
5.6.24-1.fc23
5.6.23-1.fc24
5.6.23-1.fc22
5.6.23-1.fc23
5.6.22-1.fc22
5.6.22-1.fc23
5.6.22-1.fc24
5.6.21-1.fc24
5.6.21-1.fc22
5.6.21-1.fc23
5.6.20-1.fc22
5.6.20-1.fc23
5.6.20-1.fc24
5.6.19-1.fc22
5.6.19-1.fc23
5.6.18-1.fc22
5.6.18-1.fc23
5.6.17-1.fc23
5.6.17-1.fc22
5.6.14-1.fc22
5.6.14-1.fc23
5.6.14-1.fc21
5.6.13-1.fc23
5.6.13-1.fc22
5.6.13-1.fc21
5.6.11-1.fc21
5.6.9-1.fc21
5.6.9-1.fc22
5.6.8-1.fc21
5.6.8-1.fc22
5.6.7-1.fc21
5.6.7-2.fc22
5.6.6-1.fc21
5.6.5-1.fc21
5.6.4-2.fc21
5.6.2-1.fc21
8.3.18-1.fc40
8.3.18-1.fc41
8.4.5-1.fc42
8.1.12-1.fc36
8.1.12-1.fc37
8.0.25-1.fc35
8.0.24-1.fc35
8.1.11-1.fc36
8.1.11-1.fc37
8.1.8-1.fc36
8.1.7-1.fc36
8.0.20-1.fc35
8.0.16-1.fc35
7.4.28-1.fc34
8.0.13-1.fc35
7.4.26-1.fc34
7.4.26-1.fc33
7.4.25-1.fc34
7.4.25-1.fc33
8.0.12-2.fc35
7.4.23-1.fc34
7.4.23-1.fc33
8.0.10-1.fc35
7.4.21-1.fc34
7.4.21-1.fc33
7.4.19-1.fc34
7.4.19-1.fc33
7.4.19-1.fc32
7.4.18-1.fc34
7.4.18-1.fc32
7.4.18-1.fc33
7.4.15-1.fc33
7.4.15-1.fc32
7.4.14-1.fc32
7.4.14-1.fc33
8.3.14-1.fc41
8.3.14-1.fc40
8.2.24-1.fc39
8.3.12-1.fc40
8.3.12-1.fc41
8.3.8-1.fc40
8.2.20-1.fc39
8.2.18-1.fc38
8.2.18-1.fc39
8.3.5-1.fc40
8.2.9-2.fc38
8.1.22-1.fc37
8.2.9-1.fc38
8.1.20-1.fc37
8.2.7-2.fc38
8.1.16-1.fc36
8.1.16-1.fc37
8.1.14-1.fc37
8.1.14-1.fc36
Vulnerabilities (128)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU140834 - Out-of-bounds write CVE-2026-17544 |
CWE-787 | Medium | 8.4.24-1.fc43, 8.5.9-1.fc44 | 03.08.2026 |
SB2026080395 SB2026080397 SB2026080398 and 1 more |
||
| #VU140833 - Uncontrolled Recursion CVE-2026-7260 |
CWE-674 | Low | 8.4.24-1.fc43, 8.5.9-1.fc44 | 03.08.2026 |
SB2026080395 SB2026080397 SB2026080398 and 10 more |
||
| #VU140832 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2026-17543 |
CWE-89 | High | 8.4.24-1.fc43, 8.5.9-1.fc44 | 03.08.2026 |
SB2026080395 SB2026080397 SB2026080398 and 10 more |
||
| #VU112190 - Server-Side Request Forgery (SSRF) CVE-2025-1220 |
CWE-918 | Medium | 8.3.23-1.fc41, 8.4.10-1.fc42 | 04.07.2025 |
SB2025070427 SB2025070433 SB2025070434 and 16 more |
||
| #VU112189 - NULL Pointer Dereference CVE-2025-6491 |
CWE-476 | Medium | 8.3.23-1.fc41, 8.4.10-1.fc42 | 04.07.2025 |
SB2025070427 SB2025070433 SB2025070434 and 18 more |
||
| #VU112187 - Error Handling CVE-2025-1735 |
CWE-388 | Medium | 8.3.23-1.fc41, 8.4.10-1.fc42 | 04.07.2025 |
SB2025070427 SB2025070433 SB2025070434 and 17 more |
||
| #VU105644 - Improper input validation CVE-2025-1217 |
CWE-20 | Medium | 8.3.18-1.fc40, 8.3.18-1.fc41, 8.4.5-1.fc42 | 12.03.2025 |
SB2025031234 SB2025031232 SB2025031231 and 21 more |
||
| #VU105643 - Improper input validation CVE-2025-1734 |
CWE-20 | Medium | 8.3.18-1.fc40, 8.3.18-1.fc41, 8.4.5-1.fc42 | 12.03.2025 |
SB2025031234 SB2025031232 SB2025031231 and 21 more |
||
| #VU105642 - Improper input validation CVE-2025-1861 |
CWE-20 | Low | 8.3.18-1.fc40, 8.3.18-1.fc41, 8.4.5-1.fc42 | 12.03.2025 |
SB2025031234 SB2025031232 SB2025031231 and 21 more |
||
| #VU105641 - Improper Authentication CVE-2025-1736 |
CWE-287 | Medium | 8.3.18-1.fc40, 8.3.18-1.fc41, 8.4.5-1.fc42 | 12.03.2025 |
SB2025031234 SB2025031232 SB2025031231 and 21 more |
||
| #VU105640 - Resource Management Errors CVE-2025-1219 |
CWE-399 | Low | 8.3.18-1.fc40, 8.3.18-1.fc41, 8.4.5-1.fc42 | 12.03.2025 |
SB2025031231 SB2025031232 SB2025031233 and 20 more |
||
| #VU105639 - Use After Free CVE-2024-11235 |
CWE-416 | Medium | 8.3.18-1.fc40, 8.3.18-1.fc41, 8.4.5-1.fc42 | 12.03.2025 |
SB2025031231 SB2025031232 SB2025031233 and 10 more |
||
| #VU100674 - Buffer over-read CVE-2024-11233 |
CWE-126 | Medium | 8.3.14-1.fc40, 8.3.14-1.fc41 | 19.11.2024 |
SB2024111985 SB2024112137 SB2024112138 and 16 more |
||
| #VU100673 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2024-11234 |
CWE-93 | Medium | 8.3.14-1.fc40, 8.3.14-1.fc41 | 19.11.2024 |
SB2024111985 SB2024112137 SB2024112138 and 15 more |
||
| #VU100672 - Integer overflow CVE-2024-11236 |
CWE-190 | High | 8.3.14-1.fc40, 8.3.14-1.fc41 | 19.11.2024 |
SB2024111985 SB2024112137 SB2024112138 and 12 more |
||
| #VU100671 - Buffer over-read CVE-2024-8929 |
CWE-126 | Medium | 8.3.14-1.fc40, 8.3.14-1.fc41 | 19.11.2024 |
SB2024111985 SB2024112137 SB2024112138 and 15 more |
||
| #VU100670 - Out-of-bounds read CVE-2024-8932 |
CWE-125 | Medium | 8.3.14-1.fc40, 8.3.14-1.fc41 | 19.11.2024 |
SB2024111985 SB2024112137 SB2024112138 and 11 more |
||
| #VU100666 - Use After Free |
CWE-416 | High | 8.3.14-1.fc40, 8.3.14-1.fc41 | 19.11.2024 |
SB2024111985 SB2024112137 SB2024112138 |
||
| #VU97691 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2024-8926 |
CWE-78 | High | 8.2.24-1.fc39, 8.3.12-1.fc40, 8.3.12-1.fc41 | 25.09.2024 |
SB2024092519 SB2024092520 SB2024092524 and 7 more |
||
| #VU91106 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2024-4577 |
CWE-78 | Critical | 8.2.20-1.fc39, 8.2.24-1.fc39, 8.3.8-1.fc40, 8.3.12-1.fc40 | 04.06.2024 |
SB2024060501 SB2024060502 SB2024060503 and 12 more |
Showing elements 1 - 20 out of 128